34 ms·
Evaluation of five password managers
- redwards510 8y ago> Yubikey support in browser (Personal) BitWarden: no huh? I use my yubikey in the Bitwarden browser extension. Otherwise, a very extensive collection of comparison data. Not surprised to see Bitwarden come out on top.
- tmikaeld 8y agoI'm also currently using it with a Yubikey and on personal account.
- drdaeman 8y ago"Yubikey support" is a meaningless phrase, anyway. Bitwarden supports 2FA with Yubico OTP - although there's a bug so it works only for QWERTY layouts. Or you can use Yubikey's static password feature for your master password, I guess. There's also OpenPGP Card and PIV, which, to my knowledge, is not used/supported by any password manager software except for `pass` and some compatible implementations.
- dmoy 8y agoNo u2f support? :(
- village-idiot 8y agoU2f support is badly hampered by half-assed browser support. Only chrome enables it by default, Firefox disables it by default, and no love from safari. Even LastPass in the browser uses yubico’s proprietary otp algorithm rather than u2f.
- danieldk 8y agoIt seems that Apple is working to add support for hardware tokens. It is all a bit vague, but the latest Safari Preview notes state [1]: Added support for CTAP HID authenticators on macOS It also gives me "Web Authentication" under "Experimental features" in the Develop menu. https://developer.apple.com/safari/technology-preview/release-notes/ https://developer.apple.com/safari/technology-preview/releas...
- sebazzz 8y agoIsn't that WebAuthn suppport? That is different from U2F.
- tialaramex 8y agoYes and no. U2F is basically the MVP of WebAuthn. If you're doing this today you should ignore U2F and just implement WebAuthn. Firefox has WebAuthn out of the box, and there's a hack behind a pref to half-arse U2F if you still need that.
- StavrosK 8y agoIt doesn't, though. I've been trying to implement WebAuthn and, as far as I know, CTAP 2 doesn't work on any browser yet.
- dbrgn 8y agoU2F support in Firefox should work out of the box if the developers use the WebAuthn API and not the old JS library: https://hacks.mozilla.org/2018/01/using-hardware-token-based-2fa-with-the-webauthn-api/ https://hacks.mozilla.org/2018/01/using-hardware-token-based...
- village-idiot 8y agoThat was not my experience on google and github.
- jik 8y agoGoogle and Github both built their U2F support for Firefox before WebAuthn was released, and as you've pointed out, the U2F support in Firefox is gated out by default. Presumably Google, Github, and other companies that coded to U2F will migrate to WebAuthn eventually.
- jik 8y agoYes, my initial evaluation was flawed because I was looking at the free version of Bitwarden, but supports neither U2F nor attachments, but the evaluation grid said that it didn't support U2F but did support attachments. I've updated the grid to fix this. It now says that YubiKey is supported for Bitwarden and has a separate pricing line for personal use without attachments or YubiKey vs. with them.
- CompuHacker 8y agowe decided that Bitwarden is the best choice for our company, and we’ve begun the process of migrating from LastPass to Bitwarden. whois lastpass.com LogMeIn, Inc. whois bitwarden.com WhoisGuard, Inc.
- gregmac 8y agoWhat is your point?
- CompuHacker 8y agoWHOIS Privacy on the website wasn't a consideration on the table the company used. Maybe it's not important in 2018, or is enabled by default, or an oversight, or they're using the spam filtering. But: It’s at the bottom of the page. So why the discrepancy?
- scarejunba 8y agoIt’s at the bottom of the page. 8bit solutions LLC and they’re in Florida.
- echelon 8y agoUsing WhoisGuard for their domain is so not a problem. Namecheap gives you that for free and by default, and it cuts down on spam mail from other registrars. Bitwarden is open source and self-hosted. This is a better trust model than any of the other offerings by a mile.
- CompuHacker 8y agoI have no criticism of the service or WhoisGuard, just the idea of that kind of site using it.
- Avery3R 8y agoNo keepass? Disappointed.
- mooman219 8y agoExtremely. I've been so pleased with Keepass and the security it provides. I'm using a web interface now (https://app.keeweb.info/ https://app.keeweb.info/) which is open source and worth checking out.
