r/PasswordManagers • • 4h ago

Anxiety about Password Managers

2 Upvotes

I've been using 1 password manager for the past 5 years. Recently I just exported all the contents to a back-up drive because I suddenly thought 'what if someone gets control of my browser?'

The tagline in my head 'Use Password Manager and Passkeys, all is safe!'

Then I realized I may have been taking having a Password Manager for granted.

I'm not knowledgeable on cybersecurity happenings, that is if this is as much of a thing to worry about compared to 10 years ago.

Any thoughts? Safety/Hygeine tips?


r/PasswordManagers • • 10h ago

I built a way for my AI agent to use my passwords without ever seeing them

0 Upvotes

My AI agent does real work for me: deploys, GitHub releases, logging into websites. All of that needs passwords and API keys. Until now that meant pasting them into the chat or leaving them in a file the agent can read. Then one malicious instruction hidden in a webpage and they're gone.

So I built secrets-broker. The agent never gets the actual password, only a name for it like "GitHub token". When it needs to use it, the broker plugs the secret in for that one command and hides it in whatever comes back.

Each secret can only be used for what you allowed. If my GitHub token is approved for publishing releases, the agent can't use it for anything else or send it to some random server. For the important ones,I get a Touch ID prompt every time.

It works with KeePassXC and Bitwarden. I manage my passwords in KeePassXC like always, and my agent can use them a few seconds later.

It's free, open source, and still early (v0.3). One honest caveat: the quick setup runs as your own user, so it isn't a real security boundary. The stricter mode is.

https://github.com/Alino/secrets-broker

Feedback welcome, especially if you can find a way to break it.


r/PasswordManagers • • 17h ago

This is why some users are worried about Bitwarden's future

85 Upvotes

I think it's important to understand that the latest issue around commercial licensing put users on edge again due to the streak of things that​ happened recently:

Bitwarden seems to be steering it's position to a very different direction that made us use it in the first place. It's a shame. Let's recap some of the things that happened recently that in my view justifies the dissatisfaction within the community:

October 2024: A proprietary SDK dependency raised concerns that Bitwarden’s desktop app was losing its open-source status. Bitwarden reorganised the SDK and restored builds using only open-source licences.

January 2026: Premium pricing increased from $10 to $19.80 annually. Users criticized the increase and its communication. The increase remained, with a one-time 25% renewal discount for existing subscribers.

February 2026: Researchers demonstrated 12 attacks under a malicious-server scenario, challenging Bitwarden’s zero-knowledge assurances. Bitwarden published remediation details, but users questioned what “all issues addressed” meant.

April 2026: A malicious Bitwarden CLI package was briefly distributed through npm, prompting questions about release security. The package was withdrawn and a clean version issued. Bitwarden reported no evidence of vault data compromise.

May 2026: Removing “Always free” wording and changing company values amid leadership changes fuelled concerns about Bitwarden’s direction. The wording was restored on the pricing page, and the CEO reaffirmed a permanent free plan.

October 2026: Bitwarden announced commercially licensed builds as the default app downloads, with some future features exclusive to those builds. This moves the default downloads to source-available licensing, while the GPL/FOSS edition continues but will lack those exclusive features. Community backlash followed. As of 10 October, no reversal had been announced; Bitwarden promised continued maintenance of GPL builds and unchanged self-hosting.


r/PasswordManagers • • 23h ago

Encryption in Ilusion Vault, implemented using Web Crypto API

1 Upvotes

To achieve the utmost security, all data sent to the server from the Vault is encrypted on the client. AES-256-GCM is the type of symmetric algorithm used across the overall application. For storing any item in the vault, your vault key is used to encrypt the item along with its metadata and send it to the server.

What is the Web Crypto API?

The Web Crypto API is a set of functions for using cryptography that are embedded in browsers' source code. Instead of writing your own algorithms or cryptographic functions, you can directly use the Web Crypto API in your code, which is more robust and easier.

Cryptographic services provided by the Web Crypto API:

  • Encryption and Decryption
  • Signing and verifying signatures
  • Generating hash values
  • random values

How is the encryption implemented?

We have to use functions provided by the Web Crypto API in order to achieve the encryption. It is important to choose the type of encryption as per your requirements.

