45 votes

What is you preferred password manager?

I use Lastpass at work but don't have experience with any others. Last time I looked into it Lastpass and Keepass were the only two viable options if I recall (though my memory isn't the most reliable thing). A few quick searches seem to indicate that the market has opened up a bit since then. I'd like to use something open source with Linux, Windows, and Android clients. So, what's your preferred password manager and why?

62 comments

  1. [10]
    tomf
    Link
    I started with LastPass, but was part of the exodus when LogMeIn acquired them. 1Password was good, but was lacking support for Linux. I tried KeepassXC for a time, but I ran into syncing issues...

    I started with LastPass, but was part of the exodus when LogMeIn acquired them. 1Password was good, but was lacking support for Linux. I tried KeepassXC for a time, but I ran into syncing issues

    Bitwarden to the rescue! Its a browser extension, so its perfect for those of us who jump between operating systems. The experience between each is identical, yadda yadda yadda, and I love it. Also, the mobile apps are excellent.

    I believe there's a completely self-hosted version coming down the pipe, but I could be wrong about that. I found BitBetter, but I haven't tried it out yet.

    23 votes
    1. teaearlgraycold
      Link Parent
      I just checked and Bitwarden is all FOSS. Not only do they use GPL, but they use AGPL for their backend code. I might actually use it since self-hosting is an option.

      I just checked and Bitwarden is all FOSS. Not only do they use GPL, but they use AGPL for their backend code. I might actually use it since self-hosting is an option.

      10 votes
    2. Zlyme
      Link Parent
      +1 for bitwarden! btw you can already host bitwarden yourself

      +1 for bitwarden! btw you can already host bitwarden yourself

      7 votes
    3. anomoly
      Link Parent
      Thanks for the recommendation! I checked it out today and being able to share with a 'company' looks like it may work for the limited sharing I need. This may be what I end up running with.

      Thanks for the recommendation! I checked it out today and being able to share with a 'company' looks like it may work for the limited sharing I need. This may be what I end up running with.

      4 votes
    4. [2]
      klieber
      Link Parent
      Just as an FYI, 1Password has now come out with linux support via their browser extensions for Chrome and Firefox. I'm using it now and it works great -- seamlessly integrates with their desktop apps.

      Just as an FYI, 1Password has now come out with linux support via their browser extensions for Chrome and Firefox. I'm using it now and it works great -- seamlessly integrates with their desktop apps.

      4 votes
      1. tomf
        Link Parent
        Does that also work with the standalone license, or only their subscription?

        Does that also work with the standalone license, or only their subscription?

        1 vote
    5. [2]
      Triseult
      Link Parent
      I've stuck it out with LastPass and they're still as great as ever.

      I've stuck it out with LastPass and they're still as great as ever.

      2 votes
      1. phedre
        Link Parent
        Same. I have lastpass on my phone and all browsers, works great. Took me a while to get everything set up properly, but it's all good now.

        Same. I have lastpass on my phone and all browsers, works great. Took me a while to get everything set up properly, but it's all good now.

    6. xxx
      Link Parent
      yeah, bitwarden rocks. that's what i've used for a few months now and it just works. i use the hosted service. the android app works well too.

      yeah, bitwarden rocks. that's what i've used for a few months now and it just works. i use the hosted service. the android app works well too.

      1 vote
    7. Droplet
      (edited )
      Link Parent
      I was part of the exodus as well, will have to check out Bitwarden.

      I was part of the exodus as well, will have to check out Bitwarden.

      1 vote
  2. [4]
    cheers
    Link
    KeepassXC, backed up twice locally and once to Google Drive. Development is more active than that of the other Keepass variants, and the browser extension works quite well.

    KeepassXC, backed up twice locally and once to Google Drive. Development is more active than that of the other Keepass variants, and the browser extension works quite well.

    9 votes
    1. [3]
      booleancat
      Link Parent
      Nice! I've been using KeePass2 for years because I was too lazy to port my database over to something else. I never really used the browser integration because setting up that weird http proxy...

      Nice! I've been using KeePass2 for years because I was too lazy to port my database over to something else. I never really used the browser integration because setting up that weird http proxy always seemed like more hassle than it was worth.

      But KeepassXC and the browser extension worked like a charm!

      1 vote
      1. [2]
        whyarentihigh
        Link Parent
        HTTP-Connector has been deprecated (at least in KeepassXC). It's really insecure.

        HTTP-Connector has been deprecated (at least in KeepassXC). It's really insecure.

