Live data from Hacker News

Ask HN: What is the best password manager available today?

news.ycombinator.com

31–40 of 75 posts

Re: Ask HN: What is the best password manager available today?

#31
post #27

Earlier quoted context omitted.

I've used KeePass for ages and every time another password manager comes up in the headlines it's only ever made me feel more confident about that decision. Zero games, no cloud/other party to be dependent on, and I have total freedom to implement whatever backup/sync methods work best for my situation.

KeePass is not KeePassXC. The former is written in .NET, the latter in C++; numerous open source audits have shown that KeePassXC is far and away more secure than KeePass. Not to mention that cross-platform performance for KeePassXC is superior.

Same project, two versions of the software. I use both. New devices all get KeePassXC.

Re: Ask HN: What is the best password manager available today?

#32
post #29

I'd echo what others say, KeePassXC on local storage, which you can then sync across devices either with syncthing, dropbox etc. However, I have just started exploring using vaultwarden (a rust rewrite of bitwarden, which is self-hosted).

I am very happy with my vaultwarden setup, but if you don't run your own server, you don't want to, KeePassXC + syncthing is probably the best you can do.

Re: Ask HN: What is the best password manager available today?

#33
Keeweb.info

Kepass kdb file compatible but can access through browser interface. Backup kdb file to cloud storage.

Don't like bitwarden. Keeping your encrypted password file in Google drive is much better and portable than self hosting on your own server.

Re: Ask HN: What is the best password manager available today?

#34

1password

1Password is the best password manager I've used, and the family plan works great and is reasonably priced ($60/year). Unlike many folks who are cloud-averse, I prefer a cross-platform solution that syncs to the cloud, and I'm comfortable with their security model (https://support.1password.com/1password-security/).

It's worth noting that they really fubared the 1Password 8 transition and I was very irritated that they had me looking at alternatives. However, they gradually fixed the problems and missing features and now I'm 100% satisfied with it again.

Re: Ask HN: What is the best password manager available today?

#35
Back when 1password, 90% sure it was that, had no Linux client I was searching for a solution to store passwords and settled for Enpass.

I sync via WebDAV on my Synology NAS and I’m not really worried to lose anything since every synced device has a full copy of the data.

Thought about switching to 1password a few months back since we’re using it at work and the client is better but they don’t have an Enpass import. It supports some kind of CSV transfer but I don’t want to pay for a bunch of, worst case scenario, not really perfectly structured data so I decided to stick with what I have.

Edit: when thinking of switching I was a little nitpicky. I’m pretty happy with Enpass everything considered. 1p client is just even better but with the give them your data and your money thing, which I’m not necessarily fond of

Re: Ask HN: What is the best password manager available today?

#39

1password

I have to agree. Been using it ~5 years with no issues. There may be application specific reasons some other manager is better, but for an easy to use and seemingly solid product, I'd recommend 1password.

Re: Ask HN: What is the best password manager available today?

#40
post #7

Earlier quoted context omitted.

1Password is making choices for the business at the cost of security. Sucking people's password vaults into their cloud is very not cool. Additionally removing the local vault only option is another business first decision. It's only a matter of time before 1Password has a real security problem because the business forces at 1Password appear to be much stronger than the engineering forces.

1Password is E2E encrypted no with decryption/encryption happening only at the edge? If the cloud storage is compromised, that doesn't mean the attacker can read the passwords?

No but it means a fake 1P login page can be served and that will result in some non-zero number of people who didn't have a choice on a local sync having their credentials compromised. I am a huge 1P and I think their whitepapers show off their top-tier talent in the crypto space but killing local sync was a very crummy decision.
Post reply on HN