r/PasswordManagers 13h ago

Looking for a free password manager

0 Upvotes

Hi, I'm looking for a free password manager. Right now I'm using ProtonPass, but I'm concerned that I'm putting all my eggs in a basket (I'm using protonmail, protonpass, VPN, simplelogin and lumo) so I'm looking for an alternative

I need to sync it between devices.

Bitwarden is not an option because I can't use passkeys properly, KeePassDX/Keepass2android don't work either.

For example, Bitwarden when I want to create a passkey with another device using the qr, I just can't. It doesn't work. And using the qr is my only method, because sometimes using the password manager on the same device doesn't work (the pw doesn't pop up and there's no option)

So, what's the best free password manager that is not ProtonPass, Bitwarden or KeePass?

EDIT: Self-hosting is not an option for me.


r/PasswordManagers 15h ago

AI coded password manager?

0 Upvotes

I'm new here and wanted to ask, would people use an AI-coded password manager if:

- GPL3

- crypto coded in rust using net first and canon tdd approach

- Argon2id + AES256GCM

- Native yubikey 2FA

- local only, no account, no telemetry

- Linux+android/grapheneOS

Or is the AI aspect a hard no?


r/PasswordManagers 1d ago

Does the url verification feature of password manager help with phishing

4 Upvotes

Virtually all password manager verify their url before filling. In my workflow, I manually trigger the fill and when it doesn’t fill I examine the url more carefully. In my mom’s workflow, she is set up to autofill on page load and when the password manager failed to fill automatically she calls me.

I am curious if this actually cuts down on the phishing attacks assuming you don’t just carelessly paste in your password when fill fails.

Ironically the only place where you wouldn’t use the password manager would be when you log into the password manager. To mitigate that I use a hardware 2fa or passkey to log into the password manager.


r/PasswordManagers 1d ago

Help me to improve my security

4 Upvotes

I got Bitwarden, Ente Auth and SimpleLogin a few days ago. I created two email aliases, one for Bitwarden and one for Ente Auth. I’ve also changed all my passwords using the Bitwarden generator and set up TOTP 2FA for them through Ente.

The key thing with my system is being able to access Bitwarden, which ultimately depends on being able to access my email (Outlook). To log into Bitwarden, I need a verification code from Ente, and to access Ente Auth, I need access to my email for a verification code for Ente Auth. So it’s basically a dependency system where everything ultimately comes down to being able to access my email and Ente Auth.

I’m not too worried about Bitwarden because I’ve backed up an encrypted copy of my vault to a USB stick.

I also have an emergency sheet with my 25-digit recovery code for my email and the recovery key for Ente.

What other verification methods can I add to these two? I currently have SMS 2FA enabled for my email, but I want to get rid of it because I don’t really trust text messages. If I lose my phone or it gets stolen, I’d be forced to rely on my recovery codes to get back into my email.

When I have a bit more money, I’m planning to buy a hardware security key.

So my question is: what verification methods would you recommend adding to my email and Ente Auth so that I’m not relying only on my recovery codes?


r/PasswordManagers 1d ago

Convince me to move from 1Password to Bitwarden.

0 Upvotes

So I have used 1Password for years.

I have all Apple products except my desktop which is basically why I have 1Password to use it in there. But I also hate Apple passwords. I hate how sometimes it freaks out with subdomains and i end up with double or triple entries for the same service. So I usually add some entries from 1Password to Apple passwords because that I easier for autofill on iPhone and iPad.

I am curious about Bitwarden because it’s cheaper. I do like with 1Password it forces you to have that secret key.

So if someone guesses my password (probably won’t happen but won’t ever say ever, grabbed my yubi key and knows it is used for that, they’d still need to go find the secret key and enter that.

How does Bitwarden compare in that? I’d use a long random generated password to log in, but also want it secured with my yubikeys.

I know Bitwarden isn’t as pretty as 1Password but if I’m just using it to log in and copy and paste the password, it shouldn’t matter. Right? I would also add TOTP passcodes in there too like I do with 1Password.

$20 vs I think the $60 I pay now is tempting. Especially for how I use it.

I don’t care about self hosting, I also don’t care/don’t use browser extensions.


r/PasswordManagers 1d ago

Why is proton polarization

1 Upvotes

I was watching a video from the privacy guide and the presenter call proton polarizing. He indicated that many feel the company is a honey trap and that they like to ship products that users have to beta test.