        1 vote
        1. tan
          Link Parent
          More info on this: the replacement and deprecation is from KeePassXC 2.3 onwards, which was released at the end of February this year, and which has landed in Fedora 27 and 28. The new system is...

          More info on this: the replacement and deprecation is from KeePassXC 2.3 onwards, which was released at the end of February this year, and which has landed in Fedora 27 and 28.

          The new system is detailed here: https://keepassxc.org/docs/keepassxc-browser-migration/

          1 vote
  3. [2]
    Tang_Un
    Link
    Keepass with regular backups .

    Keepass with regular backups .

    8 votes
    1. trwork
      Link Parent
      I use Keypass sync'd to Google Drive across all my devices, so I don't even need to remember to backup - I use access it straight from the Google Drive location.

      I use Keypass sync'd to Google Drive across all my devices, so I don't even need to remember to backup - I use access it straight from the Google Drive location.

      4 votes
  4. MangoTiger
    Link
    Bitwarden. Open source, fast, has all the features I need. I previously used Lastpass, but I got tired of their bloated apps and had security and privacy concerns.

    Bitwarden. Open source, fast, has all the features I need. I previously used Lastpass, but I got tired of their bloated apps and had security and privacy concerns.

    8 votes
  5. what
    Link
    I stay far away from online password managers (keeping all my passwords in one place is already a risk, I think putting that online in any capacity is way too risky). I use KeePassXC on Linux and...

    I stay far away from online password managers (keeping all my passwords in one place is already a risk, I think putting that online in any capacity is way too risky). I use KeePassXC on Linux and KeepassDroid on Android, and use Syncthing to sync my database locally across all my devices.

    8 votes
  6. [4]
    KehrBehr
    Link
    pass It's extremely simple! I also utilize QtPass for the nice GUI. There's an Android app on F-Droid that uses pass, but I never got it to work correctly on my device.

    pass

    It's extremely simple! I also utilize QtPass for the nice GUI.

    There's an Android app on F-Droid that uses pass, but I never got it to work correctly on my device.

    5 votes
    1. zowesiouff
      Link Parent
      Seconding pass 100%: it's simple, you can backup / sync the .password-store wherever you want ( I've got a copy on bitbucket and one on my private git server + typical backup for my gpg keys ). No...

      Seconding pass 100%: it's simple, you can backup / sync the .password-store wherever you want ( I've got a copy on bitbucket and one on my private git server + typical backup for my gpg keys ). No nonsense, no trying to auto-log me in based on BS rules with URLs, no messing with other apps, no leaks via browser extensions, just nobrain simple: exactly what I want out of a password manager.

      And for mobile, I try to stay logged-out as much as possible anyway.

    2. [2]
      JuanPotato
      Link Parent
      Pass is great. I didn't have any issues with the f-droid app, just installed it and synced. What did you have trouble with?

      Pass is great. I didn't have any issues with the f-droid app, just installed it and synced. What did you have trouble with?

      1. KehrBehr
        Link Parent
        Your question made me realized I worded my issue pretty poorly. The main function of the app was working fine. It's been a while so i'm a little hazy on the specifics, but it was the pop-over...

        Your question made me realized I worded my issue pretty poorly. The main function of the app was working fine. It's been a while so i'm a little hazy on the specifics, but it was the pop-over feature or whatever that I could never get working. I was hoping when I browsed a site that required a login via my bowser, I could easily sign in via a pop up dialog of some sorts and not have to open up pass, copy the pass, switch apps, then paste.

  7. [3]
    frank
    Link
    I use lastpass for the most part, its just easy to set up and use everywhere. I've also heavily used pass in the past, and love its implementation on plain PGP encryption. Between that and keybase...

    I use lastpass for the most part, its just easy to set up and use everywhere. I've also heavily used pass in the past, and love its implementation on plain PGP encryption. Between that and keybase its simple to share passwords with someone, and I can embed whatever extra data I want in the encrypted files

    4 votes
    1. [2]
      Comment deleted by author
      Link Parent
      1. frank
        Link Parent
        Yep. I have credit card numbers, bank accounts, socials, all kinds of stuff stored in mine still I just want a better Android app

        Yep. I have credit card numbers, bank accounts, socials, all kinds of stuff stored in mine still

        I just want a better Android app

    2. GyroTech
      Link Parent
      Pass for me, backed by a simple git repository for sharing between devices.

      Pass for me, backed by a simple git repository for sharing between devices.

  8. microfracture
    Link
    I personally prefer to use KeePassXC on the desktop combined with Keepass2Android for my various Android devices.

    I personally prefer to use KeePassXC on the desktop combined with Keepass2Android for my various Android devices.

