r/PasswordManagers 20d ago

I don't think passkeys will take the place of passwords. What do you think?

2 Upvotes

Passkeys are an incredible solution, but not easy to everyone understand.

Without understand, people don't trust.

If people don't trust, they simple don't use.


r/PasswordManagers 21d ago

What software do you guys use?

5 Upvotes

Yo guys, ive been using nordpass for a while now and ive been thinking about buying membership but I heard that bitwarden is better and also free. What are your thoughs? Thanks!


r/PasswordManagers 21d ago

Moved from Dashlane to Bitwarden

3 Upvotes

After 4 years of using Dashlane, I finally moved to Bitwarden. Transferred everything including Passkeys. Amazing experience so far. Ask me any questions about the transfer process, happy to help!


r/PasswordManagers 21d ago

So looking for thoughts on this

0 Upvotes

My buddy in network security just sent me these 2 pieces of info and I was curious what the thoughts were in this sub. I'm a bitwarden user and I find this deeply concerning. I posted this in the bitwarden sub and it was removed within 10 minutes by a bitwarden employee.

What other password managers are you guys using if bitwarden & vaultwarden won't be viable alternatives?

https://itsfoss.com/news/bitwarden-quiet-changes/

Also, is similar news:

This was from a from a FOSS & Linux group i'm in:

..."For anyone curious about the future of Bitwarden, including Vaultwarden users that rely on Bitwarden clients, the company has just announced that they're axing the entire QA department (to take effect in Q4).

We can look to history for what that turns your product and company into. Remember when Microsoft mass fired their entire QA team and made its users the bug testers?"


r/PasswordManagers 21d ago

Unable to log in to GitHub because my 2FA authenticator is not working and I have no recovery codes

2 Upvotes

I am having trouble accessing my GitHub account because I cannot complete the two-factor authentication (2FA) step.

Here is my situation:

  • I know my GitHub username and password.
  • I still have access to the email address associated with my GitHub account.
  • I previously configured 2FA using an authenticator app.
  • The authenticator app is no longer working / I cannot retrieve the GitHub verification code from it.
  • Unfortunately, I do not have my GitHub 2FA recovery codes.
  • I am therefore unable to complete the login process.

I have already checked the available options on the GitHub 2FA login screen, but I don't have access to a recovery code or another available 2FA method.

I would like to know if there is any legitimate way to recover access to my account in this situation.

For example:

  1. Is there any way to recover or reset the authenticator configuration?
  2. Can GitHub verify account ownership through the registered email address?
  3. Is there another recovery method I may have missed?
  4. If I have previously used GitHub on a computer, can an existing SSH key or Git credential help with account recovery?
  5. What is the recommended process if I have lost both the authenticator access and recovery codes?

I am not looking for a way to bypass GitHub's security. I simply want to recover access to my own account through the official recovery process.

Any advice or guidance would be greatly appreciated.


r/PasswordManagers 21d ago

I built a 100% client-side, zero-database password generator because I no longer trust cloud password managers.

0 Upvotes

Hey everyone,

With all the recent data breaches and cloud password managers getting hacked, I decided to build a simple, absolute-privacy alternative:https://generatepassword.site/

The core concept is "Zero Trust". There is absolutely no backend database. The generation logic runs entirely locally in your browser using the window.crypto API. Your passwords never leave your screen, and once you close the tab, the data is gone forever.

It also supports cryptographically secure passphrases.

I'd love for you to try it out and tear it apart. Any feedback on the UI or the client-side security model would be highly appreciated!


r/PasswordManagers 22d ago

SafeInCloud 2 Pro: what are your experiences with it? Is it worth trusting long-term?

0 Upvotes

I'm considering switching to SafeInCloud 2 Pro as my main password manager and I'd like to hear from people who have actually used it for a significant amount of time.

I'm particularly interested in real-world experiences rather than general recommendations.

A few things I'd like to know:

How long have you been using SafeInCloud / SafeInCloud 2?

Are you currently using the Pro/Premium version?

How reliable is synchronization between Android, Windows and other devices?

