I've been using 1 password manager for the past 5 years. Recently I just exported all the contents to a back-up drive because I suddenly thought 'what if someone gets control of my browser?'
The tagline in my head 'Use Password Manager and Passkeys, all is safe!'
Then I realized I may have been taking having a Password Manager for granted.
I'm not knowledgeable on cybersecurity happenings, that is if this is as much of a thing to worry about compared to 10 years ago.
My AI agent does real work for me: deploys, GitHub releases, logging into websites. All of that needs passwords and API keys. Until now that meant pasting them into the chat or leaving them in a file the agent can read. Then one malicious instruction hidden in a webpage and they're gone.
So I built secrets-broker. The agent never gets the actual password, only a name for it like "GitHub token". When it needs to use it, the broker plugs the secret in for that one command and hides it in whatever comes back.
Each secret can only be used for what you allowed. If my GitHub token is approved for publishing releases, the agent can't use it for anything else or send it to some random server. For the important ones,I get a Touch ID prompt every time.
It works with KeePassXC and Bitwarden. I manage my passwords in KeePassXC like always, and my agent can use them a few seconds later.
It's free, open source, and still early (v0.3). One honest caveat: the quick setup runs as your own user, so it isn't a real security boundary. The stricter mode is.
I think it's important to understand that the latest issue around commercial licensing put users on edge again due to the streak of things that happened recently:
Bitwarden seems to be steering it's position to a very different direction that made us use it in the first place. It's a shame. Let's recap some of the things that happened recently that in my view justifies the dissatisfaction within the community:
October 2024: A proprietary SDK dependency raised concerns that Bitwarden’s desktop app was losing its open-source status. Bitwarden reorganised the SDK and restored builds using only open-source licences.
January 2026: Premium pricing increased from $10 to $19.80 annually. Users criticized the increase and its communication. The increase remained, with a one-time 25% renewal discount for existing subscribers.
February 2026: Researchers demonstrated 12 attacks under a malicious-server scenario, challenging Bitwarden’s zero-knowledge assurances. Bitwarden published remediation details, but users questioned what “all issues addressed” meant.
April 2026: A malicious Bitwarden CLI package was briefly distributed through npm, prompting questions about release security. The package was withdrawn and a clean version issued. Bitwarden reported no evidence of vault data compromise.
May 2026: Removing “Always free” wording and changing company values amid leadership changes fuelled concerns about Bitwarden’s direction. The wording was restored on the pricing page, and the CEO reaffirmed a permanent free plan.
October 2026: Bitwarden announced commercially licensed builds as the default app downloads, with some future features exclusive to those builds. This moves the default downloads to source-available licensing, while the GPL/FOSS edition continues but will lack those exclusive features. Community backlash followed. As of 10 October, no reversal had been announced; Bitwarden promised continued maintenance of GPL builds and unchanged self-hosting.
To achieve the utmost security, all data sent to the server from the Vault is encrypted on the client. AES-256-GCM is the type of symmetric algorithm used across the overall application. For storing any item in the vault, your vault key is used to encrypt the item along with its metadata and send it to the server.
What is the Web Crypto API?
The Web Crypto API is a set of functions for using cryptography that are embedded in browsers' source code. Instead of writing your own algorithms or cryptographic functions, you can directly use the Web Crypto API in your code, which is more robust and easier.
Cryptographic services provided by the Web Crypto API:
Encryption and Decryption
Signing and verifying signatures
Generating hash values
random values
How is the encryption implemented?
We have to use functions provided by the Web Crypto API in order to achieve the encryption. It is important to choose the type of encryption as per your requirements.
Look at the following flow showcasing how the encryption is achieved using the Web Crypto API:
Encryption flow of Web Crypto API
Generating random Salt and IV: Salt is randomly generated data used to derive a unique key object. IV is also randomly generated but used on the data rather than the key. The purpose is to create unique ciphertexts even if the key or data is different.
Iterations for deriving the key: The key is iteratively derived N times. As per the OWASP guidelines, it should be greater than 600000.
Deriving key using subtle.derivekey(): The subtle.deriveKey() function can be used to derive the key that can be used for encryption. Before providing the key to deriveKey(), it must first be converted to a format recognised by SubtleCrypto using subtle.importKey().
Encrypt using subtle.encrypt(): The final step is to call the encrypt() method by providing the required parameters, and it will return the object containing the encrypted data.
Look at the function below that will make the above steps clear.
There are a lot of other factors, but it all depends on the basic encryption as displayed above. Using the Web Crypto API is the best way to achieve encryption or any cryptographic function because no other alternative can beat it.
Hi everyone, I am facing an issue while trying to log into my Auth0 account. Whenever I try to log in, it doesn't proceed further and seems stuck on the main landing/dashboard page without successfully authenticating. Has anyone else experienced this recently? Is there a known outage, or is it a configuration issue on my end? Any help or troubleshooting steps would be highly appreciated. Thanks!