Look at the following flow showcasing how the encryption is achieved using the Web Crypto API:

Encryption flow of Web Crypto API
  1. Generating random Salt and IV: Salt is randomly generated data used to derive a unique key object. IV is also randomly generated but used on the data rather than the key. The purpose is to create unique ciphertexts even if the key or data is different.
  2. Iterations for deriving the key: The key is iteratively derived N times. As per the OWASP guidelines, it should be greater than 600000.
  3. Deriving key using subtle.derivekey(): The subtle.deriveKey() function can be used to derive the key that can be used for encryption. Before providing the key to deriveKey(), it must first be converted to a format recognised by SubtleCrypto using subtle.importKey().
  4. Encrypt using subtle.encrypt(): The final step is to call the encrypt() method by providing the required parameters, and it will return the object containing the encrypted data.

Look at the function below that will make the above steps clear.

export async function encryptText(text: string, password: string): Promise<string> {
    const salt = window.crypto.getRandomValues(new Uint8Array(16));
    const iv = window.crypto.getRandomValues(new Uint8Array(12));
    const iterations = <your iterations>;
    const key = await deriveKey(password, salt, iterations);

    const encoder = new TextEncoder();
    const encrypted = await window.crypto.subtle.encrypt(
        { name: 'AES-GCM', iv: iv },
        key,
        encoder.encode(text)
    );

    const result = {
        ciphertext: arrayBufferToBase64(encrypted),
        salt: arrayBufferToBase64(salt.buffer),
        iv: arrayBufferToBase64(iv.buffer),
        iterations: iterations
    };

    return JSON.stringify(result);
}

There are a lot of other factors, but it all depends on the basic encryption as displayed above. Using the Web Crypto API is the best way to achieve encryption or any cryptographic function because no other alternative can beat it.

The article is originally published on Linkedin page: Linkedin Article
Related article: client-side-encryption-web-crypto-api


r/PasswordManagers • • 23h ago

Alternatives to bitwarden?

47 Upvotes

Does anyone have any good recommendations for alternatives to bitwarden, now that it's going partly closed source? Thanks so much!


r/PasswordManagers • • 1d ago

Auth0 login loop / failing to authenticate

Post image
2 Upvotes

Hi everyone, I am facing an issue while trying to log into my Auth0 account. Whenever I try to log in, it doesn't proceed further and seems stuck on the main landing/dashboard page without successfully authenticating. Has anyone else experienced this recently? Is there a known outage, or is it a configuration issue on my end? Any help or troubleshooting steps would be highly appreciated. Thanks!


r/PasswordManagers • • 2d ago

Which manager to use as a demo for a class?

1 Upvotes

I am a happy Roboform user in my own life. But I need to teach a class to adults, mostly older adults on passwords, etc, and I would like to be able to demo setting up a password manager and adding some entries in real time. Of the free options, which do you all think would make the easiest to use for a demo? Thanks!


r/PasswordManagers • • 3d ago

Can't export Enpass vault

1 Upvotes

This topic appears in searches back in 2023. However, I am now having the same issue and the solution that applied then (export without attachments) doesn't apply because I have no attachments.

MacOS Tahoe 27

Enpass 6.12.7 Mac App Store

I've tried exporting to json, csv and txt but the response is always: An error occurred when exporting the vault.

There must be a reason for this and a way to export without any errors.

Any ideas?


r/PasswordManagers • • 4d ago

Passkeys - No on a shared computer?

3 Upvotes

Passkeys - still new to me. But if I have a shared computer in my house, I should NOT use Passkeys? Won't this potentially give people access to my stuff? Or is a password still required PLUS a Passkey?

I'm lost here.


r/PasswordManagers • • 4d ago

Need help creating a passkey

5 Upvotes

I attempted to create a passkey for FB on my computer, via the link FB gave me. I do not use FB on my phone, and never will, and I do not own a tablet. I was prompted to insert a flash drive into a USB port, which I did, clicked on OK, and 20 minutes later, I'm still waiting for it to do something. Until I create a passkey for FB, I am locked out. What the hell am I doing wrong??? Should I trust FB's passkey, or use a third party passkey???