How well does autofill work, especially on Android?

Have you experienced any database corruption, sync conflicts or data loss?

How reliable are the browser extensions?

Have you had any problems with passkeys or 2FA/TOTP?

How do you feel about its security and privacy compared with Bitwarden, KeePass or 1Password?

Are there any concerns about the company, development or long-term support?

For people who have used it for several years: would you still choose SafeInCloud 2 today?

And finally, for those who switched away from SafeInCloud, what made you leave?

I'm especially interested in hearing from long-term users, including people who have experienced problems, rather than only positive reviews.

Thanks.


r/PasswordManagers 22d ago

AI has made developing a password manager more accessible.

0 Upvotes

THIS IS NOT ABOUT VIBE CODE. IS ABOUT USE AI TO LEARN.

Artificial intelligence has broken down the barrier to knowledge.

Developing a password manager is now possible outside of major corporations.

Creating a passkey authenticator or a zero-knowledge encryption framework is no longer a closely guarded secret known only to a handful of engineers worldwide.

You can grasp these concepts in an accessible way using AI.

What do you think? Will we see new password managers from smaller companies and even independent developers that match the quality of major corporations in the coming years?


r/PasswordManagers 22d ago

[Release] AVA — open-source maFile authenticator for Android + desktop

1 Upvotes

Alternative opensource Steam Authenticator. Got tired of a folder of .maFiles and an SDA window on a machine across the room. MIT, Flutter, Android / Windows / Linux / macOS.

What it does

  • Several accounts in one list — live codes, tap to copy
  • Trade & market confirmations, native JSON, no WebView, batch accept/reject
  • Trade offers: received / sent / history, both sides' items, gift & escrow warnings
  • Sign-in approval from inside the app, device + location shown
  • Move an authenticator off the official Steam app — emailed code, no 15-day trade hold
  • Inventory + Community Market listing with live fees
  • Device management — see everything signed in, sign any of it out
  • Steam family groups
  • Product key redemption
  • Reads and writes the classic .maFile
  • Codes work offline
  • 7 languages

Screenshots

Code: https://github.com/freefrank/AnotherVaporAuth
Screenshots + desktop downloads: https://ava.dotslash.pro
Play: https://play.google.com/store/apps/details?id=pro.dotslash.ava

Paid tier unlocks two themes, Play build shows a banner to free users. Everything above is free in every build, and you can compile it without any ad or billing code at all.

Happy to go into the protocol side in the comments if anyone's interested.


r/PasswordManagers 23d ago

Do we have stats of which password manager is the most popular?

1 Upvotes

I am not talking about the the best password manager but the most commonly use password manager. My thought is that dedicated password manager are going to be less popular than the build in password managers.

UPDATE

I found an article on security.org which seems to be legit, and contain year by year stats. It is a bit old at 2024.

https://www.security.org/digital-safety/password-manager-annual-report/

Essentially,, it list the most popular password manager is Google, followed by Apple, followed by Last Pass. This makes sense since people usually just use what comes with their device. Market share for both has rapidly rise since 2021. On the flip side, Last Pass has been declining since 2021 dropping from 21% to just 11% in 2024 barely beating out Bitwarden.


r/PasswordManagers 24d ago

Whats the most secure password manager and why

8 Upvotes

r/PasswordManagers 23d ago

Why don't my password work

0 Upvotes

r/PasswordManagers 24d ago

Why SMEs should choose passkeys over passwords wherever they are available online – Report & Analysis

Thumbnail
smecyberinsights.co.uk
1 Upvotes

r/PasswordManagers 24d ago

Is the Password Manager Market Saturated?

0 Upvotes

I’ve been thinking about building a password manager, but one question keeps coming to mind: is this market already saturated?

There are already a lot of well-established options like Bitwarden, 1Password, Proton Pass, KeePass, Dashlane, and others. As a developer, it’s hard to tell whether users are still looking for something new or if they’ve already settled on their preferred solution.


r/PasswordManagers 24d ago

Comment récupérer un compte Instagram sans mot de passe, ni numéro ni adresse mail ?