- mnutt 8y agoKeeweb is pretty awesome, and is amazingly just a static HTML page. If you're comfortable running your own secure webserver, you can self-host that for added security: https://github.com/keeweb/keeweb#self-hosting https://github.com/keeweb/keeweb#self-hosting
- syntheticnature 8y agoGiven their particular usage case, which includes not just shared, synchronized access to secrets but managed, tiered levels of access, it seems to be a bit beyond what I've seen of Keepass.
- brobinson 8y agoNo mSecure either.
- arunc 8y agoAbsolutely. I'm using keepass on Windows, Linux and Android in parallel with Google drive sync. Just fantastic!
- com2kid 8y agoThe one issue I had with Keepass is that on iOS (and this is Apple's fault!) it is not possible to choose different cloud storage providers to keep the password database file on. This silly thing alone would preclude me ever buying an iOS device! (My wife ran into it when I tried to get her up and running with Keepass, she gave up...) I love keepass's simplicity, no browser plugins with pop up dialog boxes or UIs that conflict with the browser's own password management, just, a list of accounts and passwords.
- Kiro 8y agoI'm using Chrome's built-in password manager. What are the drawbacks besides it being Google?
- Wowfunhappy 8y agoYou're forever locked into Google Chrome! I realize this is becoming an increasingly minor problem in the modern world, but it still bothers me. I don't know what future situations I'll find myself in, and I don't want to be locked out of all my accounts. • What if a new browser comes out that's actually better than Chrome? (I don't want to admit to myself how unlikely this actually is.) • What happens if I'm using a Windows 10 S device, or a locked-down library computer, or a Wii U, or some other weird gadget with a non-Chrome browser?
- excalibur 8y ago> What if a new browser comes out that's actually better than Chrome? (I don't want to admit to myself how unlikely this actually is.) Firefox has a nifty feature where it doesn't send ALL your data to Google, you could try that.
- Wowfunhappy 8y agoI should mention, I'm currently using Firefox on Windows and Safari on macOS; Chrome is gone from my life. I really like Firefox following their Quantum update; it feels super speedy! But, I was kinda putting myself in the mindset of the GP. They're currently using Chrome's password manager, so they clearly prefer Chrome, and while Safari and Firefox have advantages, there's no overwhelming need for anyone to switch right now. For the sake of a democratized web, I hope that changes some day in the future.
- quicklime 8y agoI recently starting using Firefox again, and getting my passwords out of Chrome was by far the most difficult part of the process for me. A few things I learned: Chrome has a feature to export passwords to a CSV file, but I had to enable it via a chrome:flag, so who knows if/when support for this will disappear. This created a bit of a sense of urgency for me, as Google aggressively removes features that they don't want to support. My employer MITMs all web traffic, so I would never log into my Google account from work. They also have an ridiculously strict password change policy (every 3 months). But having a password manager on my phone lets me store passwords for my various work-related accounts somewhere, which makes each password change fairly easy, and also lets me log into certain work-related apps/sites (e.g. Slack) from home. If you have multiple accounts on a single website, it's a bit easier to do in a password manager (at least Keepass or Bitwarden). Chrome is a web browser, so it only remembers passwords to websites. If you have passwords that don't map to a website - e.g. hard drive encryption password, a pgp/ssh key, a wifi password), it's a bit easier to do in a password manager. Some password managers have OTP generators built-in, which can be convenient.
- mithr 8y ago> Mac OS, Windows, Linux, Android, and iOS ... full functionality can’t be dependent on an app which is only available on Mac OS and/or Windows. In other words, lack of full Linux support is a show-stopper for us. This ruled out 1Password... ...Huh? 1Password supports all of those platforms (including Linux) https://1password.com/downloads/linux/ https://1password.com/downloads/linux/
- SloopJon 8y agoThat page says, "Requires Google Chrome or Firefox," and the download link takes you to the Chrome web store. I'm not sure the poster considers that full support.
- bsamuels 8y agoHow many Linux users don't have chrome or firefox installed? I think the article would be a bit more accurate to say there's not native client support for Linux.
