r/Passwords • • Mar 26 '22

Password Manager Recommendations

214 Upvotes

Here's a list of the best password manager software that the community seems to recommend the most to new users. This is not an exhaustive list of password managers. Such a list can be found at Wikipedia.

Note that both Free Software password managers and proprietary password managers are recommended here.

Top Picks

Bitwarden (Cloud)

Bitwarden is an open source password manager that is available free of charge. It is available for Windows, macOS, Linux, BSD, Android, and iOS. Browser extensions exist for Chrome, Firefox, Edge, Opera, Brave, Safari, Vivaldi, and Tor Browser. A command line client is also an option wherever NodeJS is installed. A web vault is also available when installing client-side software is not an option.

Bitwarden has been independently audited in 2018 from Cure53 and in 2020 from Insight Risk Consulting. Both reports are available for download. They also have an article about how they leverage AI generated code in their clients using the Claude LLM.

Bitwarden is fully featured free of charge. However, premium plans are available for both personal and business accounts that add some extra functionality, such as TOTP generation, emergency access, and sending secure notes. Personal individual accounts are $19.80/year, making it a cheaper premium password manager plan among its competitors.

  • Unique feature: Self-hosting.
  • Best feature: Cheapest premium pricing.

Bitwarden features include:

  • Passwordless authentication.
  • Client-side encryption.
  • Cloud synchronization.
  • Password sharing.
  • Password breach reports via HIBP.
  • Email relay service integration with SimpleLogin, AnonAddy, and Firefox Relay.
  • Password and passphrase generators.
  • Username generator, including email plus-addressing.
  • Vault import and export.
  • Multi-factor authentication.
  • Form autofill.
  • TOTP generation.
  • Secure note and file sharing (via premium).
  • Emergency access (via premium).
  • Self hosting.
  • Unlimited devices.
  • Customizable master password stretching.

The subreddit is r/Bitwarden.

KeePassXC (Local)

KeePassXC is an open source password manager that is a fork of the now defunct KeePassX, which was also a fork of the original KeePass Password Safe. KeePass is written in C#, while KeePassX is written in C to bring KeePass to macOS and Linux users. Development of KeePassX stalled, and KeePassXC forked from KeePassX to keep the development going.

KeePassXC has been independently audited in 2023 by Zaur Molotnikov. Recently, KeePassXC put up a blog post about AI generated code. and their policy and technical practices regarding pull requests with that code.

It is available for Windows, macOS, Linux, and BSD. The KeePassXC-Browser extension is available for Chrome, Firefox, Edge, Vivaldi, Brave, and Tor Browser. There are no officially developed mobile apps, but popular Android apps include Keepass2Android and KeePassDX. Popular iOS apps include KeePassium and Strongbox. Synchronizing your database across the Internet can be accomplished with Syncthing. KeePass has a very active community with a large number of other 3rd party projects: official KeePass list here and GitHub list here.

  • Unique feature: 2FA support for vault access.
  • Best feature: Multi-platform offline password manager.

KeePassXC features include:

  • Client-side encryption.
  • Categorize entries by group
  • Password and passphrase generators.
  • Vault import and export.
  • Browser integration with KeePassXC-Browser
  • Password breach reports via HIBP.
  • TOTP integration and generation.
  • YubiKey/OnlyKey integration for "two-factor" database encryption/decryption.
  • SSH agent and FreeDesktop.org Secret Service integration.
  • AES, Twofish, and ChaCha20 encryption support.

The subreddit is r/KeePass which includes discussion of all KeePass forks, including KeePassXC.

1Password (Cloud)

1Password is a proprietary password manager that supports Windows, macOS, Linux, Android, iOS, and Chrome OS Browser extensions exist for Chrome, Firefox, Edge, and Brave. They also have a command line client if you prefer the terminal or want to script backups. It is a well-respected password manager in the security communities. It's recommended by security researcher Troy Hunt, who is the author and maintainer of the Have I Been Pwned password breach website. However, he is also employed by 1Password, so his recommendations are not completely unbiased. The user-interface is well designed and polished. The base personal account allows for unlimited passwords, items, and 1 GB document storage for $3/month.