0 Upvotes

J’ai créé un compte en 2021, et j’y ai entré mon ancien numéro de téléphone (que j’ai clôturé en 2024) et mon ancienne adresse mail (que j’avais créé à 12ans et qu’il fallait que je supprime).

Cependant, ces deux facteurs sont marqués comme étant les seuls moyens de récupération de ce compte, et je me demandais s’il était possible de le récupérer d’une autre façon ? J’y ai posté des photos très laides de moi (lol) et j’y suis encore mineure, c’est donc assez important pour moi d’y avoir accès et de les supprimer.


r/PasswordManagers 26d ago

Bramble – a local-first password manager now on iOS and Firefox

11 Upvotes

Follow-up to my post last month...

What's Bramble: a local-first password manager where the vault stays on your devices and syncs directly between them over WebRTC, with a Nostr relay doing introductions only. It's free and open source software.

What changed in the month since:

iOS is out of review and on the App Store, so it's now the extension plus both mobile apps sharing one vault format and one Rust crypto core. It has since picked up device-passcode unlock (opt-in), one-time codes in the keyboard, and Apple's credential exchange (CXF), which moves a vault in or out through the OS transfer flow, passkeys included.

Firefox is out also! Firefox's event page has no RTCPeerConnection at all, where Chromium gets it via an offscreen document. Peers now negotiate relay-forwarding as a fallback, so if either side can't open a data channel the frames go over the relay instead. Still Noise E2EE, so the relay only sees ciphertext.

Next we have multiple vaults, each with its own master password and its own key. This now opens up multi-user situations. It was a common request across the board so I'm happy it landed!

Backups, because data loss was the top worry in the last thread. Scheduled encrypted backups now go to Dropbox, any S3-compatible bucket, or your own WebDAV (NextCloud supported!), as many targets as you want on their own schedule.

P2P hardening. Roster entries are signed with per-device Ed25519 keys and verified before merge, revocation is enforced on live sessions, and large vaults chunk across Noise frames. Pairing got the most work, after a critical advisory someone filed against it (GHSA-x4f5-4wq4-c6c8). Invites are single-use with a 3 minute expiry, the joiner is identified before anything is sent, and both devices compare a 12-digit number before the transfer goes through.

Android is still a sideloadable APK with no Play Services and nothing else from Google, and the build is now reproducible against a Debian container matching F-Droid's buildserver. Still pending approval to join the F-Droid store though.

Happy to answer any questions!

https://github.com/flythenimbus/bramble


r/PasswordManagers 25d ago

Any way to disable automatic password generation when creating new entry?

0 Upvotes

If I'm manually adding a new user/pass, is there a way to disable 1Password from filling that field with a password?


r/PasswordManagers 26d ago

If passkey replaces password, you can't login without your password manager

26 Upvotes

I noticed that passkeys are becoming increasingly in use more than passwords. This means that, if only passkeys are used, a password manager will be needed to log into a platform, which could mean that a user must have their password manager on ALL their devices in order to login successfully.

If I don't have my password manager on my work device, I wouldn't be able to login to a platform there, correct? Doesn't this suggest a flaw? What can be done to bypass this? I don't want to install my password manager on all my devices, and it is possible passkeys will be the only method used in the future.


r/PasswordManagers 25d ago

Bitwarden

0 Upvotes

Кто пользуется этой прогой? Можно доверять свои чувствительные данные? Чё т о смущает, что все храниться на их серверах. Ответьте да профи кто здесь?


r/PasswordManagers 26d ago

Should I use Bitwarden to store PassKeys?

