{"id":46755,"date":"2019-03-11T14:53:48","date_gmt":"2019-03-11T14:53:48","guid":{"rendered":"https:\/\/owncloud.com\/?p=46755"},"modified":"2020-08-17T14:50:47","modified_gmt":"2020-08-17T14:50:47","slug":"all-your-passwords-everywhere-with-a-secure-password-manager-in-owncloud","status":"publish","type":"post","link":"https:\/\/owncloud.com\/de\/blogs\/all-your-passwords-everywhere-with-a-secure-password-manager-in-owncloud\/","title":{"rendered":"All Your Passwords, Everywhere \u2013 With a Secure Password Manager in ownCloud"},"content":{"rendered":"<div class=\"headline-wrap\">\n<h1>All Your Passwords, Everywhere \u2013 With a Secure Password Manager in ownCloud<\/h1>\n<div class=\"excerpt bold\">\n<p>Weak passwords are one of the main reasons for successful hacking attacks \u2013 password managers can protect you. With ownCloud, you can even share your passwords between devices.<\/p>\n<\/div>\n<\/div>\n<div class=\"content\">\n<p>Usually, security comes with a price. Most tools which can protect your online security, like javascript blockers or GPG, get in the way of your tasks. Password managers are an exception.<\/p>\n<p>A password manager is one of the few tools which both protect you\u00a0<em>and<\/em>\u00a0make your life easier. You only need to remember one passphrase to decrypt your vault \u2013 then you can copy-paste all other passwords from there.<\/p>\n<p>No reason to keep weird username\/passphrase combinations in mind. No reason for 4 different passwords, of which one contains a * and two $$ characters, but another doesn\u2019t, because the platform forbid it. No reason to type out all those passwords ever again.<\/p>\n<p>&nbsp;<\/p>\n<h2>Why Put Your Passwords in the Cloud?<\/h2>\n<p>One problem with password managers is that they usually stay on one device. This is more secure, but inconvenient \u2013 you may need your bank credentials on your phone one day, e.g. during vacations.<\/p>\n<p>If only you had an ownCloud account to synchronize your passwords between all your devices, just as you are used to with your files. Fortunately, this is possible.<\/p>\n<p>&nbsp;<\/p>\n<div id=\"attachment_17037\" class=\"wp-caption alignnone\" style=\"width: 550px;\">\n<p><a class=\"fancybox image\" href=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-best-hacker-secure-password-manager.jpg\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-17037 \" src=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-best-hacker-secure-password-manager.jpg\" sizes=\"(max-width: 1200px) 100vw, 1200px\" srcset=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-best-hacker-secure-password-manager.jpg 1200w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-best-hacker-secure-password-manager-300x180.jpg 300w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-best-hacker-secure-password-manager-768x460.jpg 768w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-best-hacker-secure-password-manager-1024x613.jpg 1024w\" alt=\"A woman sitting on a bed with a laptop\" width=\"550\" height=\"329\" aria-describedby=\"caption-attachment-17037\" \/><\/a><\/p>\n<p id=\"caption-attachment-17037\" class=\"wp-caption-text\"><em>Don\u2019t be fooled \u2013 not all hackers wear a black hoodie or a mask. At least not all the time.<\/em><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p>If you store your passwords in the cloud, you have to worry about who owns the server, of course. Here comes the ownCloud bonus: in contrast to other cloud storage providers, with ownCloud you know which admin you trust with protecting your passphrases.<\/p>\n<p>With most password managers, and definitely with the two tools I\u2019m showing today, you don\u2019t even have to worry about that. The password vaults are encrypted with your master passphrase, so the admin can\u2019t access them.<\/p>\n<p>There are several password managers out there \u2013 the tools with the best integration into ownCloud are KeePassXC and Passman.<\/p>\n<p>&nbsp;<\/p>\n<h2>KeePassXC \u2013 All Your Passwords in One File<\/h2>\n<p>KeePassXC stores all of your passphrases in one file, the password database. It\u2019s easy: you just download KeePassXC from\u00a0<a href=\"https:\/\/keepassxc.org\/download\/\" target=\"_blank\" rel=\"noopener noreferrer\">the official website<\/a>\u00a0or the packages for your distribution, install it, and create a database.<\/p>\n<p>The best way is to use the\u00a0<a href=\"https:\/\/owncloud.org\/download\/#owncloud-desktop-client\" target=\"_blank\" rel=\"noopener\">ownCloud desktop client<\/a>. Then you can save it in your synchronization folder, so it stays in sync with your other devices.