- avhon1 8y agoThere are applications besides web browsers that require passwords. For example, password-protected documents, or encrypted archives. A password managers that requires, or only supports, web browsers is incomplete.
- eridius 8y agoA password manager that is only usable in a web browser may be annoying to use for non-web-related tasks, but presumably you can just switch to your web browser, open up the password manager, and then search for what you need within it. It's not like the password manager is restricted to only giving you access to the passwords for the current site.
- freehunter 8y agoNone of my headless servers have Chrome or Firefox installed.
- the_duke 8y agoA comparison matrix would help.
- KSS42 8y agoIt's in the article. Click on "Result".
- VectorLock 8y agoDoes the one further down on the page hosted on JSFiddle count?
- w8rbt 8y agoHere's a plug for DPG (zero storage password manager). I wrote it years ago and it meets my needs well. https://github.com/w8rbt/dpg https://github.com/w8rbt/dpg
- deleted 8y ago[deleted]
- thedanbob 8y agoI rarely see it mentioned, but when 1Password changed to a subscription model I switched to Enpass (https://www.enpass.io https://www.enpass.io) and I've been very happy with it.
- sys_64738 8y agoMe too. Enpass is great.
- clairity 8y agothey don't make it very obvious, but note that 1password doesn't require a subscription. i use it with vaults shared and kept in sync via dropbox for example.
- rrdharan 8y agoSame. I recently purchased an upgrade and consider it well worth the price, although I'm considering switching to the subscription model / family plan to make it easier to support my parents and in-laws. However my main concern is that you can't disable browser access when using ay of the subscription plans: https://discussions.agilebits.com/discussion/80105/cant-disable-web-browser-access-from-1password-com-to-unencrypted-passwords https://discussions.agilebits.com/discussion/80105/cant-disa...
- clairity 8y agoyup, i don't use 1password.com because of those security concerns. not sure if it would work for your situation, but it's possible to set up different vaults for different groups of people and share them via separate dropbox folders (or even just different share settings on the vault files). i have 5 vaults set up that way.
- eridius 8y agoI'm confused as to what the security issue is here. > Limiting the access of unencrypted passwords to only properly setup 1PW applications would seem to eliminate the possible (probable?) web based attack vector to a 1password.com account. This doesn't make sense. What's a "properly setup 1PW application"? Presumably that's an instance of 1Password that has been given both the master password and account key for the account. But when you use the web-based portal, you have to give it, yep, the master password and account key. Anyone who is able to access the passwords using the web portal can already set up a local instance of the 1PW application that syncs with the same account. Ultimately, asking to "disable browser access" is basically the same thing as asking to "disable the syncing API", which would obviously defeat the entire point of having the family account.
- beat 8y agoHas anyone gone through the process of switching? I use Keeper for personal stuff, and I suppose there's always the chance to switch if one turns out to be technically or politically much superior, but there are dozens and dozens of passwords in there to transfer...
- Reedx 8y agoI switched from LastPass to 1Password. It was a quick and simple export -> import process.
- fokinsean 8y agoAs a current LastPass user, what prompted you to switch?
- CharlesW 8y agoNot the person you asked, but I also switched from LastPass to 1Password. The reasons were (1) 1Password's more integrated/more convenient 2FA support, and (2) AgileBits seems to care more about design.
- jammygit 8y ago...just checked and there is literally no export option for Dashlane on linux. I will start switching to a replacement shortly. I wish I'd known sooner.
- Avamander 8y agoI switched from LastPass to Bitwarden, I do not miss a single thing and quite a few irritating things have been fixed.
- amanzi 8y agoAgree - switching to Bitwarden was super easy.
- dgacmu 8y ago
- VectorLock 8y agoI like the functionality comparison but I'm really curious how they stack up to each other security wise.
