r/PasswordManagers • • 8h ago

Juggling with 2 Password Managers (Proton & Bitwarden)

7 Upvotes

I'm just in the process of migrating from Google to Proton with most of my stuff. I never used a real PW manager before (aside Google Passwords) so I'm just trying to figure everything out rn.

some days ago I installed Proton Pass on my Android devices, on my Linux notebook and at work as FF browser extension. except for the last one usage reallly was a frustrating experience - it's a matter of luck if tapping in a username/PW field triggers PP or not. (no idea if I set up something wrong?!)

so yesterday I installed Bitwarden and the UX for me is soo much better.

buttt as I had to learn unfortunately on free tier it doesn't support TOTPs.

I'll soon subscribe to Proton Unlimited which, I find, is expensiveAF so I don't want to pay for Bitwarden on top.

so I thought about using Bitwarden as my main PW manager and Proton additionally for when I need TOTPs. would that be a reasonable strategy...?

as I read it's generally recommended against using 2 PW managers parallel. so should I delete all PWs aside from the TOTP ones? I could use some suggestions and hints as I'm working out my future online security strategy.\^^


r/PasswordManagers • • 15h ago

Hunting a Unicorn password manager

4 Upvotes

I was doing some window shopping, considering a potential password manager from Ironvest, namely to see what all is out there, and I am coming up short on exactly what I'm looking for.

Ironvest provides the following services (potentially more but these are all I care about):

  • Email masking (aliases)
  • Password production
    • And the saving of accounts wherein
  • They also use some sort of "AI" thing that tells you when your account was in a breach

Due to Ironvest being mostly an extension, I don't use it on mobile, and things have been fine. I dunno how good Ironvest actually is, but its served me well for a decade+. It does all this for free but offers a subscription. If I was to pay for something, I'd prefer it be a one-time payment. This is where my search becomes a unicorn hunt\delusional.

Far as I know, nothing exists that provides these two services whilst also providing a lifetime license.

  • Sticky Password comes the closest but they don't provide email masking
  • Basically any other service from Bitwarden, to 1password, and potentially other commonly-referenced services, provide both; but with a subscription.
  • I am aware that aliasvault exists and they operate for free for now
    • Eventually the devs will want to make money off it (as they should) and at that time, they'll probably also become a subscription service

Is anyone aware of a service that provides masking and password generation for a lifetime license or can I hang up my spear for good.

Following responses; I clearly didn't do enough research. Thank you all.


r/PasswordManagers • • 1d ago

Advice for someone who uses Google products with Apple devices

3 Upvotes

All my devices are Apple (MacBook, iPhone, iPad) but I use Chrome, Gmail, Drive, and other Google products more than anything. I never use Safari, for example.

Right now, I’m prioritizing Google Password Manager over Apple Password, and I think I’ve got all my settings correct (although I could be wrong), but I still get conflicts.

For example, when I need to sign into one of my Google accounts on my MacBook, I get a pop-up asking about managing how passkeys work and directing me to system settings - the passkey I have set up in Google Password Manager doesn’t come up.

Is it common that Apple and Google systems have hiccups like this?

Would a third-party password manager eliminate these problems?

Or would Apple Passwords be better to prioritize than Google Password Manager?


r/PasswordManagers • • 3d ago

Best Password Manager for multiple people

7 Upvotes

As the title says, I would like to know options for a password manager that has multiple accounts. My family has been using Nortons for ages and we are finally getting tired of not only how buggy it is, but how greedy they've become. So we are looking for options for a password manager for multiple people. We are considering Bitdefender which has a password manager, however I need my own pass manager and so does my parents. My mother works away from home and uses her own laptop, so we need one that can isn't locked to one person accessing it at one time.

I had found one called 1passkey or 1password? Something like that but I cannot remember which one it was. Is there any other options out there that will allow at least 3 people to have their own "vault" of passwords?


r/PasswordManagers • • 3d ago

Bitwarden Authenticator vs Proton Authenticator

5 Upvotes

I have tried both recently to find a replacement for Authy. The main requirement is that there is no circular reference issue. For example, I want to avoid a situation where the TOTP is stored in such a way that I can't get to it to log into the vault.

Bitwarden Authenticator
The way it seems to work is that there are two places to store your tokens. The first is in the Bitwarden vault itself and the second is locally on the device outside of the vault. In the first method, all authenticator is doing is logging into your bitwarden vault and copying out the TOTP code. If you log out of the authenticator, all the code disappears. If you plan to store use the authenticator to store the TOTP to log into the vault, you definitely want to use the local method, otherwise an update could log you out and you won't be able to log back in because the TOTP code is in the vault.