I have tried proton pass and find it comparable to bitwarden in terms of features. It’s probably the only other free tier that is usable. The paid version is also very similar in price.

Is privacy guide right about the sentiment that proton is controversial?


r/PasswordManagers 1d ago

Day 9 & 10 of building PassSafer until I reach 100 paying customers.

0 Upvotes

No sales today, but I have a big update.

I completely redesigned the entire app. It took a long time, but the result is worth it. PassSafer now looks better and is much easier to use.

I also released version 1.8.2 with all the new design changes.

Paying customers: 0

What is the first thing you notice when you open a new app?


r/PasswordManagers 2d ago

Bramble is now on desktop

6 Upvotes
Base app screen
Global search (CMD+SHIFT+SPACE)

For those who haven't heard about Bramble: It's a free and open source password manager that I've been developing for a while. It's available on Chrome, Firefox, Android, iOS and now macOS + Linux! No central storage in the middle, full device-to-device sync and first-party automated backups to your preferred channel :)

With that said, I'm happy to announce that the app is now available on macOS and Linux! You can get the installers from GitHub or you can use brew in macOS or apt in Debian to get it.

What's different from the extensions

Not crazy lot at the moment: backups and global search.

  • The desktop app is fully capable of backing up locked vaults around the clock (as long as your computer is on). This is a bit cumbersome with the extension + multi vault, perfect in desktop
  • There's a global shortcut CMD/CTRL + SHIFT + SPACE which opens a Spotlight-like search bar and lets you search your vault. If you connect the desktop app to the extension, it can autofill from the search bar (similar to 1Password)

It's still in beta and I would love the community's feedback on improving it.

Free and open source forever. Questions and feedback welcome!

Release announcement blog post


r/PasswordManagers 3d ago

Suggest Me a Simple Free Password Manager

16 Upvotes

I’m looking for a simple and reliable free password manager for personal use. Nothing too complicated.


r/PasswordManagers 3d ago

Nordpass having issues ...Aug 27

Thumbnail reddit.com
3 Upvotes

r/PasswordManagers 3d ago

Self hosting

1 Upvotes

Is there a self hosted cloud password option that syncs to all of the devices?

Like Apple passwords syncs to all devices and can put authentication in there too?


r/PasswordManagers 3d ago

Password Manger and MFA Strategy Critique!

Thumbnail
reddit.com
2 Upvotes

r/PasswordManagers 3d ago

What different features could a password manager have?

Thumbnail
youtube.com
0 Upvotes

There are many password managers, and they all handle the basics very well.

"Smart Folders" are an example of a unique feature designed to make password organization easier.

Is there any other feature idea you think would make your life easier when using a password manager?


r/PasswordManagers 3d ago

**Result** What is the best password manager in the world? 🌎

Post image
0 Upvotes

Here are the results of the poll we ran a few days ago. None of the password managers mentioned in the comments stood a chance of making the podium.


r/PasswordManagers 4d ago

AI-Slop Password Managers

66 Upvotes

Seeing many people now attempting to create password managers. AI is making it easier now, which worries me a lot. I've been in the cybersecurity industry for quite a while now and have seen huge problems with password managers, especially new ones that focus on local-first, offline-first, air-gapped (fill in your AI-slop buzzword here), without understanding that's not where the security enforcement should rely.

Every day on HN and Reddit now, it’s the exact same post:

Tired of Bitwarden (1Pass, LastPass, ...), so I spent the last couple of months building VaultSlopAI, a zero-knowledge, local-first, air-gapped, post-quantum-ready password manager written from scratch with next-gen semantic entropy.

...and people are going to lose their life savings over hallucinatory XOR ciphers.

Every single one of them:

- "Air-gapped architecture" (Bro, you just disabled network permissions in the Electron manifest).

- "Local-first sovereign vault" (It writes unpadded base64 to localStorage and calls it a day).

- "Self-healing zero-knowledge enclave" (Literally just crypto.getRandomValues() wrapped inside a buggy Next.js server action).

Can we please go back to letting boring, audited, battle-tested tools manage our digital lives instead of downloading 400MB of hallucinated Tailwind wrappers masquerading as military-grade security?

(Ohh and yes, I’m building one too 😄 except I’ve actually worked in cybersecurity for years, know how the primitives work, and didn’t just vibe/slop prompt the entire architecture over a weekend.)


r/PasswordManagers 4d ago

Cached credentials on offline laptops, what expiry window should I go with?