- tmikaeld 8y agoBitwarden recently completed a 3rd party Audit[1] and Bitwarden is the only one to be completely open source[2] (server and client). [1] https://blog.bitwarden.com/bitwarden-completes-third-party-security-audit-c1cc81b6d33 https://blog.bitwarden.com/bitwarden-completes-third-party-s... [2] https://github.com/bitwarden/ https://github.com/bitwarden/
- woolvalley 8y agoIt also has pretty much zero automated (unit, integration, etc) tests as of a few weeks ago.
- jopsen 8y agoBut you only know that because you can see the source.
- paulryanrogers 8y agoThey may have non-public tests to discourage forking. IIRC, Sqlite similarly has some proprietary tests only available to paying customers.
- rollinDyno 8y agoI've been using masterpassword [1] which is stateless and requires no sync. I wonder what the HN crowd thinks of its features. Another option with the same paradigm is lesspass [2]. 1. https://masterpassword.app/ https://masterpassword.app/ 2. https://lesspass.com/#/ https://lesspass.com/#/
- sdfjkl 8y agoThere's a few issues with the master password derived password system, including: What if you need to change your password for a site to a different one? What if the site changes its URL?
- bdibs 8y agoThere's a counter on Master Password, so if the password expires or you need to change it, you just +1 and it's new. They also have settings depending on password requirements (no special characters, etc.). I'm unsure what the URL really has to do with it, you could just generate a new password for the new URL and change it.
- kybernetikos 8y agoIn my system, you have a number of additional pieces of information that are used to generate the password, including a counter and a salt. If you need to change your password, you would typically just increment the counter. You can also do this if the password policies don't allow your password for some reason. This does mean that you need to remember what the version is. Fortunately this information doesn't need to be kept secret. I also have a system that generates emojis based on your settings, so as long as you remember the emoji that goes with the site, you can just increment it until you get the right one, so it's down to you whether you store the version number somewhere or remember the emoji. I use URLs by default, but you can enter anything you want into the 'purpose' field. It's still pretty raw, but it's at https://github.com/kybernetikos/sinkless https://github.com/kybernetikos/sinkless Most of the complaints people have about deterministic systems don't really hold up in practice for me. Protecting them by 2fa would be better of course, which deterministic can't do and lots of the good password managers do, but I really dislike having to worry about syncing state beyond just emailing it to myself. One thing that would be awesome would be if someone came up with a standard machine readable way of describing the limitations on passwords for sites (allowable characters, number of characters, any restrictions on previous values / sequences etc), and all good sites could embed that information, and poor sites could be looked up in a third-party service.
- Wowfunhappy 8y agoOne feature I didn't see mentioned—LastPass has a Bookmarklet that can be used in leu of a proper extension. This means that if I ever decide to start using a random niche web browser, I won't have to start copying and pasting from a web vault in order to log in to sites. The freedom to do this is important to me regardless of whether I ever actually use it.
- CiPHPerCoder 8y agoI'm surprised there was no mention of recent security audits. BitWarden just famously had one.
- psetq 8y agoResult for the curious (pdf): https://cdn.bitwarden.net/misc/Bitwarden%20Security%20Assessment%20Report%20-%20v2.pdf https://cdn.bitwarden.net/misc/Bitwarden%20Security%20Assess...
- tptacek 8y agoMany of these have had audits, not just this Bitwarden audit. There are some disquieting things in that audit, for what it's worth. I don't understand how this information is actionable. It would be worth knowing whether something has _ever_ been audited (again: most of the major password managers have been), but just knowing an audit has been done isn't sufficient to know whether it's secure.
- beatgammit 8y agoSure, but if it has been audited, it's more likely that security issues were found and resolved than if it hasn't gone through one. Our company went through an audit and did quite well, and we fixed most of the findings. However, I know for a fact that there are things we can do to improve that weren't covered. Not all audits are created equal, no audit will catch everything, and there's no guarantee that findings were patched sufficiently. However, I feel much better knowing that an audit was done, which means the author cares at least somewhat about security.
- tptacek 8y agoI think Scott knows that most of these other password managers have been audited, and I know he knows audits are of varying quality and are virtually never conclusive, so I'm not sure what he's trying to say by pointing Bitwarden's audit out.