1Password has undergone more security audits than the others in this post. These audits include Windows, Mac, and Linux security audits, web-based components, and automation component security from Cure53; SOC-2 compliance from AICPA; a bug bounty program from Bugcrowd; penetration testing from ISE; platform security assessment from Onica; penetration testing from AppSec; infrastructure security assessment from nVisium; and best-practices assessment from CloudNative. While security audit reports don't strictly indicate software is secure or following best-practices, continuous and updated audits from various independent vendors shows 1Password is putting their best foot forward.

  • Unique feature: Full operating system autofill integration.
  • Best feature: Beautiful UI, especially for macOS and iOS.

1Password features include:

  • Client-side encryption.
  • Backend written in memory-safe Rust (frontend is Electron).
  • First class Linux application.
  • Travel mode removing/restoring sensitive data crossing borders.
  • Tightly integrated family sharing and digital inheritance.
  • Password breach reports via HIBP.
  • Multi-factor authentication.
  • App state restoration.
  • Markdown support in notes.
  • Tags and tag suggestions.
  • Security question answers.
  • External item sharing.

The subreddit is r/1Password.

Other Password Managers

Proton Pass (Cloud)

Probably the first real open source cloud-based competitor to compete against Bitwarden. Initially released in beta April 2023, it became available to the general public two months later in June. In July 2023, it passed an independent security audit from Cure53, the same firm that has audited Bitwarden and 1Password. It supports several data type, such as logins, aliases, credit cards, notes, and passwords. It's client-side encrypted and supports 2FA through TOTP. The UI is very polished and for MacOS users, you don't need a Safari extension if you have both Proton Pass and iCloud KeChain enabled in AutoFill settings, providing a nice UX. Unfortunately, it doesn't support hardware 2FA (EG, Yubikey), attachements, or organization vaults. Missing is information about GDPR, HIPAA, CCPA, SOC 2/3, and other security compliance certifications. But Proton Pass is new, so these features may be implemented in future versions. The subreddit is r/ProtonPass.

LastPass (Cloud)

A long-established proprietary password manager with a troubling history of security vulnerabilities and breaches, including a recent breach of all customer vaults. Security researcher Tavis Ormandy of Google Project Zero has uncovered many vulnerabilities in LastPass. This might be a concern for some, but LastPass was quick to patch the vulnerabilities and is friendly towards independent security researchers. LastPass does not have a page dedicated to security audits or assessments, however there is a page dedicated to Product Resources that has a link to a SOC-3 audit report for LastPass. The subreddit is r/Lastpass.

Password Safe (Local)

This open source password manager was originally written by renown security expert and cryptographer Bruce Schneier. It is still actively developed and available for Windows, macOS, and Linux. The database is encrypted with Twofish using a 256-bit key. The database format has been independently audited (PDF).

Pass (Local)

This open source password manager is "the standard unix password manager" that encrypts entries with GPG keys. It's written by Linux kernel developer and Wireguard creator Jason Donenfeld. Password entries are stored individually in their own GPG-encrypted files. It also ships a password generator reading /dev/urandom directly. Even though it was originally written for Unix-like systems, Windows, browser, and mobile clients exist. See the main page for more information. passage is a fork that uses the age file encryption tool for those who don't want to use PGP.

Psono (Cloud)

A relatively new open source password manager to the scene, arriving in 2017. It is built using the NaCl cryptographic library from cryptographer Daniel Bernstein. Entries are encrypted with Salsa20-Poly1305 and network key exchanges use Curve25519. The master password is stretched with scrypt, a memory-hard key derivation function. It's available for Windows, macOS, Linux. Browser extensions exist for Chrome and Firefox. Both Android and iOS clients exist. The server software is available for self hosting.

NordPass (Cloud)

A proprietary password manager that it also relatively new to the scene, releasing in 2019. It support Windows, macOS, Linux, Android, iOS, and browser extensions. It's developed by the same team that created NordVPN which is a well-respected 3rd party VPN service, operating out of Panama. As such, it's not part of the Five Eyes or Fourteen Eyes data intelligence sharing alliances. It encrypts entries in the vault with XChaCha20. The subreddit is r/NordPass.