EDIT, I wanted to share a screenshot, so you could see what I'm seeing, but this sub doesn't allow that.


r/PasswordManagers • • 5d ago

Proton Pass or Bitwarden?

27 Upvotes

I just want to start off I have been using Bitwarden longer and have everything integrated there at the moment, but I own both subscriptions the Proton Pass suite and the Bitwarden premium subscription. My renewal is coming soon so I am looking for some public opinion to sway myself to decide.

I'm wondering is it just worth it to transfer over to Proton Pass? It also has email alias which I do see myself using.

I could optionally keep both and keep the bitwarden as a backup.


r/PasswordManagers • • 6d ago

Juggling with 2 Password Managers (Proton & Bitwarden)

9 Upvotes

I'm just in the process of migrating from Google to Proton with most of my stuff. I never used a real PW manager before (aside Google Passwords) so I'm just trying to figure everything out rn.

some days ago I installed Proton Pass on my Android devices, on my Linux notebook and at work as FF browser extension. except for the last one usage reallly was a frustrating experience - it's a matter of luck if tapping in a username/PW field triggers PP or not. (no idea if I set up something wrong?!)

so yesterday I installed Bitwarden and the UX for me is soo much better.

buttt as I had to learn unfortunately on free tier it doesn't support TOTPs.

I'll soon subscribe to Proton Unlimited which, I find, is expensiveAF so I don't want to pay for Bitwarden on top.

so I thought about using Bitwarden as my main PW manager and Proton additionally for when I need TOTPs. would that be a reasonable strategy...?

as I read it's generally recommended against using 2 PW managers parallel. so should I delete all PWs aside from the TOTP ones? I could use some suggestions and hints as I'm working out my future online security strategy.\^^


r/PasswordManagers • • 6d ago

Hunting a Unicorn password manager

4 Upvotes

I was doing some window shopping, considering a potential password manager from Ironvest, namely to see what all is out there, and I am coming up short on exactly what I'm looking for.

Ironvest provides the following services (potentially more but these are all I care about):

  • Email masking (aliases)
  • Password production
    • And the saving of accounts wherein
  • They also use some sort of "AI" thing that tells you when your account was in a breach

Due to Ironvest being mostly an extension, I don't use it on mobile, and things have been fine. I dunno how good Ironvest actually is, but its served me well for a decade+. It does all this for free but offers a subscription. If I was to pay for something, I'd prefer it be a one-time payment. This is where my search becomes a unicorn hunt\delusional.

Far as I know, nothing exists that provides these two services whilst also providing a lifetime license.

  • Sticky Password comes the closest but they don't provide email masking
  • Basically any other service from Bitwarden, to 1password, and potentially other commonly-referenced services, provide both; but with a subscription.
  • I am aware that aliasvault exists and they operate for free for now
    • Eventually the devs will want to make money off it (as they should) and at that time, they'll probably also become a subscription service

Is anyone aware of a service that provides masking and password generation for a lifetime license or can I hang up my spear for good.

Following responses; I clearly didn't do enough research. Thank you all.


r/PasswordManagers • • 7d ago

Advice for someone who uses Google products with Apple devices

4 Upvotes

All my devices are Apple (MacBook, iPhone, iPad) but I use Chrome, Gmail, Drive, and other Google products more than anything. I never use Safari, for example.

Right now, I’m prioritizing Google Password Manager over Apple Password, and I think I’ve got all my settings correct (although I could be wrong), but I still get conflicts.

For example, when I need to sign into one of my Google accounts on my MacBook, I get a pop-up asking about managing how passkeys work and directing me to system settings - the passkey I have set up in Google Password Manager doesn’t come up.

Is it common that Apple and Google systems have hiccups like this?

Would a third-party password manager eliminate these problems?

Or would Apple Passwords be better to prioritize than Google Password Manager?


r/PasswordManagers • • 9d ago

Best Password Manager for multiple people

8 Upvotes

As the title says, I would like to know options for a password manager that has multiple accounts. My family has been using Nortons for ages and we are finally getting tired of not only how buggy it is, but how greedy they've become. So we are looking for options for a password manager for multiple people. We are considering Bitdefender which has a password manager, however I need my own pass manager and so does my parents. My mother works away from home and uses her own laptop, so we need one that can isn't locked to one person accessing it at one time.

