what is your Favorite passwords manager and why

My favorite password manager is KeypassDx. I also use proton pass. What do you use and why?

69 points · 72 comments · view on lemmy.world

72 Comments

Matt@lemdro.id · 78 pts · 1y (6 replies)

Bitwarden. It is open source, reliable, easy to use, and compatible with everything. The free version has nearly everything, but I have the paid version to support development because $10 per year is very reasonable.

I do regularly export my password vault to KeePassXC as my backup though.

bluespin@lemmy.world · 8 pts · 1y (4 replies)

Does Bitwarden have sharing/family features? I'd like to switch but those are a hard requirement for me

Andromxda@lemmy.dbzer0.com · 17 pts · 1y (1 reply)
bluespin@lemmy.world · 4 pts · 1y

Awesome, thanks!

littlewonder@lemmy.world · 3 pts · 1y (1 reply)

Yes! They have a family plan that is basically their organization plan but cheaper.

bluespin@lemmy.world · 2 pts · 1y

Great to know! I'm on a similar plan for 1password now so I'll have to look at switching

mrlupulus@lemmy.world · 1 pts · 1y

Not open source anymore ..

mitexleo@buddyverse.one · 59 pts · 1y (7 replies)

Bitwarden is simple, reliable and works on all of my devices.

Stomata@buddyverse.one · 12 pts · 1y (6 replies)

I never used it. Is it possible to self host?

mitexleo@buddyverse.one · 30 pts · 1y (4 replies)

Yep! It's fully open source and free. I use the hosted version though.

Stomata@buddyverse.one · 4 pts · 1y (3 replies)

Looks like i need to run a server. I actually wanted a fully offline one. Maybe I'll stick with keepass

SwordInStone@lemmy.world · 20 pts · 1y (1 reply)

well, running a server is in the definition of self-hosting

Fuck_u_spez_@sh.itjust.works · 1 pts · 1y
[ removed ]
Chewy7324@discuss.tchncs.de · 4 pts · 1y

Like others've said, Bitwarden is awesome if you want a (selfhosted or hosted) server (e.g. as a much better replacement for LastPass).

If you want an offline password manager, KeePass is the way to go (i.e. KeePassDX/KeePassXC for mobile/pc).

atomicpeach@pawb.social · 11 pts · 1y

You can self host with Vaultwarden! It's just the server; you use the same Bitwarden clients.

AsudoxDev@programming.dev · 33 pts · 1y (3 replies)

Bitwarden. The UI is about to be updated to something more modern so that's no longer is an issue for most people. It's also open source, so yes.

The 10€ per year as the premium subscription is just unbeatable. You pay less than a euro per month for a reliable and robust password manager. And you don't even need the premium subscription, because almost everything is free. I honestly consider it a donation rather than a subscription.

SwordInStone@lemmy.world · 4 pts · 1y (1 reply)

10 EUR per year is a bit more than half an EUR per month

AsudoxDev@programming.dev · 3 pts · 1y

oh yeah sorry meant less than a euro

Appoxo@lemmy.dbzer0.com · 3 pts · 1y

Also how I treat it

gratux@lemmy.blahaj.zone · 24 pts · 1y

Bitwarden, i can self host it and it is quite convenient to have official apps for all platforms i use.

Mwa@lemm.ee · 16 pts · 1y

Bitwarden idk why I use it but it works fine for me

irish_link@lemmy.world · 16 pts · 1y (3 replies)

I specifically use Vaultwarden. Great for syncing and sharing across family

https://github.com/dani-garcia/vaultwarden

jasep@lemmy.world · 4 pts · 1y

Same here, self hosted on docker. I migrated from KeepassXC and I'm very happy.