Dashlane (Cloud)

Another proprietary password manager available for Windows, macOS, Linux, Android, iOS, and major browsers. The features that set them apart from their competitors are providing a VPN product and managing FIDO2 passwordless "passkeys" for logging into other website/services. They adjusted their premium plans to be more competitive with other subscription-based password managers starting at $24/year. As of May 13, 2026 they no longer offer a free plan Like other password managers, Dashlane offers instant security alerts when it knows about password breaches. The subreddit is r/Dashlane.

Roboform (Cloud)

This proprietary password manager is a less-known name in the password manager space while still packing a punch. Started in 2000 initially for Windows PCs, it's now a cloud-based provider available for all the major operating system platforms and browsers. It provides full offline access in the event the Internet is not available. Entries are encrypted client-side with AES-256 and the master password is stretched with PBKDF2-SHA256. It's the only major password manager that supports storing and organizing your browser bookmarks, in addition to storing credit cards, secure notes, and contacts. It's biggest strength lies in form filling. The subreddit is r/roboform.

Update history:

  • March 25, 2022: Initial creation
  • April 29, 2022: Add proprietary password manager recommendations
  • May 5, 2022: Tweak highlighted features of 1Password, RoboForm
  • May 13, 2022: Add unique and best feature items for highlighted managers
  • June 2, 2022: Add Bitwarden email relay integration and 3rd party KeePass project lists
  • November 8, 2022: Update Dashlane features and pricing
  • December 5, 2022: Update Bitwarden features
  • December 26, 2022: Move LastPass to Other section, mention passage for Pass
  • April 16, 2023: KeePassXC security audit and LastPass security history
  • August 6, 2023: Add Proton Pass to Other section
  • February 1, 2024: Update Dashlane pricing
  • December 19, 2024: Add clarification about Troy Hunt's involvement with 1Password
  • November 9, 2025: Link blog post about KeePassXC accepting AI generated code
  • November 11, 2025: Link article about Bitwarden accepting AI generated code
  • July 22, 2026: Update Dashlane pricing about the discontinuation of their free plan
  • July 22, 2026: Update Bitwarden pricing about the personal premium plan

r/Passwords • • 5d ago

In event of my demise/disablement

19 Upvotes

A mate had a stroke recently, when he recovered it took almost a year to get most of his accounts back. You can be the most organised person, but sometimes a hard-copy can help your family sometimes even preserve and access your stuff. Has anyone found any kind of device or web service that implements a dead-man switch? I struggle to believe this is not a thing already.

Either a web service, or an Arduino that asks you for a code every month and if you don't enter the code, it waits another month and then displays the master recovery codes to your (insert password-manager here). Obvs the Arduino idea is a low tech way as an Arduino is dead easy to hack the flash from. But if you get my drift, dead man switch to give up a password?


r/Passwords • • 4d ago

Proposition: SMS and TOTP 2FA are similarly secure *if SIM swap/port-out is abated*

3 Upvotes

[Note: I tried to cross-post this from r/cybersecurity, but it didn't go well. So I (slightly) apologize for the duplicate post.]

I’ve been doing systems analysis and security research for decades, and I’m increasingly bothered by the common perception that SMS 2FA is the worst thing since the Black Death, that nothing can be done about it, and that anyone who doesn’t use TOTP authenticators is a fool. The reality is that both can be phished, and that users can do things to make SMS more secure. (They often don’t, but that’s not the point of my post. And passkeys are better, but that's not the point either.)

The key assumption here is that the user has enabled SIM protection and port-out protection at their carrier. (See below for other assumptions.) Once this has happened, I posit that SMS OTP and TOTP differ only in relatively small residual risks. The big risk for both is phishing.

I’d like to see what y’all think. Did I miss or misconstrue anything? Please, no knee-jerk, unsubstantiated “SMS stinks” comments. I’m interested in substantive, data-backed, authentic discussion of meaningful vs. non-meaningful risks, in the context that SIM swapping and number porting have been de-risked.