- 8y ago
- zmmmmm 8y agoIn the end I've just been using the Unix pass password manager [1]. It's just cobbling together of GPG and git with shell scripts but it works like a normal git repository so you get all your synchronization, from that, your security from GPG which are all things I know and trust without introducing other components that I don't know / understand. [1] https://www.passwordstore.org/ https://www.passwordstore.org/
- hkri 8y agoFor developers/tech-savvy people it is more or less perfect. I love the fact that it is based on git giving you a history and great control over synchronization. I use it to store all kinds of things such as passwords and files containing environment variables that can be sourced directly from the output of pass (source <(pass dotenv/project)). It even exists a great open-source iOS client: https://github.com/mssun/passforios https://github.com/mssun/passforios
- pietroglyph 8y agoI love the iOS app, but things like this concern me (not quite a dealbreaker though): https://github.com/mssun/passforios/issues/223 https://github.com/mssun/passforios/issues/223
- zapzupnz 8y agoIt's insane that people working on a password manager thought it was a good idea to put passwords in UserDefaults. Apple expressly states in its documentation that sensitive information should be stored in Keychain; how does someone setting out to make a password manager miss that?
- otachack 8y agoWhat's crazy is Apple makes it super easy to use Keychain. APIs are great and there are good examples of how to use them.
- 8y ago
- vbezhenar 8y agoFor me an important selling point of 1Password was that their software looks like native Windows software and native iOS software while Bitwarden is just Chrome wrapper or something like that for desktop and C# for mobile and I don't want to support that kind of cross-platform software.
- notatoad 8y agoWhat did you find changed in lastpass after the logmein acquisition? We've been using lastpass since before the acquisition, and i can't say i've noticed any substantial changes (either positive or negative)
- chrisfosterelli 8y agoSame here, but I only use the personal version.
- humantiy 8y agoNot sure if its related to the acquisition, but if you're a firefox user the app has gotten very slow in past few years. I think the issue is related to the move to chrome extensions but really that shouldn't be an excuse. Lots of add-on have done this move and haven't had a problem.
- PuffinBlue 8y agoIn the last few days it's had a good improvement. Copy username/password directly from the window is back (had to previously edit and view password, then copy) and speed is just as good as I see on chrome. I'm using Windows an Linux and these improvements have come in the past week or so for me. Perhaps they recently updated, I haven't checked. Worth taking another look if you can.
- e40 8y agoMore bugs and the support was horrible. I moved my entire company from LP to 1Password. I'm impressed with the quality of 1Password. They get huge props from me for telling me, in the upgrade dialog, what the changes are, before I agree to upgrade.
- jik 8y ago>More bugs and the support was horrible. ^^^Yes, this. In 2018, we reported nine different substantive security holes to LastPass. At least two of them were security issues. All of them took far too long to fix; some of them still aren't fixed. There's a tenth bug which impacts many of our users on a regular basis which we haven't bothered to report to them because by the time we started running into it, our users were like, "Meh, whatever, that's just LastPass being LastPass." It's not good when you stop reporting bugs to a vendor because you've become convinced that they just don't care. They've had 12 outages of varying severities and lengths in the past six months. Pretty much every time I reported a bug to them -- and believe me, most of my bug reports were extremely detailed and often included videos or screenshots demonstrating them -- their first response was, "Try uninstalling and reinstalling your plugin." I hate that. HATE, HATE, HATE it.
- amanzi 8y agoGlad to see Bitwarden up on top. They tick all the boxes for me - open source, transparent security (including recently published audit), feature-rich, optional self-hosted, and easy to use.
- jamesb93 8y agoUsed to be a keepass user until I found bitwarden. It does everything better, more simply. Sync is handled so much better and the browser extensions are super intelligent at picking up login fields.
- InGodsName 8y agoIs Bitwarden a native app?
- h1d 8y agoExcept there isn't much info on who 8 bit solutions is. It seems like a 1 man effort and apparently he doesn't want to reveal much. A few requests aren't exactly answered. https://github.com/bitwarden/website/issues/12 https://github.com/bitwarden/website/issues/12 https://community.bitwarden.com/t/who-is-hosting-bitwarden/1614/12 https://community.bitwarden.com/t/who-is-hosting-bitwarden/1...