Keepass was ok but because I have various devices (Mac, Windows, Android, and iPad) all accessing it, at times it would cause issues. No issues that way with VaultWarden.

ouch@lemmy.world · 1 pts · 1y (1 reply)

If you self-host, do you get TOTP support and sharing, or do you need to also pay for a subscription?

irish_link@lemmy.world · 2 pts · 1y

You totally get it and sharing without paying. I encourage you to take a look at it. Super easy to setup with docker and a front end proxy.

slazer2au@lemmy.world · 11 pts · 1y

I use keepass2android to access my keypassxc database.

SuperFola@programming.dev · 10 pts · 1y

Self hosted Bitwarden. It has been awesome for three years, never had any problems when switching from windows to Mac and then my phone from android to iPhone.

Better than keeper and last pass. Good synchronization and more options to share passwords or notes with friends compared to Firefox password store.

stardust@lemmy.ca · 10 pts · 1y (3 replies)

KeePassDx because of Magikeyboard to not have to copy paste in stuff.

Andromxda@lemmy.dbzer0.com · 8 pts · 1y

Android has password auto-fill by default, and it works with most password managers, including Bitwarden

Stomata@buddyverse.one · 2 pts · 1y

After using it for two years i just find how magikeyboard works by your comment 🤦‍♂️

Stomata@buddyverse.one · 1 pts · 1y

After using it for two years i just find how magikeyboard works by your comment 🤦‍♂️

dinckelman@lemmy.world · 9 pts · 1y (1 reply)
[ removed ]
Andromxda@lemmy.dbzer0.com · 2 pts · 1y

One of my favorites is the built-in ssh-agent.

You can accomplish the same thing using Bitwarden, completely for free: https://github.com/joaojacome/bitwarden-ssh-agent

clmbmb@lemmy.dbzer0.com · 9 pts · 1y

Bitwarden since they starded. Didn't need anything more than the free subscription, but I'm thinking of self-hosting my own vaultwarden instance.

avidamoeba@lemmy.ca · 9 pts · 1y

Proton

Sunny@slrpnk.net · 8 pts · 1y (3 replies)

Protonpass user here. Their aliasing is just too good to have.

Andromxda@lemmy.dbzer0.com · 5 pts · 1y (1 reply)

Proton Pass is not the only password manager with email aliasing integration. For example, 1Password integrates with Fastmail aliases, and Bitwarden can be used with multiple services: addy.io, SimpleLogin, Firefox Relay, Fastmail, DuckDuckGo Email Protection, and Forward Email.

Sunny@slrpnk.net · 3 pts · 1y

While true, none of the other ones are as seamless and easy as what Proton achieves. I've tried multiple other services, and always come back to Proton for exactly this.

Stomata@buddyverse.one · 3 pts · 1y

This feature is actually cool

WeLoveCastingSpellz@lemmy.dbzer0.com · 8 pts · 1y

keepass because it is simple and local

redxef@feddit.org · 7 pts · 1y (5 replies)
[ removed ]
Andromxda@lemmy.dbzer0.com · 2 pts · 1y (3 replies)

Do you also use it for TOTP?

redxef@feddit.org · 3 pts · 1y
[ removed ]
mlaga97@lemmy.mlaga97.space · 2 pts · 1y

pass-otp

ouch@lemmy.world · 2 pts · 1y

pass-otp can do TOTP as well.

midnightblue@lemmy.ca · 1 pts · 1y

I'm assuming you use this app to access your passwords on android? https://f-droid.org/en/packages/dev.msfjarvis.aps/

Fedditor385@lemmy.world · 7 pts · 1y (1 reply)

KeePass. It has everything I need and is fully under my own control.

Stomata@buddyverse.one · 2 pts · 1y

This is why i also like it

zer0bitz@lemmy.world · 7 pts · 1y

Locally stored KeePass

altima_neo@lemmy.zip · 7 pts · 1y (5 replies)

Keypass as well. I hate the PC one though, but I still use it.

I use keypass DX on my phone.

ililiililiililiilili@lemm.ee · 5 pts · 1y

Its spelled KeePass (not to be pedantic, just for clarity). Here's a link on F-droid for KeePassDX. Others should chime in, but I think KeePassXC is the best choice for Win/Linux/Mac. Then sync your database via Syncthing (or your trusted cloud provider).