    4 votes
  9. [3]
    unknown user
    Link
    KeePass2, using the desktop client via Mono on my Linux box and Keepass2Android on my phone; the database is synced to Google Drive (if the NSA wants my passwords, they can just as easily get them...

    KeePass2, using the desktop client via Mono on my Linux box and Keepass2Android on my phone; the database is synced to Google Drive (if the NSA wants my passwords, they can just as easily get them from me). I use the Url in title Chrome extension and KeePass' autotype rather than a specific KeePass plugin to isolate my passwords from the browser process (and also because I couldn't find a decent KeePass browser plugin…)

    4 votes
    1. [2]
      scituselectrum
      (edited )
      Link Parent
      I assume you have used the first KeePass. If so, what do you think about KeePass2 in comparison to KeePass? Is it worth switching?

      I assume you have used the first KeePass. If so, what do you think about KeePass2 in comparison to KeePass? Is it worth switching?

      2 votes
      1. unknown user
        Link Parent
        I don't think I ever really used KeePass 1.x, since it doesn't run particularly well on Linux. OTOH, KeePass2 supports database compression, custom fields, custom entry icons, and database...

        I don't think I ever really used KeePass 1.x, since it doesn't run particularly well on Linux. OTOH, KeePass2 supports database compression, custom fields, custom entry icons, and database synchronisation, none of which are supported by 1.x AFAIK. Sync is especially important for me because I don't reopen my database on my laptop very often, so it's useful to get a warning on save if I'm about to overwrite changes I made on my phone, and so far it's always been able to automatically merge them too.

        2 votes
  10. toaster
    Link
    I use LastPass. My favorite feature is being able to view reused passwords, automatically reset passwords (good in case an account was compromised), and auto-generate passwords. Haven't tried...

    I use LastPass. My favorite feature is being able to view reused passwords, automatically reset passwords (good in case an account was compromised), and auto-generate passwords. Haven't tried 1Pass or KeePass but I have tried RememBear and boy it's autofill feature on mobile is trash compared to LastPass.

    3 votes
  11. [2]
    MindsRedMill
    Link
    1Password, been a customer for years. The family plan now is amazing value. On all platforms for five people. Great support too.

    1Password, been a customer for years. The family plan now is amazing value. On all platforms for five people. Great support too.

    3 votes
    1. Kraetos
      Link Parent
      The apps are a joy to use, too. Even their Windows app, which is a pleasant surprise.

      The apps are a joy to use, too. Even their Windows app, which is a pleasant surprise.

      1 vote
  12. [2]
    starchturrets
    Link
    iCloud Keychain because it's convenient and is already installed on my iPhone.

    iCloud Keychain because it's convenient and is already installed on my iPhone.

    2 votes
    1. nathreed
      Link Parent
      Same. It also syncs to my Macs. My favorite thing about it is that when I get a new device, I can just sign in on it and all my stuff is there right away, the browser fills it in and everything....

      Same. It also syncs to my Macs. My favorite thing about it is that when I get a new device, I can just sign in on it and all my stuff is there right away, the browser fills it in and everything. Don’t have to install any extra apps or browser extensions.

  13. [4]
    joelthelion
    Link
    I use Firefox' password manager. It might not be the best, but it works and does all I need.

    I use Firefox' password manager. It might not be the best, but it works and does all I need.

    2 votes
    1. tvfj
      Link Parent
      Mozilla has a project that aims to improve the password manager eventually. It's called Lockbox.

      Mozilla has a project that aims to improve the password manager eventually. It's called Lockbox.

      7 votes
    2. [2]
      ubel
      Link Parent
      Me too, sometimes I feel "unsafe" using it, but I didn't save the passwords for my email accounts, paypal, etc so at least I can't lose any money if someone hacks me. It might be ironic but that's...

      Me too, sometimes I feel "unsafe" using it, but I didn't save the passwords for my email accounts, paypal, etc so at least I can't lose any money if someone hacks me.

      It might be ironic but that's the reason I haven't tried any of the other password managers, they claim to be safe and I don't know if I can trust them ... Firefox's password manager makes no claims and I realize it's not safe.

      Bitwarden does sound interesting though, I like that it's open source.

      1 vote
      1. joelthelion
        Link Parent
        There's nothing unsafe about it if you use a master password. It's a bit inconvenient to use with the master password, though.

        There's nothing unsafe about it if you use a master password. It's a bit inconvenient to use with the master password, though.

        2 votes
  14. [2]
    greynol5
    Link
    I prefer SafeInCloud. But I also share 1pass with my husband.