<\/p>\n<p>If you want to access it on mobile, you have to install the ownCloud\u00a0<a href=\"https:\/\/owncloud.org\/download\/#owncloud-mobile-apps-android\" target=\"_blank\" rel=\"noopener\">Android<\/a>\u00a0or\u00a0<a href=\"https:\/\/owncloud.org\/download\/#owncloud-mobile-apps-ios\" target=\"_blank\" rel=\"noopener\">iOS<\/a>\u00a0app, and a KeePass app like\u00a0<a href=\"http:\/\/www.keepassdroid.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">KeePassDroid<\/a>. Then you can import the KeePass database from the ownCloud directory.<\/p>\n<p>&nbsp;<\/p>\n<h3>Add a Passphrase to Your KeePass Store<\/h3>\n<p>Pick a strong, long passphrase which you can definitely remember.\u00a0<a href=\"https:\/\/www.xkcd.com\/936\/\" target=\"_blank\" rel=\"noopener noreferrer\">This XKCD comic<\/a>\u00a0is very good advice on how to create strong passwords, which are easy to remember. Then you can start to save your passwords:<\/p>\n<p>&nbsp;<\/p>\n<div id=\"attachment_17018\" class=\"wp-caption alignnone\" style=\"width: 551px;\">\n<p><a class=\"fancybox image\" href=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-create-password.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-17018\" src=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-create-password.png\" sizes=\"(max-width: 1326px) 100vw, 1326px\" srcset=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-create-password.png 1326w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-create-password-300x185.png 300w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-create-password-768x474.png 768w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-create-password-1024x632.png 1024w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-create-password-1320x814.png 1320w\" alt=\"ownCloud KeePassXC create password\" width=\"551\" height=\"340\" aria-describedby=\"caption-attachment-17018\" \/><\/a><\/p>\n<p id=\"caption-attachment-17018\" class=\"wp-caption-text\"><em>Create a new password entry in KeePassXC.<\/em><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<h3>Built-in Password Generator<\/h3>\n<p>When you need a new passphrase though, you better use the built-in password generator. It creates random passwords, which are nearly impossible to guess. This is what it looks like in KeePassXC:<\/p>\n<p>&nbsp;<\/p>\n<div id=\"attachment_17019\" class=\"wp-caption alignnone\" style=\"width: 552px;\">\n<p><a class=\"fancybox image\" href=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-password-generator.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-17019\" src=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-password-generator.png\" sizes=\"(max-width: 1231px) 100vw, 1231px\" srcset=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-password-generator.png 1231w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-password-generator-300x206.png 300w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-password-generator-768x528.png 768w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-password-generator-1024x705.png 1024w\" alt=\"ownCloud KeePassXC password generator\" width=\"552\" height=\"380\" aria-describedby=\"caption-attachment-17019\" \/><\/a><\/p>\n<p id=\"caption-attachment-17019\" class=\"wp-caption-text\"><em>Use the built-in password generator of KeePassXC to generate a password.<\/em><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<h3>Export Your Credentials to Other Password Managers<\/h3>\n<p>KeePassXC is a great tool to start, and has almost all features you need. If you miss something and find another password manager which supports it, you can still export all your passwords to a .csv file and import it somewhere else.<\/p>\n<p>&nbsp;<\/p>\n<div id=\"attachment_17022\" class=\"wp-caption alignnone\" style=\"width: 551px;\">\n<p><a class=\"fancybox image\" href=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-export-csv.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-17022\" src=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-export-csv.png\" sizes=\"(max-width: 1218px) 100vw, 1218px\" srcset=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-export-csv.png 1218w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-export-csv-300x192.png 300w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-export-csv-768x492.png 768w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-KeePassXC-export-csv-1024x656.png 1024w\" alt=\"ownCloud KeePassXC export csv\" width=\"551\" height=\"353\" aria-describedby=\"caption-attachment-17022\" \/><\/a><\/p>\n<p id=\"caption-attachment-17022\" class=\"wp-caption-text\"><em>You can export you passwords from KeePass into a csv file.