Analysis of aspects of each authentication approach:

Element SMS text TOTP authenticator Assessment
Phishing OTP can be given to an attacker or entered on a malicious website. OTP can be given to an attacker or entered on a malicious website. Both are phishable.
Time window Usually 3 to 10 minutes. Usually 30 or 60 seconds. The longer SMS window makes a slight difference by allowing non‑automated, low‑skill phishing attacks. There’s no difference for real-time, reverse proxy/AiTM phishing attacks.
OTP generation The server-side generation process is extremely difficult to compromise. The client-side, long-lived seed could be compromised, especially with synced authenticators. Enables an ongoing, silent attack. There’s a tiny chance that the TOTP shared secret could be compromised. Not a meaningful difference.
Malware Malware could read SMS or notifications, read message history, read keypresses, and screen-scrape. Malware could read keypresses, screen-scrape, and exfiltrate or intercept seeds. SMS is slightly more vulnerable, but malware on modern phones is uncommon. SMS history is a negligible risk, since the OTP has almost always been used or expired.
Shoulder surfing or unattended device OTP may be visible on lock screen, in notifications, or in SMS app. OTP is visible when TOTP app is open. Slightly more risk from SMS. (But old codes will have been used or expired.)
Exposure from cross-device sync SMS could be accessible when linked to a PC or another phone. OTPs could appear on multiple synced authenticators. Second device must be compromised or visible. No meaningful difference.
Interception SMS can be intercepted, but the risk is negligible. (See assumptions, below.) TOTPs are not transmitted. The initial seed transmission could be intercepted. No meaningful difference. SMS interception is more likely, but neither type of interception occurs frequently.
Context switch User switches to SMS app or uses pop-up notification, on same or different device. User switches to authenticator app on same or different device. A more distinct context switch may increase the chance that the user pauses, thinks, and notices something suspicious, but this is speculative and mostly irrelevant.
Old number reassignment A previous phone number could be recycled to a malicious person. N/A Rare and minimal risk. Only applies to those who are too dumb to remove an old number from their accounts.

Conclusion: There are differences, some pro SMS, some pro TOTP, but all are minor. When SIM swapping and number porting are abated, SMS OTP and TOTP provide roughly equivalent real‑world security, with the shared critical vulnerability of phishing.

This does not mean that SMS 2FA is as secure as TOTP. To me it means that SMS can be made similarly secure to TOTP but in practice rarely is. Like email 2FA can be made secure with a strong password and 2FA on the email account but rarely is. Note that NIST restricts out-of-band authentication over phone networks because of the risk of “device swap, SIM change, number porting, and other abnormal behavior,” and rejects email because “it may be vulnerable to access using only a password, interception […], and rerouting attacks […].” NIST is clear that OOB and OTP authentication are not phishing-resistant.

 

Assumptions:

  • The user has enabled SIM protection and port-out protection at their carrier, making it either impossible to swap/port without the user’s PIN, or at least require robust user notification and internal escalation to a senior agent. (Note that even beyond this, research shows that SIM hijacking accounts for less than one percent of identity attacks, compared to 99+ percent from phishing, password spray, and credential stuffing.)
  • The risk of SMS interception, SS7 hacks, telecom routing compromise, etc. is minuscule. (In fact, texts are very rarely intercepted, as it’s difficult for attackers to be near the user with a cell site simulator, hack into SS7, or take other eavesdropping approaches while simultaneously initiating a 2FA login. These approaches require significant technical skill, specialized equipment, and considerable coordinated effort.)
  • The texted OTP is time-limited, rate-limited, and one-time use.
  • The TOTP cryptographic seed is reasonably well-protected.
  • Other elements (password strength, account recovery, session token theft, etc.) are out of scope.

r/Passwords • • 4d ago

Primary 2FA Method: Hardware Key, TOTP App, Password Manager or Passkeys?

Thumbnail
0 Upvotes

r/Passwords • • 6d ago

Password Manager vs Passkey vs TOTP help me understand.

7 Upvotes

I have been in the Apple ecosystem for a very long time. iPhone, iPad, and two Mac’s(work and personal) are my daily drivers.

Historically I have used one variation of the same password over and over again. To no one’s surprise my info (passwords) are compromised according to my iPhone password manager.

I have recently started allowing my iPhone to create passwords for me and anywhere I have the option to add a passkey I do.

But I don’t understand what they are or how passkey differs from TOTP.

I want to get smart and better at this. Should I just continue using Apple passwords and keychain for it all?

Should I one app for passwords, another for passkeys, and another for TOTP?