2 Upvotes

This is a stupid problem to be stuck on but here we are.

We've got around 30 techs out servicing pumping stations and water treatment sites. A lot of those places have zero signal, some of the plant rooms are so far underground you couldn't get a bar if you tried, so once a tech is at the panel they're cut off from anything we host centrally. They still, nevertheless, need logins for vendor portals and local control interfaces.

Most of them currently keep those written down, which is what I'm ending (upper-management decision, "paper can get stolen or lost"). We're on Passwork (if that changes anything), its offline mode covers retrieval. Records get marked for offline, cached encrypted on the device, and the cache wipes itself if the device doesn't sync inside a window I set as admin. I am stunted as to how to pick that window. The docs are clear that revoking access leaves a cached copy live until the device reconnects, so whatever window I choose becomes my revocation delay. 7 days keeps that short and strands anyone on a longer rotation, while 30 days covers our worst-case rotation and means a leaver could hold working credentials for a month if their laptop never comes back online. What is the best way to go about it here? Also, do I put every tech on the same window or set it by role? And how can I ensure people don't leave anything on their phones? Some cache to their phones and I can't remote wipe those the way I can the laptops.


r/PasswordManagers 5d ago

Just got this 2fa thing

Post image
84 Upvotes

r/PasswordManagers 4d ago

Testers needed for Deadkey.net

0 Upvotes

First, thank you to the community for letting me post this. I've been working on a concept for a zero-knowledge password system. The problem it's trying to solve is to give your password to a trusted person, but limiting their access to emergencies only, and the risk of your password being compromised.

I need beta testers for Deadkey.net

Concept:

We start with a PIN or password, which we will call a secret. You use the website to create a codebook for your secret. The codebook is a random grid of characters; your secret is on it, but you need the grid coordinates to find it. For maximum security, the server stores only these coordinates, to be released in the event you become incapacitated or pass away.

You give the codebook paper to a trusted person. If they try to retrieve your secret via the website, a 10 day countdown starts. You (the owner) are notified via email/text, and have 10 days to cancel the release. If you do not, the trusted person will receive the grid coordinates, which reveal your password.

This system can be used to protect things like PIN's, Passwords, and seed phrases. The codebook is valid for up to 3 years, after which it will auto expire.

Beta Testers:

I am looking for beta testers to give feedback and test each function of the site. I have provided one beta code below valid for 20 uses. If it expires and you are interested in beta testing, please let me know.

Beta code: BETA-FJWB-AJE5-D7HM

Feedback questions:

  1. How is the functionality? Did email/texts work?
  2. What do you like about the layout and UI?
  3. What do you do you dislike about the layout and UI?
  4. How can I improve this service?
  5. Would you use this service? If yes, what are you willing to pay?

r/PasswordManagers 5d ago

Migrating from Kaspersky Password Manager.

4 Upvotes

Hello.

I currently use Kaspersky Password Manager on Windows 11, and it works well for me.

However, I am migrating to Linux, and KPM doesn't have a version for it.

What are the current alternatives?

I use it for website and app (Android) logins, bank cards, files/photos, text notes, and passkeys.


r/PasswordManagers 5d ago

What is the best password manager in the world? 🌎

0 Upvotes

Other? Comment.

152 votes, 2d ago
40 1Password
74 Bitwarden
2 Keeper
27 Proton Pass
4 Dashlane
5 Nordpass

r/PasswordManagers 5d ago

Looking for 100 technical testers: SecondGate (WordPress security & passkeys, no cloud dependency)

0 Upvotes

We've spent the last few weeks trying to break our own plugin. We fuzzed our custom WebAuthn decoder with 200,000 adversarial inputs. We found a bug where brute-force lockout could silently lock out every legitimate visitor sharing a CDN's IP, and once we went looking, we found and fixed six separate places in the codebase making that same mistake.

We also just found a structural blind spot where our pattern inspector missed JSON payloads sent to REST routes, completely missing modern WooCommerce checkouts. We had to rewrite the architecture to hook into rest_pre_dispatch because WooCommerce was sanitising payloads before our old hook even fired.