Andromxda@lemmy.dbzer0.com · 2 pts · 1y (3 replies)

How do you sync your database?

wer2@lemm.ee · 6 pts · 1y

I use syncthings.

Stomata@buddyverse.one · 2 pts · 1y

I do it manually

altima_neo@lemmy.zip · 1 pts · 1y

I keep a database on my OneDrive account

fubly_glaston@feddit.org · 6 pts · 1y

I've used 1password for more years I can count on my hands, and am satisfied with it. I share vaults with family members which is extremely handy with my aging parents.

I haven't really tried much else. I see no reason to switch.

Boozilla@lemmy.world · 6 pts · 1y

Like a lot of folks, I use and recommend Bitwarden for passwords management. Their Authenticator app is really good for mobile TOTP, too.

absGeekNZ@lemmy.nz · 6 pts · 1y

KeePassXC + Keepass2Andriod, keep it all synced using Syncthing. Desktop/Laptop/Phone all have the passwords synchronized, it is super convenient.

I have been doing it this way for years, never had any issues; just starting to investigate using passkeys where I can. So that is a new adventure; I'll see how it goes with my current workflow.

stewie410@programming.dev · 5 pts · 1y

At work we're using Bitwarden for the group benefits; though I still have KeePassXC running to simplify SSH keys (Windows, naturally) for native & PuTTY.

Personally, I use KeePassXC & KeePass android (currently); and sync'd through GDrive; which is good enough for my needs.

shapis@lemmy.ml · 5 pts · 1y

Proton pass.

Used bitwarden for a long time til I lost my 2fa and lost the account. I also lost proton’s 2fa and they helped me get the account back. Been a customer since.

Case@lemmynsfw.com · 4 pts · 1y

I use proton pass currently.

My life is changing in less than two weeks.

I have an enterprise grade server that I can't run for a variety of home reasons.

When me and the wife... for lack of a better term, escape, our situation, I'll be able to self host. I know its gonna be a struggle, I have things to learn, and that is why I'm so excited.

Humanius@lemmy.world · 3 pts · 1y (1 reply)

Personally I use Enpass.
It's both my password manager, but also the place where I keep track of notes about devices, accounts and software licences.

I tried to change over to Bitwarden a few weeks ago, because that is what my office wants us to move to, but the limitations are not really bridgeable for me. Bitwarden seem to me to be very specifically a password manager and not much else.

nemno@lemmy.world · 2 pts · 1y

Yeah im on enpass for quite a few years myself. Both android and pc. Does what it says on the tin.. :)

node815@lemmy.world · 3 pts · 1y

Hands down, Bitwarden app on phone and in browser. Vaultwarden self hosted. Since I host it at home, I know it's always in my server. The winning thing for me is that Bitwarden Supports Webuathn now, you can use it as it's own webuathn key you authorize to log in with, so basically go the site you want to login with and when it asks for the webuathn, you can either have Bitwarden use the credentials you stored for it or your own biometric or hardware key instead.

With this, I sign into Authentik for my SSO just by clicking one link, and Bitwarden prompts to log in and I click the option. I'm auto logged into my server and no UN/PW passed to it.

I've tested others and nothing quite comes close except for KeepassXC, but for me, it's a matter of personal preference on my side. I've been with Bitwarden since the early days.

cafuneandchill@lemmy.world · 3 pts · 1y (1 reply)

I use Firefox' built-in password manager; anything else is a hassle to use tbh

ILikePigeons@lemmy.ml · 2 pts · 1y

Same, I do however also write all of my password in a notebook, so I don't lose them if anything bad happens.

4am@lemm.ee · 2 pts · 1y

I notice there aren’t a lot of Dashlane fans. (I use Bitwarden myself.)