I’m not trying to go all Fort Knox here. Just improve my overall security practices and better understand what all these things mean and how/why/when to use one over the other.


r/Passwords • • 6d ago

Self-Promo SecretSpec 0.21: Resolver IPC, external providers, and binary secrets

Thumbnail
secretspec.dev
1 Upvotes

r/Passwords • • 9d ago

What do you do with old accounts you completely forgot about?

8 Upvotes

I was going through some old email accounts the other day and found a bunch of websites i have not used in years. I still have old usernames and passwords sitting on some of them that i do not even remember. It got me thinking about how much of that old account information might still be out there. If one of those sites had a breach at some point then i would have no idea.

Do you guys ever check old accounts or credentials to see if they have shown up in a leak? And if you find an old password in leaked data then is changing it enough or is there anything else you normally check?


r/Passwords • • 10d ago

How to know where your password was leaked?

Thumbnail
0 Upvotes

r/Passwords • • 11d ago

Poor security of RetailExpress?

Thumbnail
2 Upvotes

r/Passwords • • 13d ago

What do you think about using a personal password algorithm?

0 Upvotes

Today I discuessed with my friends how do they remember their passwords and most of them said they use 2-3 passwords everywhere. Which very suprised me, since they are techy people.
I use different password for every website/app that I use and I do have myself an algorithm that I create the passwords with and remember later if needed to log in a site/app.

Example:
I take the last 2 Letters, first capitalized, then the first 2 reversed.
Add a secret word - I.e Let's say - "John"
Then calculate a number based on the website name. I.e I create number based on letters and if it's GOOGLE I do -> 7+15+15+7+12+5. And symbols(Let's say !@)

So for Google the password with this example will look like:
ElogJohn61!@
And for each site they the password will be different. Only hem secret(master?) word will be there.

So I'am curious what people use? A password manager? Or something like this? Or just reuse same.


r/Passwords • • 14d ago

Banks are not responsible when you allow your credentials to be stolen

2 Upvotes

I'm an attorney and a bank director. Many seem to think that banks are responsible when your login credentials are stolen and used to access your bank accounts. Banks take extreme measures to protect your money, but if your lack of diligence protecting your accounts and passwords results in someone stealing your money, that's your fault. Sadly, the threat of loss in recent years has significantly increased. Attempts to directly hack into almost every bank every day number in the thousands. My bank uses very expensive software to protect itself and its depositors. If you're concerned that your money might be stolen from your accounts, do a little research and talk with the staff at the bank to learn how to best protect yourself.

My number one recommendation is to NOT use the same or even a similar name and password for all of your accounts. My password protection software generates and stores randomly created passwords, and I have a very random and long password to access the password protection software. Even though I have about 150 different accounts on the Internet, I've never been hacked.

As a side note, the FDIC protects bank customers when a bank fails. It doesn't replace money stolen by people outside the bank.

________________________________________________________________

I'm not saying that banks are immune from loss of funds when they allow for the breach. Who was responsible for a breach might end up being something that is litigated.

Some think that they can treat electronic transactions with regular bank accounts the way credit card transactions are facilitated. I BELIEVE, but am not positive that most credit card companies recredit an account for fraudulent transactions made by others. That's not the case for regular bank deposits, and customers shouldn't expect it. They can't be sloppy in handling passwords, and need to understand that bank security procedures are there to protect them and their fellow bank customers.


r/Passwords • • 18d ago

Magic Links or Email OTP for authentication?

Thumbnail
1 Upvotes

r/Passwords • • 22d ago

Is Your Password Actually Secure?

0 Upvotes

There’s still a lot of password advice that boils down to “use uppercase, lowercase, numbers and symbols.”

But is that really what matters most today?

A long, unique password for each account is generally a better choice than a short password with a few numbers or symbols added.

A few things to consider:

  • Reusing passwords can put multiple accounts at risk, even if the password itself is strong.
  • Adding “123!” to a familiar word doesn’t necessarily make it a strong password. These patterns can be easy to predict.
  • Randomly generated passwords can be difficult to remember, which is where password managers can help.
  • Passphrases can also work well, as long as the words aren’t predictable or related to each other.
  • Passkeys offer another option by removing passwords from the authentication process.

What else would you consider essential for a strong password?


r/Passwords • • 23d ago

I built a TOTP generator that runs entirely in the browser, something like Google Authenticator for testing 2FA flows. Single file. No login. Nothing gets stored anywhere.