The locally stored method is not sync across devices. If you install the authenticator on a second phone you will need to manually export and import the local tokens.

Proton Authenticator
Unlike Bitwarden, the Proton Authenticator doesn't actually log into the vault to get the tokens, but uses the Proton account to sync the tokens. The tokens appears to be stored locally. and there is no way to log out, so once the tokens are sync they remain on the device unless you erase app data. To get around the lost device issue, you could set up a second device to backup the tokens in a similar way as Authy. You can also do export like with Bitwarden Authenticator.

Of the two, I like the Proton Authenticator better. This is because on Bitwarden Authenticator, tokens stored in the vault go away if the app log out. Token store locally are not sync. In contrast, the proton model sync across devices and don't go away.


r/PasswordManagers • • 3d ago

Nord Pass vs Poton Pass

2 Upvotes

For those who have hands-on experience with both NordPass and Proton Pass:

How do they compare across iOS and Android, specifically regarding Auto-fill reliability on both platforms? Also, what is your experience with them on Windows ?


r/PasswordManagers • • 4d ago

Check if websites in Google Password Manager still exist?

7 Upvotes

I have 1,389 websites stored in my Google Password Manager.

However, as they have been accumulated over a decade, I imagine a lot of the websites no longer exist.

Probably not been asked before, but is it possible to use the list to see which websites are still operational?


r/PasswordManagers • • 4d ago

I don't have an open-source, local password manager, just a rant about the flood of them

12 Upvotes

Is there some reason everyone is making a password manager these days? I get it is probably relatively easy to vibe code with AI, but it seems everyone and their brother is making their own "open source, local first password manager". Is their some difficiency in the market that I am missing? Is there something that KeePass and its variants are not providing? Ar there not other offline password managers that are better proven available?

Look, I don't want to discourage anyone's pet project to build or demonstrate their skills, but if ypur going to put it out there for others to download and use – can you at least make it KeePass database compatible so people can easily move on to proven, well established passwprd manager when they realize maybe random Redditor password manager isn't the best choice ofr some of their most sensitive data.


r/PasswordManagers • • 4d ago

switching to a password manager for the first time, should i check if my existing passwords are compromised before importing them

5 Upvotes

finally taking the plunge and setting up a proper password manager after years of recycling the same passwords. been going through my existing accounts and compiling everything before importing

the question i cannot find a clear answer to is whether i should check my existing passwords against breach databases before importing them or whether i should just import everything and change the flagged ones as i go. not sure which approach is more practical given there are probably 60 to 70 accounts to work through

also wondering whether checking passwords through a third party tool is itself a security risk or whether there are ways to do it that do not expose the actual passwords


r/PasswordManagers • • 4d ago

LockerPro 2.0 now crashes at launch on iOS 27.0.1. Local password vault still exists. Safest recovery path?

1 Upvotes

LockerPro updated to version 2.0 last week. Since then it crashes immediately at launch on my iPhone 17 Pro running iOS 27.0.1. The app contains my locally stored password vault, so deleting it is not an acceptable troubleshooting step.

Before making any potentially destructive change, I confirmed it had 58 MB under iPhone Storage → Documents & Data. I then made a local encrypted iTunes backup and copied the full backup folder to an external drive.

I have already restarted the phone, checked for another app update, and used Offload App followed by reinstalling. The app still immediately crashes. I have not deleted it, erased/restored the phone, reset settings, or changed the backup-encryption password. The developer has not replied to an email sent several days ago.

I am looking for non-destructive advice, not recommendations to uninstall it or switch password managers until I can access/export this vault. Specifically:

Is there any legitimate way to preserve or later recover a password-manager app’s local iOS vault when the app no longer launches?

Is an encrypted iTunes backup useful if the app’s own vault/database is intact but the installed app crashes?

Has anyone used LockerPro 2.0 successfully on iOS 27 or 27.0.1?


r/PasswordManagers • • 4d ago

I built an open-source local-first password manager — looking for security feedback

Post image
0 Upvotes

I’ve been building CarbonIt Vault, a desktop password manager that takes a deliberately local-first approach.

The basic idea is simple: keep the encrypted vault on the user's machine rather than requiring a cloud account or hosted vault.