Is there something wrong with them?

vamp07@lemm.ee · 1 pts · 1y

Mine is 1Password mainly because I really like the way they handle Security by forcing you to use a key that they issue you that we know is very secure because of its length than randomness. It also has the best ui of the ones I have used.

leftzero@lemmynsfw.com · -15 pts · 1y (8 replies)

My brain. A password manager seems like a completely unnecessary single point of failure.

communist@lemmy.frozeninferno.xyz · 1 pts · 1y (7 replies)
leftzero@lemmynsfw.com · -3 pts · 1y (6 replies)

This assumes a) passwords, and b) poor passwords at that.

Passphrases are easy to remember, extremely hard to crack, and easily customisable for every site, and you don't need no fucking password manager to store them.

Though I'll give you this: password managers are not, after all, necessarily single points of failure.

If you need a password manager to manage your passwords you're a much more vulnerable point of failure than your password management bloatware itself.

correct horse battery staple

communist@lemmy.frozeninferno.xyz · 7 pts · 1y (4 replies)

Or you could not have to remember all of that, have vastly more complex passwords, have it be significantly more convenient.

I currently have 100+ passwords stored in my password manager, do you actually expect people to remember 100+ unique phrases?

leftzero@lemmynsfw.com · -3 pts · 1y (3 replies)

vastly more complex passwords

Complexity is practically irrelevant when compared to length when it comes to passwords. That's the point of passphrases.

do you actually expect people to remember 100+ unique phrases

You can have a small number of passphrases and simply choose one and add a word or two based on the site. It's trivial to “remember” an infinite number of unique passphrases if you've got an algorithm. 🤷‍♂️

communist@lemmy.frozeninferno.xyz · 4 pts · 1y (2 replies)

Complexity is practically irrelevant when compared to length when it comes to passwords. That’s the point of passphrases.

are you trolling me? I can have 20,000 character long passwords with a password manager. Length is just an aspect of complexity...

You can have a small number of passphrases and simply choose one and add a word or two based on the site. It’s trivial to “remember” an infinite number of unique passphrases if you’ve got an algorithm. 🤷‍♂️

...that makes it significantly less secure and almost defeats the purpose of unique passwords, I could have 20,000 character completely unique passwords with a password manager.

leftzero@lemmynsfw.com · -3 pts · 1y (1 reply)

I can have 20,000 character long passwords with a password manager

Sure. Most websites will either truncate them or outright reject them due to being too long, but sure.

Most users, however, will use the 12 to 16 characters auto-generated ones, though, which are sufficiently hard to crack (though not as much as an easy to remember passphrase, not that it matters; the easy to remember part is what matters about passphrases).

that makes it significantly less secure

No it doesn't. Even if a few of the passphrases leak, your algorithm, if well chosen, shouldn't be easy to reverse engineer... and unless someone is specifically targeting you (and has access to enough of your passphrases) there's much easier fish to catch; if a leaked passphrase doesn't work in other sites, no one will waste time trying to figure out if it has some logic to it.

I could have 20,000 character completely unique passwords with a password manager

No you couldn't. You'd have one password and one password manager (which would have all “your” other passwords; as would anyone else with access to your password manager).

Until you lose access to your password manager, of course... which is bound to eventually happen, due to hardware or software issues or loss of the device if it's local, or due to network issues, the provider discontinuing the service, or inevitable enshittification if it's online.

And, of course, you'll have a single point of attack from which your password can be leaked (or sold, if it's an online service) or stolen.

communist@lemmy.frozeninferno.xyz · 4 pts · 1y

Until you lose access to your password manager, of course… which is bound to eventually happen, due to hardware or software issues or loss of the device if it’s local, or due to network issues, the provider discontinuing the service, or inevitable enshittification if it’s online.

It has never happened to me and is absolutely not bound to happen, especially if it's local and backed up...

I'd rather remember one REALLY secure password than 100+ bad ones.

skuzz@discuss.tchncs.de · 2 pts · 1y
[ removed ]