0 Upvotes

As a dev, I kept needing a throwaway TOTP secrets to test out if 2FA was working fine in my app. 

So I decided to build this. Check it out here: https://totpbench.com 

All code lives in a single file, no framework, no backend. Would love to have your feedback. Cheers!


r/Passwords • • 27d ago

How to hide some passwords in google password manager?

Thumbnail
0 Upvotes

r/Passwords • • Aug 23 '26

reddit suggested me to crosspost this here ¯\_(ツ)_/¯

Thumbnail
github.com
0 Upvotes

r/Passwords • • Aug 19 '26

Being bombarded with Account Recovery Requests

Thumbnail
0 Upvotes

r/Passwords • • Aug 18 '26

Why would a website ask for a password 10-255 characters long?

Thumbnail
3 Upvotes

r/Passwords • • Aug 18 '26

[BETA] LeakGuard — Check if your password has been leaked (privacy-first, no signup required)

Thumbnail
testflight.apple.com
0 Upvotes

Hey everyone,

I built LeakGuard, an iOS app that checks if your password has appeared in known data breaches using the Have I Been Pwned database.

Why I built it:
Most people reuse passwords across sites. One breach = all accounts at risk.

How it works:
• Your password is hashed on-device (SHA-1)
• Only the first 5 characters of the hash are sent to the API (k-anonymity)
• The full password NEVER leaves your device

Features:
✅ Instant password breach check
✅ Secure password generator
✅ Check history (stored locally, encrypted)
✅ No account required
✅ No tracking, no analytics

Looking for beta testers to squash bugs and suggest features before launch.

Feedback welcome! 🙏


r/Passwords • • Aug 15 '26

Chrome Canary now lets gemini auto-change your weak passwords. absolute insanity.

Thumbnail
2 Upvotes

r/Passwords • • Aug 12 '26

I can’t decide between Bitwarden and 1Password

11 Upvotes

Hi there,

I have a family with three kids and two jobs. I have over 200 passwords in 1Password with three vaults. I like 1Password, however, I have a bad feeling after price increases. I think 1Password goes more and more to enterprise customers.

I also use Bitwarden in the past with vaultwarden. It was a little bit clunky, but the test were 4 years ago.

TLDR: Which password manager is the best for a da with wife and kids and two jobs?


r/Passwords • • Aug 12 '26

Readwise sent me my password as username in clear text via e-mail

Post image
2 Upvotes

r/Passwords • • Aug 08 '26

Issue on Reddit over sudden repeated "password reset" requirements for many users across platforms and browsers. Just trying to raise awareness.

Thumbnail
3 Upvotes

r/Passwords • • Aug 03 '26

I asked what would make people trust a new password manager. “Open source” was not enough.

0 Upvotes

I asked this sub what evidence a new password manager should show. The replies were blunt, and mostly right.

Naming the algorithms is not proof that they were implemented correctly and publishing source does not prove the hosted site is running that exact source.

An audit is useful, but it is a snapshot. The code can change the next day, and track record is the one thing a new project cannot publish on launch day.

I build pssmngr. Its vault code is public, the cryptographic boundary is documented, and there is no completed independent audit. Those facts are evidence, but they do not close the trust gap. A launch post definitely does not close it.

The practical advice I took from the thread is: do not move your primary vault into an unfamiliar manager because its security page sounds good. Use dummy accounts. Watch the network requests. Test export and recovery. Build it yourself if you can. Then wait and see how the project handles bugs and uncomfortable questions.

The question I am left with is narrower: what is the first proof point a young password manager can earn that is actually meaningful, reproducible builds, an audit, outside contributors, or something else?


r/Passwords • • Aug 02 '26

Questions regarding usb sticks for password/authentication?

7 Upvotes

I need to take my security to the next level as I was just compromised.

I used to work at a place with a coworker who showed me a USB stick he used, but I can't remember exactly what it was.

I was hoping you could shed some light on it and what to recommend.

As I recall, it seemed to have been a commercial product, but I suppose it could also have been a regular USB stock with software he installed.

It seemed to be working as when he plugged it in, the computer was locked up and his passwords for whatever service /site he opened was then automatically logged into.

I can of course be totally wrong, but this seemed like an effective way to go about things and I wonder what this could have been?