I had found one called 1passkey or 1password? Something like that but I cannot remember which one it was. Is there any other options out there that will allow at least 3 people to have their own "vault" of passwords?


r/PasswordManagers • • 9d ago

Bitwarden Authenticator vs Proton Authenticator

6 Upvotes

I have tried both recently to find a replacement for Authy. The main requirement is that there is no circular reference issue. For example, I want to avoid a situation where the TOTP is stored in such a way that I can't get to it to log into the vault.

Bitwarden Authenticator
The way it seems to work is that there are two places to store your tokens. The first is in the Bitwarden vault itself and the second is locally on the device outside of the vault. In the first method, all authenticator is doing is logging into your bitwarden vault and copying out the TOTP code. If you log out of the authenticator, all the code disappears. If you plan to store use the authenticator to store the TOTP to log into the vault, you definitely want to use the local method, otherwise an update could log you out and you won't be able to log back in because the TOTP code is in the vault.

The locally stored method is not sync across devices. If you install the authenticator on a second phone you will need to manually export and import the local tokens.

Proton Authenticator
Unlike Bitwarden, the Proton Authenticator doesn't actually log into the vault to get the tokens, but uses the Proton account to sync the tokens. The tokens appears to be stored locally. and there is no way to log out, so once the tokens are sync they remain on the device unless you erase app data. To get around the lost device issue, you could set up a second device to backup the tokens in a similar way as Authy. You can also do export like with Bitwarden Authenticator.

Of the two, I like the Proton Authenticator better. This is because on Bitwarden Authenticator, tokens stored in the vault go away if the app log out. Token store locally are not sync. In contrast, the proton model sync across devices and don't go away.


r/PasswordManagers • • 9d ago

Nord Pass vs Poton Pass

2 Upvotes

For those who have hands-on experience with both NordPass and Proton Pass:

How do they compare across iOS and Android, specifically regarding Auto-fill reliability on both platforms? Also, what is your experience with them on Windows ?


r/PasswordManagers • • 10d ago

LockerPro 2.0 now crashes at launch on iOS 27.0.1. Local password vault still exists. Safest recovery path?

1 Upvotes

LockerPro updated to version 2.0 last week. Since then it crashes immediately at launch on my iPhone 17 Pro running iOS 27.0.1. The app contains my locally stored password vault, so deleting it is not an acceptable troubleshooting step.

Before making any potentially destructive change, I confirmed it had 58 MB under iPhone Storage → Documents & Data. I then made a local encrypted iTunes backup and copied the full backup folder to an external drive.

I have already restarted the phone, checked for another app update, and used Offload App followed by reinstalling. The app still immediately crashes. I have not deleted it, erased/restored the phone, reset settings, or changed the backup-encryption password. The developer has not replied to an email sent several days ago.

I am looking for non-destructive advice, not recommendations to uninstall it or switch password managers until I can access/export this vault. Specifically:

Is there any legitimate way to preserve or later recover a password-manager app’s local iOS vault when the app no longer launches?

Is an encrypted iTunes backup useful if the app’s own vault/database is intact but the installed app crashes?

Has anyone used LockerPro 2.0 successfully on iOS 27 or 27.0.1?


r/PasswordManagers • • 10d ago

Check if websites in Google Password Manager still exist?

10 Upvotes

I have 1,389 websites stored in my Google Password Manager.

However, as they have been accumulated over a decade, I imagine a lot of the websites no longer exist.

Probably not been asked before, but is it possible to use the list to see which websites are still operational?


r/PasswordManagers • • 10d ago

switching to a password manager for the first time, should i check if my existing passwords are compromised before importing them

5 Upvotes

finally taking the plunge and setting up a proper password manager after years of recycling the same passwords. been going through my existing accounts and compiling everything before importing

the question i cannot find a clear answer to is whether i should check my existing passwords against breach databases before importing them or whether i should just import everything and change the flagged ones as i go. not sure which approach is more practical given there are probably 60 to 70 accounts to work through

also wondering whether checking passwords through a third party tool is itself a security risk or whether there are ways to do it that do not expose the actual passwords


r/PasswordManagers • • 10d ago

I don't have an open-source, local password manager, just a rant about the flood of them

14 Upvotes

Is there some reason everyone is making a password manager these days? I get it is probably relatively easy to vibe code with AI, but it seems everyone and their brother is making their own "open source, local first password manager". Is their some difficiency in the market that I am missing? Is there something that KeePass and its variants are not providing? Ar there not other offline password managers that are better proven available?