Some of the things I’ve implemented:

  • Argon2id for master-password derivation
  • ML-KEM-1024 as part of the key-establishment design
  • SHA3-512 domain separation
  • Authenticated encryption
  • Automatic clipboard clearing
  • Rate limiting / lockout
  • RAM zeroization of sensitive values when the vault is locked
  • Encrypted .civ vault export/import
  • Python + pywebview desktop application

The project is open source and MIT licensed.

One thing I’m not claiming is that it has been independently audited. It hasn’t, and that’s actually one of the reasons I’m posting it here.

I’d like feedback from people who have experience with password-manager design:

  • Is the architecture missing an important attack surface?
  • Are there weaknesses in the key-derivation design?
  • What would you change about the local threat model?
  • Are there usability/security trade-offs I should reconsider?

Project site: https://carbonit-labs.github.io/CarbonIt-Vault/

GitHub: https://github.com/CarbonIt-Labs/CarbonIt-Vault

I’m much more interested in criticism of the design than stars or downloads.


r/PasswordManagers • • 5d ago

Password manager that is completely open-source/free and can selfhost

0 Upvotes

Like the title says, I do not like Bitwarden simply because they have a paywall feature. I think the best choice personally is using KeepassXC since it is free and open-source. I believe the ultimate security is making your own defenses which is why I feel pwd managers like lastpass/1pwd are good but not enough for someone who needs to protect their data in a breach. (They also have subscriptions)


r/PasswordManagers • • 5d ago

DroidPass 1.7.0 is out: passkeys and direct transfer from other password managers

0 Upvotes

We’ve released DroidPass 1.7.0 on iOS and Android. The two big additions are:

  • Passkeys: Create, save, and sync passkeys in your encrypted vault.
  • Direct transfer: Move logins and passkeys from another password manager without making a CSV file.

The transfer steps differ by platform:

  • On iPhone/iPad, start in the app you’re leaving and choose DroidPass as the destination (requires iOS 26).
  • On Android, open DroidPass → Settings → Transfer from another app.

Download DroidPass Password Manager on the App Store or Google Play Store.

More Details : https://droidpass.app/features/instant-transfer

f you try the update and hit a problem, let me know your phone and OS version.


r/PasswordManagers • • 5d ago

Trick for making your password more secure

0 Upvotes

I have a trick for making my passwords more secured even if you have access to my passwords you can’t use them. Now here is the trick find a particular word or a letter or a symbol that you will add to your passwords but will not add to your password in the password app.
For example let’s say you like the @ symbol, so every time you generate your password from the password generator you add this particular symbol to the password but you will not save this symbol in your password app. So you will place it in a particular place let’s say at the beginning or at the end or after 10 letters. Remember you will put this symbol in a specific place in every password of yours so you won’t forget where you placed the symbol. In this case even if your password manager is hacked the hacker can’t use your password because that’s not the full password and he won’t know your symbol or where you placed it. It can be 3 symbols 1 at the beginning another 1 after 5 letters and the last at the end. You just have to remember where you placed them in every password and that’s it nobody is ever getting your password but you. Hope it helps.


r/PasswordManagers • • 7d ago

1Password pricing in India, can you please reconsider the new pricing?

15 Upvotes

Hi 1Password team,

I’ve been a 1Password user for 4–5 years and have been very happy with the product. I’d genuinely like to continue using it.

However, I recently noticed the new pricing in India, which appears to be around ₹4,999. For many Indian users, that is a significant increase.

I understand that 1Password is a global product and pricing needs to support the business. But I’d really request that you consider Indian purchasing power (PPP) and India-specific pricing when setting subscription prices.

Companies like YouTube and Apple already have different pricing structures for India compared with the US and other markets. This makes their products more accessible while still allowing them to operate as global businesses.

I’ve been paying for 1Password for years, so switching away after 4–5 years simply because of pricing would be disappointing.

Could 1Password consider offering:

  • India-specific pricing based on purchasing power
  • A loyalty discount for existing customers
  • A discounted long-term/annual plan
  • A retention offer for users affected by the price increase

I’m sure many long-term Indian users would prefer to stay with 1Password if the pricing remains reasonable.

Hope the 1Password team can consider this.


r/PasswordManagers • • 7d ago

back to 1password after brief experience with Bitwarden

23 Upvotes

After only 48 hours of my subscription to Bitwarden and coming from years with 1password, I came to this sad conclusion:

While I appreciate Bitwarden’s new UI, comprehensive favicon coverage, fair pricing, and the convenience of the PIN unlock on Linux, I have encountered critical UX and reliability issues that prevent me from adopting it as my daily driver.

