What is a really smart choice for password manager apps? Concerned about privacy and politically involved CEOs.

I’ve used:

  • LastPass
  • 1Password
  • ProtonPass (Now using)

I thought ProtonPass was a good choice but I’m starting to read more about it. What’s just a really solid choice all around, that you can feel good about? Free or paid.

Update: I decided to go with Bitwarden and Bitwarden Authenticator. The features and the experience are better than the three listed above that I’ve used before. Awesome advice here, thanks everyone.

  • Gayhitler@lemmy.ml
    link
    fedilink
    English
    arrow-up
    37
    ·
    9 days ago

    Bitwarden.

    You know if you need more than that and if you’re asking on lemmy you don’t need more than that.

      • Gayhitler@lemmy.ml
        link
        fedilink
        English
        arrow-up
        14
        arrow-down
        1
        ·
        8 days ago

        I would recommend people not do that unless they know they need to and again, if you know you need to you’re not asking on lemmy.

        Hosting your own secrets not only puts the burden of protecting, providing access to and preserving the secrets entirely on you, but puts a very unique set of hosting goals squarely on you as well.

        Even a skilled administrator with significant resources at hand would often be better served by simply using bitwarden instead of hosting vaultwarden.

        An example I used in another thread about password managers was a disaster. When your local server is inoperable or destroyed and general local network failure makes your cloud accessible backup unreachable, can you access your secrets safely from a public computer at the fire department, church or refugee center?

        Bitwarden works well from public computers and there’s a whole guide for doing it as safely as possible on their website.

  • Churbleyimyam@lemm.ee
    link
    fedilink
    arrow-up
    24
    arrow-down
    1
    ·
    9 days ago

    Use KeepassXC with Syncthing for maximum autonomy or Bitwarden for maximum ease. Both are FOSS. That’s my recommendation and also seems to be the consensus among those who share your needs.

    • Lad@reddthat.com
      link
      fedilink
      arrow-up
      9
      ·
      9 days ago

      It’s so much better since they updated the (IMO) ugly, dated UI design. It looks nice and fresh now. Bitwarden is the MVP.

  • Saltarello@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    9 days ago

    I use Keepass but I recommended Bitwarden to less nerdy family members as it syncs out of the box & does what they need it to do. Sync is simple enough to set up with Keepass & the big plus for me is that it allows storage of files/documents. Last time I checked this was a limited/paid feature on Bitwarden

  • ParlaMint@lemmy.mlOP
    link
    fedilink
    English
    arrow-up
    2
    ·
    9 days ago

    There’s a lot of good things here to think about. I asked, there’s a lot of experience out there, and I appreciate all of it. Great community, here!

  • NutWrench@lemmy.ml
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    1
    ·
    9 days ago

    I recommend Keepass. It’s freeware, is available on all platforms and supports biometrics (fingerprints, etc) on Android devices. It also encrypts the password file on your device, so you can keep a copy of that file on a cloud service without worrying if that service really respects your privacy or not.

    • Whooping_Seal@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      9 days ago

      This is perhaps overkill, but you can also encrypt the contents of your online cloud storage with CryFS / Cryptomater. This is particularly useful if you wish to store sensitive documents (healthcare, finances etc) in a cloud environment in case of catastrophic destruction of property (destroying computers / on site backups of data).

      In this case you can also backup your keepass file in this encrypted virtual storage medium, on top of the prexisting encryption of the database itself.

  • Lettuce eat lettuce@lemmy.ml
    link
    fedilink
    arrow-up
    5
    ·
    8 days ago

    Been a Bitwarden user for several years now, both personal and deployed at multiple small businesses.

    It has been fantastic the whole time. Pricing is great, open source, runs on basically everything, and easy to use.

    KeypassXC if you’re uber-paranoid or a hardcore Stallmanite, otherwise, Bitwarden all day 100%

    • foiledAgain@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      9 days ago

      Bitwarden paid version also lets you set emergency access for others in the case of your death or inability to access

      • trouble@lemm.ee
        link
        fedilink
        arrow-up
        13
        ·
        9 days ago

        I’m happy with Bitwarden, the iPhone app and windows software / Firefox extension all work seamlessly and easily

    • hedgehog@ttrpg.network
      link
      fedilink
      arrow-up
      18
      ·
      9 days ago

      You can self-host Bitwarden, too. My understanding is that VaultWarden is much simpler to self-host, though. Note that VaultWarden isn’t a “fork”; it’s a compatible rewrite in Rust (Bitwarden’s codebase, by contrast, is primarily C#).

      I also use Bitwarden and strongly prefer it over every other password manager I’ve tried or investigated, for what that’s worth. I’d recommend it to 99% of non-enterprise users (it’s probably great for enterprise use as well, TBF).

      The only use case I wouldn’t recommend it for is when you don’t want your passwords stored in the cloud, in which case KeePass is the way to go. To be clear, that recommendation does not apply if you’re syncing your vault with a cloud storage provider - even one you’re hosting, like SyncThing - even if your vault is encrypted. At that point just use Bitwarden or VaultWarden, because they’re at least audited with your use case in mind (Vaultwarden has only been audited once afaik, though).

  • nis@feddit.dk
    link
    fedilink
    arrow-up
    10
    arrow-down
    1
    ·
    9 days ago

    I pay for a 1Password family account. I like it.

    Getting the family to use it is hard, but that would be the case with any password manager.

    • TheColonel@reddthat.com
      link
      fedilink
      arrow-up
      7
      ·
      9 days ago

      I understand there’s a bit of of bias here, but I’ve been using 1Password for probably 10+ years and have literally never had a problem. Transferred between multiple devices, added family, etc.

      Solid as hell and super reliable.

      Selfhost if you want, but I’ll take the reliability.

      • nis@feddit.dk
        link
        fedilink
        arrow-up
        4
        ·
        9 days ago

        I do selfhost everything I can, but have chosen not to do that with my passwords. It feels to much all-eggs-in-one-basket-y.

        1Password also holds my SSH keys and acts as an ssh-agent on most systems, and I also just found out that you can get secrets from your 1Password vault in Python, which means my PyInfra scripts can use it as well.

        • TheColonel@reddthat.com
          link
          fedilink
          arrow-up
          2
          ·
          9 days ago

          Yeah, totally agree. I do backups in a similar way. Do I have cloud backups? Yes. Do I also have local? Hell yes.

          A combination of the two is likely the best bet but I will say 1Password feels like one of those “oft imitated, rarely replicated” solutions.

          Although I’ve also been using Apple’s solution for similar reasons. Works great, too.

  • deathbird@mander.xyz
    link
    fedilink
    arrow-up
    5
    ·
    9 days ago

    No one has mentioned pwsafe, which was originally created by Bruce Schneier and is still maintained.