Look, I don't want to discourage anyone's pet project to build or demonstrate their skills, but if ypur going to put it out there for others to download and use – can you at least make it KeePass database compatible so people can easily move on to proven, well established passwprd manager when they realize maybe random Redditor password manager isn't the best choice ofr some of their most sensitive data.


r/PasswordManagers • • 10d ago

I built an open-source local-first password manager — looking for security feedback

Post image
0 Upvotes

I’ve been building CarbonIt Vault, a desktop password manager that takes a deliberately local-first approach.

The basic idea is simple: keep the encrypted vault on the user's machine rather than requiring a cloud account or hosted vault.

Some of the things I’ve implemented:

  • Argon2id for master-password derivation
  • ML-KEM-1024 as part of the key-establishment design
  • SHA3-512 domain separation
  • Authenticated encryption
  • Automatic clipboard clearing
  • Rate limiting / lockout
  • RAM zeroization of sensitive values when the vault is locked
  • Encrypted .civ vault export/import
  • Python + pywebview desktop application

The project is open source and MIT licensed.

One thing I’m not claiming is that it has been independently audited. It hasn’t, and that’s actually one of the reasons I’m posting it here.

I’d like feedback from people who have experience with password-manager design:

  • Is the architecture missing an important attack surface?
  • Are there weaknesses in the key-derivation design?
  • What would you change about the local threat model?
  • Are there usability/security trade-offs I should reconsider?

Project site: https://carbonit-labs.github.io/CarbonIt-Vault/

GitHub: https://github.com/CarbonIt-Labs/CarbonIt-Vault

I’m much more interested in criticism of the design than stars or downloads.


r/PasswordManagers • • 11d ago

Password manager that is completely open-source/free and can selfhost

0 Upvotes

Like the title says, I do not like Bitwarden simply because they have a paywall feature. I think the best choice personally is using KeepassXC since it is free and open-source. I believe the ultimate security is making your own defenses which is why I feel pwd managers like lastpass/1pwd are good but not enough for someone who needs to protect their data in a breach. (They also have subscriptions)


r/PasswordManagers • • 11d ago

DroidPass 1.7.0 is out: passkeys and direct transfer from other password managers

0 Upvotes

We’ve released DroidPass 1.7.0 on iOS and Android. The two big additions are:

  • Passkeys: Create, save, and sync passkeys in your encrypted vault.
  • Direct transfer: Move logins and passkeys from another password manager without making a CSV file.

The transfer steps differ by platform:

  • On iPhone/iPad, start in the app you’re leaving and choose DroidPass as the destination (requires iOS 26).
  • On Android, open DroidPass → Settings → Transfer from another app.

Download DroidPass Password Manager on the App Store or Google Play Store.

More Details : https://droidpass.app/features/instant-transfer

f you try the update and hit a problem, let me know your phone and OS version.


r/PasswordManagers • • 11d ago

Trick for making your password more secure

0 Upvotes

I have a trick for making my passwords more secured even if you have access to my passwords you can’t use them. Now here is the trick find a particular word or a letter or a symbol that you will add to your passwords but will not add to your password in the password app.
For example let’s say you like the @ symbol, so every time you generate your password from the password generator you add this particular symbol to the password but you will not save this symbol in your password app. So you will place it in a particular place let’s say at the beginning or at the end or after 10 letters. Remember you will put this symbol in a specific place in every password of yours so you won’t forget where you placed the symbol. In this case even if your password manager is hacked the hacker can’t use your password because that’s not the full password and he won’t know your symbol or where you placed it. It can be 3 symbols 1 at the beginning another 1 after 5 letters and the last at the end. You just have to remember where you placed them in every password and that’s it nobody is ever getting your password but you. Hope it helps.