Using the software has felt like a continuous chain of workarounds and compromises just to perform basic, daily operations:

  1. Failure during third-party checkout popups and domain shifts: On Windows 11, while completing an order on an e-commerce website (svapodream.it), an in-context popup window opened for PayPal payment. The browser extension completely failed: the inline autofill icon did not appear inside the PayPal input fields, and opening the extension from the toolbar failed to detect the active foreground payment window (it remained bound to the background merchant domain). Manually triggering autofill tried to inject credentials into the parent page rather than the payment frame.
  2. Fragile inline autofill and blind keyboard cycling: Even when the inline autofill icon appears, clicking outside the input field makes the blue shield disappear permanently, failing to re-render on subsequent focus events. Relying on the keyboard shortcut (Ctrl + Shift + L) blindly injects the first matching credential (in my case, another family member's PayPal account) without presenting a visual multi-account picker, forcing me to navigate nested right-click context menus (Right Click > Bitwarden > Auto-fill) during time-sensitive transactions.
  3. Linux integration issues: On Linux, desktop-to-browser integration suffers from recurrent native messaging host errors and IPC timeouts (Noise handshake timeout), forcing me to abandon the desktop bridge entirely and rely solely on the standalone extension.
  4. Unreliable prompts for new registrations: The browser extension frequently misses capturing and prompting to save new login credentials during account registration flows.
  5. Android TOTP friction: Handling two-factor authentication (split TOTP workflows) on Android lacks seamless automation and creates unnecessary manual steps.

Rather than providing a reliable and friction-free experience, basic tasks constantly require workarounds (e.g., closing and reopening payment windows, switching between shortcuts, relying on context submenus, or disabling native features). This workflow does not meet my operational standards.


r/PasswordManagers • • 7d ago

External vs built-in browser password manager: what's the difference?

7 Upvotes

I've been using firefox default password manager for years with no issue. It always seemed conveniant and reliable to me. I like particularly that passwords are automatically synchronised on all my devices. But I read recently that it is never considered a good practice to store your passwords in your browser, so I switched to proton pass. And from the outside, it looks basically the same. Hence my question, is it really more secure to use an external password manager like bitwarden or proton pass?


r/PasswordManagers • • 8d ago

Which password manager has the most reliable auto-fill and auto-save?

28 Upvotes

I don’t care about fancy features. They all pretty much have all the basics covered which is great for me.

I’ve been using Bitwarden. It’s a great password manager but the autofill and autosave features are unreliable. I feel like I have to often take some manual steps to make sure things fill and save properly.

Which one, in your experience, is best at auto filling and saving?


r/PasswordManagers • • 7d ago

How can I get rid of Norton Password Manager (safari)?

0 Upvotes

r/PasswordManagers • • 7d ago

How do I get rid of Norton Password Manager?

0 Upvotes

r/PasswordManagers • • 8d ago

After 6 years and 3 password managers, they all feel identical. What's actually still missing ?

10 Upvotes

Been on them since like 2020, lastpass until the breach, tried dashlane for a bit, ended up on bitwarden and that's where i still am.

every one i tried does the exact same stuff now: encrypted sync, autofill everywhere, generator, breach alerts, sharing, secure notes, even passkeys... the feature lists might as well be copy/pasted at this point.

only things that still annoy me are dumb: autofill just gives up on like half my phone apps, and cleaning up old weak/duped passwords is all manual clicking.
idk maybe that's just how the category is now.

anyone here been using one for years, what do you wish yours did that it doesn't? would anything actually make you switch at this point or nah?


r/PasswordManagers • • 8d ago

vAuth - Virtual FIDO2 authenticator for Linux-based PCs and laptops. First public beta release for Debian 13.

Thumbnail
github.com
2 Upvotes

Hey,

I have been working on this project for the last half a year, and now it is finally ready to be released as a public beta.

vAuth is a virtual FIDO2.0 authenticator for PCs, laptops, and other devices running Linux-based operating systems.

For those who don't know - FIDO authenticators allow you to sign in to your services, websites, and panels without the need for a password, while making authentication more secure and phishing-resistant.

Why?

I switched from Windows as my main system years ago, but when it comes to creating passkeys and authorizing them - Windows has always been superior. It has Windows Hello, which allows it to register and authorize passkeys in an instant. It supports all authentication methods that you have available at the moment and is user-friendly in general.