<\/em><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p>For example into Passman, the second password manager I want to introduce:<\/p>\n<p>&nbsp;<\/p>\n<h2>Passman \u2013 a Password Manager Integrated Into ownCloud<\/h2>\n<p>If you don\u2019t have admin rights and can\u2019t install KeePassXC on your computer, then\u00a0<a href=\"https:\/\/marketplace.owncloud.com\/apps\/passman\" target=\"_blank\" rel=\"noopener noreferrer\">Passman<\/a>\u00a0might be the solution for you. It is an ownCloud app, the ownCloud admin installs it to the server.<\/p>\n<p>Then it works in the browser \u2013 you can open it via the app tray in ownCloud. The first step is, as with KeePassXC, to create a password vault. Choose a strong passphrase:<\/p>\n<p>&nbsp;<\/p>\n<div id=\"attachment_17027\" class=\"wp-caption alignnone\" style=\"width: 550px;\">\n<p><a class=\"fancybox image\" href=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-create-vault.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-17027\" src=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-create-vault.png\" sizes=\"(max-width: 1920px) 100vw, 1920px\" srcset=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-create-vault.png 1920w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-create-vault-300x146.png 300w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-create-vault-768x373.png 768w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-create-vault-1024x497.png 1024w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-create-vault-1800x874.png 1800w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-create-vault-1320x641.png 1320w\" alt=\"ownCloud Passman create vault\" width=\"550\" height=\"267\" aria-describedby=\"caption-attachment-17027\" \/><\/a><\/p>\n<p id=\"caption-attachment-17027\" class=\"wp-caption-text\"><em>You can create a Passman vault directly in the web interface.<\/em><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<h3>Add Passwords to Passman<\/h3>\n<p>Then you can add passphrases to the password manager. It really works similar as KeePassXC, just the interface looks slightly different:<\/p>\n<p>&nbsp;<\/p>\n<div id=\"attachment_17028\" class=\"wp-caption alignnone\" style=\"width: 550px;\">\n<p><a class=\"fancybox image\" href=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-add-passwords.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-17028 \" src=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-add-passwords.png\" sizes=\"(max-width: 1906px) 100vw, 1906px\" srcset=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-add-passwords.png 1906w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-add-passwords-300x147.png 300w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-add-passwords-768x376.png 768w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-add-passwords-1024x501.png 1024w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-add-passwords-1800x880.png 1800w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-add-passwords-1320x645.png 1320w\" alt=\"ownCloud Passman add passwords\" width=\"550\" height=\"269\" aria-describedby=\"caption-attachment-17028\" \/><\/a><\/p>\n<p id=\"caption-attachment-17028\" class=\"wp-caption-text\"><em>When you add a passphrase to Passman, you can also link a username and a login URL to it, even notes and tags.<\/em><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p>Of course a password generator is included in Passman, too. You can generate really secure passwords with one button. No one will ever be able to guess them (except quantum computers, maybe).<\/p>\n<p>In the settings you can find some options how those passwords should look like. The default option (12 chars) is a bit short \u2013 you should pick something above 30. You will only copy-paste them anyway:<\/p>\n<p>&nbsp;<\/p>\n<div id=\"attachment_17029\" class=\"wp-caption alignnone\" style=\"width: 551px;\">\n<p><a class=\"fancybox image\" href=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-Generator-settings.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-17029\" src=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-Generator-settings.png\" sizes=\"(max-width: 1905px) 100vw, 1905px\" srcset=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-Generator-settings.png 1905w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-Generator-settings-300x147.png 300w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-Generator-settings-768x376.png 768w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-Generator-settings-1024x502.png 1024w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-Generator-settings-1800x882.png 1800w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-Generator-settings-1320x646.png 1320w\" alt=\"ownCloud Passman Generator settings\" width=\"551\" height=\"270\" aria-describedby=\"caption-attachment-17029\" \/><\/a><\/p>\n<p id=\"caption-attachment-17029\" class=\"wp-caption-text\"><em>You can specify how many different kinds of special characters will be in your generated passwords.