KeePass with the database stored locally on your device(s).
I then use syncthing to synchronize the database between my devices (laptop, phone, in-house server, backup).
The data is all under my control and does not reside on any third party computer or data storage. The only exposure to third parties is when the database is synced between devices... but at that point it is encrypted and ephemeral.
I do the same: the format used for the KeePass database is supported by software on Windows, Mac, Linux, iOS and Android. I have the database in a git repo and mostly used it from my laptop. From time to time, I put a copy on google drive to make it easy to access from a phone. This has been working well for me for years already.
In my opinion, there is a big difference between a closed source solution from a company that stores the passwords on their own systems, and open source software that stores the passwords in a local file.
For this kind of thing, I specifically want something that stores the data locally, that is not part of the browser, and that is open source. Those things together make me more confident that the software is probably ok and can be trusted.
Comments
KeePass with the database stored locally on your device(s).
I then use syncthing to synchronize the database between my devices (laptop, phone, in-house server, backup).
The data is all under my control and does not reside on any third party computer or data storage. The only exposure to third parties is when the database is synced between devices... but at that point it is encrypted and ephemeral.
I do the same: the format used for the KeePass database is supported by software on Windows, Mac, Linux, iOS and Android. I have the database in a git repo and mostly used it from my laptop. From time to time, I put a copy on google drive to make it easy to access from a phone. This has been working well for me for years already.
Can't the myriad keepass app(s) themselves get compromised?
I don't think there is a perfect solution, today lastpass, tomorrow another. I guess you trade control for convenience.
In my opinion, there is a big difference between a closed source solution from a company that stores the passwords on their own systems, and open source software that stores the passwords in a local file.
For this kind of thing, I specifically want something that stores the data locally, that is not part of the browser, and that is open source. Those things together make me more confident that the software is probably ok and can be trusted.
Does this work in iOS?
KeePass Touch is in the Apple App Store.
https://apps.apple.com/us/app/keepass-touch/id966759076
A version (port/adaption) of syncthing for ios is out there too.
https://forum.syncthing.net/t/syncthing-for-ios/16045
I don't use iDevices so I don't know how well the above apps work.
I keep my KeePass file on PC, sync to Onedrive, download to my phone from Onedrive iOS to have locally and use this app on iOS to open it.
https://authpass.app/
Works great.
Due to background download restrictions on iOS, you’d have to open syncthing manually any time you wanted to sync your database.
So it’ll work, but not conveniently.