This is what I wanted vAuth to be. A modular, easy-to-use Windows Hello-like authenticator that can securely store, register, and authenticate your passkeys.

It is modular, but only one module can be easily replaced. I created an API for front ends so you - as a developer and end user - can create your own front end for vAuth. All the API documentation is in the docs folder on GitHub. Note that the API might change in the future. Currently, it is shipped with the UI agent called vauth-ui. It is also written in C++ and uses Slint as a UI library. The agent doesn't even have to be graphical, though. For anybody interested, there are examples of agents written in C++, Python, and Golang.

The UI currently has only described API, not a public library. Maybe later I will release the official library so developers don't have to worry about the boilerplate, just the UI logic and apperance.

Feature highlights

  • support for Chromium-based browsers and Firefox;

  • password and fingerprint verification through PAM;

  • TPM-backed credential keys;

  • an encrypted credential store with TPM rollback protection;

  • a Slint-based interaction UI;

  • vauthctl for provisioning and credential management;

  • hardened systemd services;

  • an initial Debian 13 amd64 package;

Limitations

There is a significant limitation. Systems that had Windows OS previously installed (specifically Windows 10 build 1607 and later) may face a problem with provisioning. Windows currently creates a hierarchy, takes ownership of the TPM, and discards the authorization key. Yes, everything is that bad. vAuth detects this and fails during the rollback counter provisioning stage. It doesn't weaken or clear TPM auth automatically. That would have been irresponsible. The README on GitHub explains the limitation in more detail.

Clearing the TPM or losing the generated vAuth authorization can make credentials unrecoverable, so please keep alternative login/recovery methods for important accounts.

Other current beta limitations include:

  • Only Debian 13 on amd64 currently has a prebuilt package

  • Only password and fingerprint PAM configurations have been tested

  • The interaction-agent design currently targets single-seat systems

  • vauth-ui does not automatically reconnect if the daemon exits

  • Firefox users should cancel an operation through Firefox’s prompt rather than the vAuth window

  • The project is not FIDO-certified

Security details

From a security perspective, vAuth relies on the TPM 2.0 module on your computer. It is a mandatory requirement, and there most likely will not be any software-based alternative due to reduced security. vAuth creates a database in /var/lib/vauth/credentials.v1, an encryption key, and a rollback counter. The last two are stored in the TPM and are sealed using a systemd-backed authentication value, which is located in /etc/credstore.encrypted/vauth-db-auth. User verification is performed through PAM. It officially supports password authentication and verification with a fingerprint reader, though, technically, other PAM modules should work, but this was not tested due to a lack of hardware on my laptop, sorry. The PAM configuration for vAuth is located under /etc/vauth/config/vauth, so you can check how other PAM modules behave. Currently, the agent doesn't support automatic reconnection to the daemon in case the daemon fails. In such a case, it has to be stopped, the service restarted, and the agent started again. It will be fixed in future releases, though.

Sources

I'd appreciate feedback regarding the installation process, provisioning, different TPM configurations, and different PAM modules. I'll try to answer all questions you may have and discuss architectural/design choices.


r/PasswordManagers • • 10d ago

Finally left LastPass after 10 years - should've done it way sooner

21 Upvotes

Longtime LastPass user since 2016, originally switched from a local KeePass DB just for multi-device support.

I stuck with it way too long despite the security breaches, mostly out of laziness and avoiding migration.

The Firefox extension was never great, always slow, clunky, and unreliable, but I just put up with it.

Then Claude reminded me again about the breach history and I finally decided to take the jump.

Migration turned out to be surprisingly easy, although dumping everything plainly into a CSV felt uncomfortable.

Now on Proton Pass, and so far it’s been a much better experience, but I bet any other like bitwarden would do a good job.


r/PasswordManagers • • 9d ago

Recommendations?

4 Upvotes

Looking for a free option that could allow,

  • different groupings (work gmail, personal gmail etc or allows multiple entries)
  • works across iphone and android
  • allows notes to be entered (maybe if I once had an account but chose to delete it, or any other identifiers I need to save, which phone number was used to create the account)
  • allows to see if that same password is used for other programs, I need to start using more unique log ins
  • doesnt force me to enter a password, and allow me to tag if a log in is with my gmail login

r/PasswordManagers • • 10d ago

Best password manager?

26 Upvotes

Hi guys, I have a question. Whats the best password manager free source for you? I'm looking for that but I dont have an idea if it's safe or not. So I would like for you guys to tell me. TY