<\/em><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<h3>Optional: Import Your Credentials From Other Password Managers<\/h3>\n<p>Passman also has an import &amp; export function \u2013 this makes migrating from something like KeePassXC a lot easier. It supports many different password managers. If you exported your KeePassXC passwords to a .csv file, you can import them like this:<\/p>\n<p>&nbsp;<\/p>\n<div id=\"attachment_17033\" class=\"wp-caption alignnone\" style=\"width: 550px;\">\n<p><a class=\"fancybox image\" href=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-import-KeePass-passwords-1.png\" target=\"_blank\" rel=\"noopener\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-17033\" src=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-import-KeePass-passwords-1.png\" sizes=\"(max-width: 1905px) 100vw, 1905px\" srcset=\"https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-import-KeePass-passwords-1.png 1905w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-import-KeePass-passwords-1-300x147.png 300w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-import-KeePass-passwords-1-768x377.png 768w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-import-KeePass-passwords-1-1024x502.png 1024w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-import-KeePass-passwords-1-1800x883.png 1800w, https:\/\/owncloud.org\/wp-content\/uploads\/2019\/03\/ownCloud-Passman-import-KeePass-passwords-1-1320x647.png 1320w\" alt=\"ownCloud Passman import KeePass passwords\" width=\"550\" height=\"270\" aria-describedby=\"caption-attachment-17033\" \/><\/a><\/p>\n<p id=\"caption-attachment-17033\" class=\"wp-caption-text\"><em>In the settings, you can choose to import passwords from many different password managers.<\/em><\/p>\n<\/div>\n<p>&nbsp;<\/p>\n<p>You can also use the export and import feature to make backups from your passphrases \u2013 this way you can be sure you have a backup on your PC when the ownCloud goes down, or when you are offline. You can also import it into several other password managers.<\/p>\n<p>This backup will be unencrypted though \u2013 if you don\u2019t want to trust your admin with all of your passwords, you should not sync the backup to your ownCloud. Why would you? The passwords are already there, encrypted and secure.<\/p>\n<p>&nbsp;<\/p>\n<h2>What Is the Best Solution? What Is Most Secure? Pick Yourself!<\/h2>\n<p>There is no solution which fits everyone\u2019s requirements \u2013 do you have admin rights at your work computer? Does your admin refuse to install the Passman app? Do you have an ownCloud mobile app? Do you use a Linux flavor where KeePassXC doesn\u2019t run?<\/p>\n<p>Try them out and choose the solution which fits for you. ownCloud is about customizability \u2013 you should be able to adjust it to your needs. If you find another tool which works better, tell us. But for now, you can try one of those:<\/p>\n<p>&nbsp;<\/p>\n<p><a class=\"button-oc\" href=\"https:\/\/keepassxc.org\/download\/\" target=\"_blank\" rel=\"noopener noreferrer\">Install KeePassXC on your computer!<\/a><\/p>\n<p><a class=\"button-oc\" href=\"https:\/\/marketplace.owncloud.com\/apps\/passman\" target=\"_blank\" rel=\"noopener noreferrer\">Install Passman to your ownCloud!<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>Do you have other password managers to recommend? Leave a comment!<\/p>\n<p>And feel free to show this post to your family &amp; friends, if their bad passwords don\u2019t let you sleep at night.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Weak passwords are one of the main reasons for successful hacking attacks \u2013 password managers can protect you. With ownCloud, you can even share your passwords between devices.<\/p>\n","protected":false},"author":7,"featured_media":46756,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","inline_featured_image":false,"footnotes":""},"categories":[43],"tags":[],"class_list":["post-46755","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"acf":[],"_links":{"self":[{"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/posts\/46755","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/comments?post=46755"}],"version-history":[{"count":0,"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/posts\/46755\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/media\/46756"}],"wp:attachment":[{"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/media?parent=46755"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/categories?post=46755"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/owncloud.com\/de\/wp-json\/wp\/v2\/tags?post=46755"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}