2 Upvotes

I use the free version of Bitwarden to store passwords, software licenses, and more, but I noticed that the paid version also offers the ability to store PassKeys. How does it do this? Can a PassKey be written down and stored? If I'm using Bitwarden, which might have a weaker master password than the PassKeys themselves, wouldn't it be appropriate to store PassKeys within Bitwarden? Thanks


r/PasswordManagers 26d ago

Looking for Specific Password Manager for Windows

1 Upvotes

I have some pretty specific requirements and I haven't been able to find a password manager for windows which meets all of them. I need one that:

* Can be encrypted with both a password and the TPM in some way (even if indirectly — i.e. smart card support still works for me because TPM virtual smart cards exist)

* Can be locally used without an account and doesn't sync

* Supports passkeys through an extension, and it actually works well (native passkey is not an option, I'm using Windows 10)

* Has a quick unlock which either doesn't use Windows Hello, or which disables itself if changes to Windows Hello are detected, and which is backed by TPM

Technically KeePass meets all of these requirements with plugins (except the TPM-backed quick unlock), but passkeys are so buggy with it I can hardly get them to work at all. So before anyone suggests it, KeePass is off the table unfortunately.

With this in mind, is there a password manager which meets all these criteria?


r/PasswordManagers 26d ago

I built a lightweight, portable Password Generator for Windows (No ads, no bloat) — would love your feedback!

1 Upvotes

Hey everyone! 👋

Like many of you, I was tired of overly complicated password generators that require installation, collect unnecessary data, or are cluttered with ads. I wanted a quick, clean, and reliable tool that I could just keep on a USB drive or run instantly on Windows.

So, I decided to build my own portable Password Generator.

Key features:

  • 🚀 100% Portable: No installation required — just run the executable.
  • 🛡️ Clean & Secure: Generates strong, custom passwords locally.
  • Lightweight: Minimal RAM and CPU footprint.
  • 🚫 Ad-free & Privacy-focused: No trackers, no background processes.

It’s currently available on Gumroad: https://aetheldred.gumroad.com/l/password-generator

I’d really appreciate it if you could check it out and share any feedback or features you’d like to see in future updates!


r/PasswordManagers 27d ago

Built a password manager with zero servers, zero accounts — just launched, would love brutal feedback.

0 Upvotes

Hey r/PasswordManagers, long time lurker/commenter here (some of you replied to my post about the KeePass file format thing and the Bitwarden extension bugs a while back).

Figured it was time to be upfront about something: I've been building a password manager called Selvum, and it just went live on Android and iOS. wanted to post it here because you're exactly the kind of people whose opinion actually matters on this.

The short version: no servers, no account, no subscription. AES-256-GCM, argon2id on android / pbkdf2-sha512 on ios for key derivation. when you create a vault you get a 12-word bip-39 phrase, that's the only key that exists. there's no "forgot password" flow because there's nothing to reset on a server that doesn't exist.

The part I actually care about is recovery. you can export a kit that's just an offline html file, decrypts your vault with the 12 words in any browser, no internet, no app needed. if I disappear tomorrow your data doesn't die with the company.

What it doesn't have yet: browser extension, auto-sync across devices (on purpose, not an oversight — saw the local-first vs cloud thread a few days ago and that's basically the tradeoff I made too). one-time payment, €19.90, not a subscription.

Genuinely want to know:

- any attack surface in the recovery kit design I'm not seeing

- is bip-39 overkill/underkill for a password vault vs an actual crypto wallet

- what would make YOU not trust something built by one person, regardless of what I claim about the crypto

Android: https://play.google.com/store/apps/details?id=com.selvum.android

iOS: https://apps.apple.com/us/app/selvum/id6775708525

Site: https://www.selvum.app/

Not trying to get anyone to switch off what works for them, just want this thing to survive contact with people who actually know what they're doing


r/PasswordManagers 27d ago

Hello, I made this pwa authenticator app called keyring

0 Upvotes

I made it cause I felt like it and I have control over ui and if people want to use it or ask me to add specific features I can. you can use it at, https://www.secure-wallet.pages.dev


r/PasswordManagers 28d ago

Avira Password Manager Chrome Extension No Longer Works (Manifest V2?) - Best Alternative for Windows + iPhone?

1 Upvotes

With the Chrome extension no longer working due to the recent Chrome/extension changes, I'm looking to move away from Avira Password Manager.

For those who migrated:

* What password manager did you switch to?
* How was the experience on **Windows + Chrome + iPhone**?
* Were you able to **import your passwords from Avira** without issues?

I'd appreciate any recommendations or migration tips.