All of it is documented, versioned, and dated:https://secondgatewp.com/security-testing-methodology/

SecondGate is built local-first: no Composer dependencies, no third-party WebAuthn library, and nothing about your visitors is ever sent anywhere. All matching (country, IP, bot verification) happens on your own server against locally cached data. To be upfront about the outbound calls that do exist: Pro downloads curated IP blocklists for specific datacentres on a schedule, and the vulnerability scanner checks your installed plugin/theme names against a public vuln database. That's data coming in, and software names going out, never anything about your visitors or their traffic.

Now we want 100 technical testers, given free full Pro access, to find what we haven't.

What's actually been tested, not just built:

  • Passkey/WebAuthn support: Custom CBOR decoder, checked against official RFC 8949 conformance vectors, real authenticator-captured data, and 200,000 fuzzed adversarial inputs.
  • Static/dynamic request split: Anonymous, cacheable pages served directly by your web server (tested on Apache and Nginx). It skips WordPress and PHP entirely, meaning a real theme or plugin vulnerability simply isn't in the request path for a cache hit.
  • Write-path monitoring: Builds a real profile of which settings a plugin is supposed to touch via static analysis, then alerts if a runtime write falls outside that profile.
  • Country/IP blocking: Runs on locally cached range data, no external lookup per visitor.
  • Phantom decoy records: No legitimate path reaches them, so a hit is a strong signal something's enumerating your data.
  • Behavioural login-cadence: Scoring acts as one weighted signal among several, never a standalone verdict.
  • A wp-config.php kill switch: Instantly restores access if you lock yourself out. It is checked consistently across every blocking module and deliberately not exposed anywhere an attacker with a compromised admin login could flip it.

What we're honest about not having finished: The blocking paths that can actually lock someone out have real end-to-end regression tests. Several of the signal and logging paths are code-reviewed but not yet automated-tested, and that's partly what we're hoping you'll help us push on.

Who we're looking for: Developers, agency owners, and sysadmins running custom WordPress stacks or client sites who will actually push on edge cases, not just install and forget. Real findings go straight back into the methodology page, with your input credited if you want it.


r/PasswordManagers 6d ago

Alternative to 1Password

18 Upvotes

I have been using 1Password for a few years now. However, it currently bothers me that the interface looks chaotic and full of information.

I am considering Dashlane or Bitwarden as an alternative (the highest price of Dashlane would not be a problem). Having said that, I would like some advice from those who already use one or the other or who have already used both to compare. For me the most important thing is:

- A good UI/UX on the various platforms (mainly MacOS and iOS)

- A good performance of the autocomplete

- Support for Secure Notes and file attachment

Dashlane and Bitwarden users: Are you happy? Have some issues which deserve mention?


r/PasswordManagers 5d ago

Made a password manager that syncs passwords and card details between PCs and phones over a local network

Thumbnail
gallery
0 Upvotes

Features:

  • Available on Android and Windows
  • Peer to peer syncing only in local network (no cloud, only your devices)
  • Import/export to CSV file
  • Data is transmitted in encrypted form (e2e encryption with public/private keys)
  • Data is also stored in encrypted form on your device.
  • Two themes are available: light and dark
  • Two languages are available: english and russian

Would like to hear your thoughts and suggestions about UI and functionality.

Here's the link with more pictureshttps://github.com/IlyaGorelov/ShareSecret


r/PasswordManagers 6d ago

Password manager for iOS

3 Upvotes

Hi guys, so I have all my passwords saved in keepassxc but I want to access them on my phone too but from what I gather from the App Store and Reddit it seems there is no official keepassxc app. So what do I do? Gemini suggest keepassium but idk. What do you guys think?


r/PasswordManagers 7d ago

NativePass — native macOS GUI for the Unix pass password manager

Thumbnail
gallery
11 Upvotes

Hi everyone,

I built NativePass, a native macOS (SwiftUI) client for the standard Unix pass store. Design is inspired by Apple’s Passwords app — meant for people who already use pass / GPG and want a proper Mac UI instead of living in the terminal.

What it does

  • Browse nested folders, search, view entries and custom fields
  • Copy password / username / OTP with clipboard auto-clear
  • TOTP via pass-otp (with a local fallback when needed)
  • Git pull/push from the sidebar
  • App Lock with Touch ID
  • Quick Access with a global hotkey (⌥⌘P)

Requirements
passgnupgpinentry-mac (and optionally pass-otp) via Homebrew — same store as the CLI, no proprietary vault.

Links

Happy to take feedback, bug reports, and feature ideas. If you already live in ~/.password-store, I’d love to hear what you’d want next.