    I prefer SafeInCloud. But I also share 1pass with my husband.

    2 votes
    1. cahaseler
      Link Parent
      One day I'll convince you to make the switch...

      One day I'll convince you to make the switch...

  15. [3]
    tvfj
    (edited )
    Link
    LessPass. It's a stateless password "manager" with clients on all major platforms and the web. Rather than storing your passwords with them, or having to sync a password database on your own, it...

    LessPass. It's a stateless password "manager" with clients on all major platforms and the web. Rather than storing your passwords with them, or having to sync a password database on your own, it simply re-generates your password every time you need it.

    2 votes
    1. [2]
      trazac
      Link Parent
      This is very cool! I use LastPass and don't have any issues with it but having my password generated offline is appealing. My only concern being the cost of switching. Would I need to change all...

      This is very cool! I use LastPass and don't have any issues with it but having my password generated offline is appealing. My only concern being the cost of switching. Would I need to change all of my passwords to switch?

      1 vote
      1. tvfj
        Link Parent
        Just the ones you want to access through LessPass. If that's all of them, then yeah.

        Just the ones you want to access through LessPass. If that's all of them, then yeah.

        1 vote
  16. BBBence1111
    Link
    Brain. I have a system I use to make passwords (obviously not sharing) based on the website.

    Brain. I have a system I use to make passwords (obviously not sharing) based on the website.

    2 votes
  17. [3]
    Gyrfalcon
    Link
    I use Keepass. I have it on Windows, and on Linux using Mono. The file lives on my Windows partition, and gets synced when I use it on Windows because the cloud syncing plugin I use needs more...

    I use Keepass. I have it on Windows, and on Linux using Mono. The file lives on my Windows partition, and gets synced when I use it on Windows because the cloud syncing plugin I use needs more than just Mono. I also use Keepass2Android for whenever I need portable logins.

    2 votes
    1. [2]
      tan
      Link Parent
      For Linux, I highly recommend giving KeePassXC a try. I had heard about it a few times before I decided to see what the fuss was about, and it's generally a nice quality-of-life upgrade, fixing...

      For Linux, I highly recommend giving KeePassXC a try. I had heard about it a few times before I decided to see what the fuss was about, and it's generally a nice quality-of-life upgrade, fixing things you didn't realise were annoying.

      1. Gyrfalcon
        Link Parent
        I'll have to look into that. It looks like KePassXC is also in the software center, so that should make trying it out pretty easy.

        I'll have to look into that. It looks like KePassXC is also in the software center, so that should make trying it out pretty easy.

  18. [2]
    Brian
    Link
    For group management—1password. I've heard good things about keepass if you're solo. LastPass made me struggle with an issue for nearly 6 weeks going back and forth with their customer service...

    For group management—1password.

    I've heard good things about keepass if you're solo.

    LastPass made me struggle with an issue for nearly 6 weeks going back and forth with their customer service over an issue that should have taken a minute to fix. They never fixed the issue either. I eventually just walked and went to 1pass.

    1 vote
    1. DrTacoMD
      Link Parent
      I use 1Password for solo management, and it’s pretty excellent. I mostly live in the Apple ecosystem and their Mac/iOS apps are top-notch, but I also have a Windows PC at the office, and I’m...

      I use 1Password for solo management, and it’s pretty excellent. I mostly live in the Apple ecosystem and their Mac/iOS apps are top-notch, but I also have a Windows PC at the office, and I’m impressed with the quality of their most recent Windows app. And they have extensions for every browser under the sun (including Edge and Safari).

      I’ve luckily never had to deal with their customer service, but I hear plenty of good things on that front too.

      Granted, they aren’t the cheapest solution, but in this case you get what you pay for.

      1 vote
  19. onyxleopard
    Link
    I’m lucky enough to use macOS on my personal machines and at work, so I use 1Password. Work also has Lastpass, but I prefer 1Password with Dropbox syncing. Never had any problems with 1Password...

    I’m lucky enough to use macOS on my personal machines and at work, so I use 1Password. Work also has Lastpass, but I prefer 1Password with Dropbox syncing. Never had any problems with 1Password and I’ve been using it for a good ~5+ years now. On macOS it supports Safari, Firefox, and Chrome pretty well (sometimes has issues if Chrome auto-updates, just requires relaunching Chrome in that case). They’re moving to a subscription model, which I understand and will probably grudgingly move to at some point. I think it’s still worth it for the peace of mind of never having to worry about my passwords, credentials, and other data/metadata that I want to keep encrypted and synced across my devices.