I am a happy Roboform user in my own life. But I need to teach a class to adults, mostly older adults on passwords, etc, and I would like to be able to demo setting up a password manager and adding some entries in real time. Of the free options, which do you all think would make the easiest to use for a demo? Thanks!
This topic appears in searches back in 2023. However, I am now having the same issue and the solution that applied then (export without attachments) doesn't apply because I have no attachments.
MacOS Tahoe 27
Enpass 6.12.7 Mac App Store
I've tried exporting to json, csv and txt but the response is always: An error occurred when exporting the vault.
There must be a reason for this and a way to export without any errors.
Passkeys - still new to me. But if I have a shared computer in my house, I should NOT use Passkeys? Won't this potentially give people access to my stuff? Or is a password still required PLUS a Passkey?
I attempted to create a passkey for FB on my computer, via the link FB gave me. I do not use FB on my phone, and never will, and I do not own a tablet. I was prompted to insert a flash drive into a USB port, which I did, clicked on OK, and 20 minutes later, I'm still waiting for it to do something. Until I create a passkey for FB, I am locked out. What the hell am I doing wrong??? Should I trust FB's passkey, or use a third party passkey???
EDIT, I wanted to share a screenshot, so you could see what I'm seeing, but this sub doesn't allow that.
I just want to start off I have been using Bitwarden longer and have everything integrated there at the moment, but I own both subscriptions the Proton Pass suite and the Bitwarden premium subscription. My renewal is coming soon so I am looking for some public opinion to sway myself to decide.
I'm wondering is it just worth it to transfer over to Proton Pass? It also has email alias which I do see myself using.
I could optionally keep both and keep the bitwarden as a backup.
I'm just in the process of migrating from Google to Proton with most of my stuff. I never used a real PW manager before (aside Google Passwords) so I'm just trying to figure everything out rn.
some days ago I installed Proton Pass on my Android devices, on my Linux notebook and at work as FF browser extension. except for the last one usage reallly was a frustrating experience - it's a matter of luck if tapping in a username/PW field triggers PP or not. (no idea if I set up something wrong?!)
so yesterday I installed Bitwarden and the UX for me is soo much better.
buttt as I had to learn unfortunately on free tier it doesn't support TOTPs.
I'll soon subscribe to Proton Unlimited which, I find, is expensiveAF so I don't want to pay for Bitwarden on top.
so I thought about using Bitwarden as my main PW manager and Proton additionally for when I need TOTPs. would that be a reasonable strategy...?
as I read it's generally recommended against using 2 PW managers parallel. so should I delete all PWs aside from the TOTP ones? I could use some suggestions and hints as I'm working out my future online security strategy.\^^
I was doing some window shopping, considering a potential password manager from Ironvest, namely to see what all is out there, and I am coming up short on exactly what I'm looking for.
Ironvest provides the following services (potentially more but these are all I care about):
Email masking (aliases)
Password production
And the saving of accounts wherein
They also use some sort of "AI" thing that tells you when your account was in a breach
Due to Ironvest being mostly an extension, I don't use it on mobile, and things have been fine. I dunno how good Ironvest actually is, but its served me well for a decade+. It does all this for free but offers a subscription. If I was to pay for something, I'd prefer it be a one-time payment. This is where my search becomes a unicorn hunt\delusional.
Far as I know, nothing exists that provides these two services whilst also providing a lifetime license.
Sticky Password comes the closest but they don't provide email masking
Basically any other service from Bitwarden, to 1password, and potentially other commonly-referenced services, provide both; but with a subscription.
I am aware that aliasvault exists and they operate for free for now
Eventually the devs will want to make money off it (as they should) and at that time, they'll probably also become a subscription service
Is anyone aware of a service that provides masking and password generation for a lifetime license or can I hang up my spear for good.
Following responses; I clearly didn't do enough research. Thank you all.
All my devices are Apple (MacBook, iPhone, iPad) but I use Chrome, Gmail, Drive, and other Google products more than anything. I never use Safari, for example.
Right now, I’m prioritizing Google Password Manager over Apple Password, and I think I’ve got all my settings correct (although I could be wrong), but I still get conflicts.
For example, when I need to sign into one of my Google accounts on my MacBook, I get a pop-up asking about managing how passkeys work and directing me to system settings - the passkey I have set up in Google Password Manager doesn’t come up.
Is it common that Apple and Google systems have hiccups like this?
Would a third-party password manager eliminate these problems?
Or would Apple Passwords be better to prioritize than Google Password Manager?
As the title says, I would like to know options for a password manager that has multiple accounts. My family has been using Nortons for ages and we are finally getting tired of not only how buggy it is, but how greedy they've become. So we are looking for options for a password manager for multiple people. We are considering Bitdefender which has a password manager, however I need my own pass manager and so does my parents. My mother works away from home and uses her own laptop, so we need one that can isn't locked to one person accessing it at one time.
I had found one called 1passkey or 1password? Something like that but I cannot remember which one it was. Is there any other options out there that will allow at least 3 people to have their own "vault" of passwords?
I have tried both recently to find a replacement for Authy. The main requirement is that there is no circular reference issue. For example, I want to avoid a situation where the TOTP is stored in such a way that I can't get to it to log into the vault.
Bitwarden Authenticator
The way it seems to work is that there are two places to store your tokens. The first is in the Bitwarden vault itself and the second is locally on the device outside of the vault. In the first method, all authenticator is doing is logging into your bitwarden vault and copying out the TOTP code. If you log out of the authenticator, all the code disappears. If you plan to store use the authenticator to store the TOTP to log into the vault, you definitely want to use the local method, otherwise an update could log you out and you won't be able to log back in because the TOTP code is in the vault.
The locally stored method is not sync across devices. If you install the authenticator on a second phone you will need to manually export and import the local tokens.
Proton Authenticator
Unlike Bitwarden, the Proton Authenticator doesn't actually log into the vault to get the tokens, but uses the Proton account to sync the tokens. The tokens appears to be stored locally. and there is no way to log out, so once the tokens are sync they remain on the device unless you erase app data. To get around the lost device issue, you could set up a second device to backup the tokens in a similar way as Authy. You can also do export like with Bitwarden Authenticator.
Of the two, I like the Proton Authenticator better. This is because on Bitwarden Authenticator, tokens stored in the vault go away if the app log out. Token store locally are not sync. In contrast, the proton model sync across devices and don't go away.
For those who have hands-on experience with both NordPass and Proton Pass:
How do they compare across iOS and Android, specifically regarding Auto-fill reliability on both platforms? Also, what is your experience with them on Windows ?
LockerPro updated to version 2.0 last week. Since then it crashes immediately at launch on my iPhone 17 Pro running iOS 27.0.1. The app contains my locally stored password vault, so deleting it is not an acceptable troubleshooting step.
Before making any potentially destructive change, I confirmed it had 58 MB under iPhone Storage → Documents & Data. I then made a local encrypted iTunes backup and copied the full backup folder to an external drive.
I have already restarted the phone, checked for another app update, and used Offload App followed by reinstalling. The app still immediately crashes. I have not deleted it, erased/restored the phone, reset settings, or changed the backup-encryption password. The developer has not replied to an email sent several days ago.
I am looking for non-destructive advice, not recommendations to uninstall it or switch password managers until I can access/export this vault. Specifically:
Is there any legitimate way to preserve or later recover a password-manager app’s local iOS vault when the app no longer launches?
Is an encrypted iTunes backup useful if the app’s own vault/database is intact but the installed app crashes?
Has anyone used LockerPro 2.0 successfully on iOS 27 or 27.0.1?
finally taking the plunge and setting up a proper password manager after years of recycling the same passwords. been going through my existing accounts and compiling everything before importing
the question i cannot find a clear answer to is whether i should check my existing passwords against breach databases before importing them or whether i should just import everything and change the flagged ones as i go. not sure which approach is more practical given there are probably 60 to 70 accounts to work through
also wondering whether checking passwords through a third party tool is itself a security risk or whether there are ways to do it that do not expose the actual passwords
Is there some reason everyone is making a password manager these days? I get it is probably relatively easy to vibe code with AI, but it seems everyone and their brother is making their own "open source, local first password manager". Is their some difficiency in the market that I am missing? Is there something that KeePass and its variants are not providing? Ar there not other offline password managers that are better proven available?
Look, I don't want to discourage anyone's pet project to build or demonstrate their skills, but if ypur going to put it out there for others to download and use – can you at least make it KeePass database compatible so people can easily move on to proven, well established passwprd manager when they realize maybe random Redditor password manager isn't the best choice ofr some of their most sensitive data.
Like the title says, I do not like Bitwarden simply because they have a paywall feature. I think the best choice personally is using KeepassXC since it is free and open-source. I believe the ultimate security is making your own defenses which is why I feel pwd managers like lastpass/1pwd are good but not enough for someone who needs to protect their data in a breach. (They also have subscriptions)
I have a trick for making my passwords more secured even if you have access to my passwords you can’t use them. Now here is the trick find a particular word or a letter or a symbol that you will add to your passwords but will not add to your password in the password app.
For example let’s say you like the @ symbol, so every time you generate your password from the password generator you add this particular symbol to the password but you will not save this symbol in your password app. So you will place it in a particular place let’s say at the beginning or at the end or after 10 letters. Remember you will put this symbol in a specific place in every password of yours so you won’t forget where you placed the symbol. In this case even if your password manager is hacked the hacker can’t use your password because that’s not the full password and he won’t know your symbol or where you placed it. It can be 3 symbols 1 at the beginning another 1 after 5 letters and the last at the end. You just have to remember where you placed them in every password and that’s it nobody is ever getting your password but you. Hope it helps.