    1 vote
  20. [2]
    athnndnly
    Link
    Anyone have any experience with Enpass?

    Anyone have any experience with Enpass?

    1 vote
    1. for4saken
      (edited )
      Link Parent
      I've tried it for a couple months, but moved to Keepass mostly because it's opensource and the android client. And that was when Enpass truly disappointed: at the time, it only exported to TXT...

      I've tried it for a couple months, but moved to Keepass mostly because it's opensource and the android client. And that was when Enpass truly disappointed: at the time, it only exported to TXT where each entry span multiple lines with labels; I had to spend a lot of time making it parse-able for import elsewhere.

  21. [2]
    soulonfire
    Link
    I’ve been using Dashlane, I have it for iOS and MacOS. Haven’t tried it on Windows at all though as I wasn’t using Windows until rather recently. But it’s been working great for me.

    I’ve been using Dashlane, I have it for iOS and MacOS. Haven’t tried it on Windows at all though as I wasn’t using Windows until rather recently. But it’s been working great for me.

    1 vote
    1. monkeypaw
      Link Parent
      Same here. Dashlane all the way. I use it across all of my devices and tablets and love it. Ever since LastPass was bought out by LogMeIn, they lost all trust/confidence from me as LogMeIn has...

      Same here. Dashlane all the way. I use it across all of my devices and tablets and love it.

      Ever since LastPass was bought out by LogMeIn, they lost all trust/confidence from me as LogMeIn has some business tactics I don't agree with.

      1 vote
  22. elf
    Link
    I use keepass in concert with dropbox to synchronize between devices. The desktop and android apps are both good in my opinion. I also occasionally use chrome's password manager for sites that...

    I use keepass in concert with dropbox to synchronize between devices. The desktop and android apps are both good in my opinion. I also occasionally use chrome's password manager for sites that constantly ask you to reenter your password.

  23. Jedi
    Link
    I use Master Password, it uses your name plus your “Master Password” to create a key that generates passwords based on the domain you give it. Absolutely no information is stored, it can be used...

    I use Master Password, it uses your name plus your “Master Password” to create a key that generates passwords based on the domain you give it.

    Absolutely no information is stored, it can be used offline, and the “algorithm” is completely open-source.

  24. fishinginthecoy
    Link
    I use lastpass not because it’s the best but because it was (imo) the easiest one to set up for my parents to use and for me to manage. They had a google doc with all their bank, email, etc...

    I use lastpass not because it’s the best but because it was (imo) the easiest one to set up for my parents to use and for me to manage. They had a google doc with all their bank, email, etc passwords and one day I just sat them down and went through account by account storing them. The peace of mind on my end is priceless.

  25. zohan6934
    Link
    Use lastpass, I loved it but right after the one year mark I couldn't log in and ended up losing all my passwords, still looking for a good replacement when I have time to transfer 300+ logins

    Use lastpass, I loved it but right after the one year mark I couldn't log in and ended up losing all my passwords, still looking for a good replacement when I have time to transfer 300+ logins

  26. tcp
    Link
    I use Lastpass and I don't know what I am missing. If you switched from Lastpass to something else, then why?

    I use Lastpass and I don't know what I am missing. If you switched from Lastpass to something else, then why?

  27. [2]
    kn100
    Link
    I currently am using Keeweb running locally, with my database file synced across Dropbox. I am considering switching to Pass (The UNIX password manager) though, I'm just concerned with how good...

    I currently am using Keeweb running locally, with my database file synced across Dropbox. I am considering switching to Pass (The UNIX password manager) though, I'm just concerned with how good the equivalent mobile client will be. Keepass2Android is such a well thought out functional client for Keepass and I'm not sure whether I'm ready to give that up yet!

    1. tan
      Link Parent
      Something to consider about pass is that since each entry is its own file and it's not a single encrypted database, the name of each entry (generally the url, i think, since you want to open the...

      Something to consider about pass is that since each entry is its own file and it's not a single encrypted database, the name of each entry (generally the url, i think, since you want to open the right one based off url) is not hidden at all.

  28. princess_mango
    Link
    I use LastPass since I am pretty much stuck remembering the logins for me, my partner, my mother, work, and since I like trying out new web services, I also get stuck with a million logins for any...

    I use LastPass since I am pretty much stuck remembering the logins for me, my partner, my mother, work, and since I like trying out new web services, I also get stuck with a million logins for any and everything. Not to mention I have 2 accounts for some services because I have to separate my US and European billing infos, or get around geo restrictions.

    I can't live without being able to easily use the login helpers iOS, OSX, Windows, and Android.