- jik 8y agoThis is informative: https://opensource.com/article/18/3/behind-scenes-bitwarden https://opensource.com/article/18/3/behind-scenes-bitwarden My impression is that Kyle cares more about spending time writing software than about hyping his company. ;-) It's an unfortunate flaw in a founder, but not a fatal one if he hires people to do the communication that he doesn't want to be doing. It feels to me like he's moving in that direction.
- zmix 8y agoI wonder, why not a single word has been spoken about Keepass/X, which is available on all platforms (not sure about iOS, though), can work with UbiKeys, afaik, has huge im- and export support and is free from any corporate interests.
- abrowne 8y agoIf you want the Qt one, make sure to use KeyPassXC, the active fork of KeePassX. https://keepassxc.org/ https://keepassxc.org/
- stcredzero 8y agoI use keepassxc on MacOS, Windows, Linux, along with MiniKeePass on iOS. It's synced through my free Dropbox account. I just make sure to set the preferences so that every change to the key database results in a file save.
- _underflow_ 8y agoI daily use the exact same setup for all three, but with the Android equivalent. ...so it's not like this app is unheard of, per this thread's parent comment. Super odd that they didn't include it haha
- faitswulff 8y ago> synced through my free Dropbox account I was always a bit paranoid about this, even though I did it myself.
- faitswulff 8y agoJust idle curiosity, but I'd be curious to see BitWarden's commit on GitHub: > ...at one point during our evaluation we submitted a bug report about Bitwarden through its Github project; one of the product’s maintainers committed a bug fix seventeen minutes later, and just a few days after that the fix was released to the public.
- fluxty 8y agoNice. That's some response time.
- philliphaydon 8y agoI assume it's this issue. https://github.com/bitwarden/web/issues/303 https://github.com/bitwarden/web/issues/303 Edit: Never mind, I can't find anything opened and fixed in ~17m.
- callalex 8y agoThat tells me that their testing is either extremely excellent , or extremely nonexistent. Rumors seem to point towards the latter, which is concerning for security software.
- cassianoleal 8y agoI don't know about the rumours, but "a few days" is a long time to test a bug fix. It should ideally take from a few seconds to a few minutes. That's not extremely excellent, it's just good practice. More than that and it hints towards heavy reliance on manual testing, and that's something I'd be worried about. EDIT: Despite the parent comment's misguided logic, it seems his/her fears are actually in the right place. An issue was opened about 6 weeks ago asking where the tests are and it received zero responses from the maintainers: https://github.com/bitwarden/core/issues/399 https://github.com/bitwarden/core/issues/399
- jik 8y agoIt was a cosmetic, not a security-critical bug, so there's really no reason why it needed to be released right away. Also "a few days" was just a guess. I noticed that it was a problem, then I noticed a few days later that the fix had been release. I don't actually know exactly how long it took to release the fix after it was committed.
- JJseiko 8y agoIf someone is still looking for a good one, I use Keepass and can very much recommend it.
- fosco 8y agoanyone use passbolt[0]? interested to know your experience good/bad/etc...I am considering installing on a vm at home to use for family. [0] https://www.passbolt.com/ https://www.passbolt.com/
- ape4 8y agohttps://pwsafe.org/ https://pwsafe.org/ by Bruce Schneier
- banku_brougham 8y agoi was using dashlane for a while. The features were great, but one thing really bothered me: On macOS everytime I opened safari it launched a dashlane.com page reminding me to install the plugin. I did not want the plugin, and after much googling never was able to prevent this behavior. I had to uninstall it. Switched to KeepassXC, its good.
- jiveturkey 8y agoi find it hilarious, hilarious i tell you, that he felt the need to put a quasi-legal disclaimer at the bottom of his medium post. i suppose it is demanded by the field he is in (investment banking) but it just strikes me as nonsense. too bad the article is quite thin.
- codesuki 8y agoQuestion about bitwarden: I found this issue saying there are no tests. https://github.com/bitwarden/core/issues/399 https://github.com/bitwarden/core/issues/399 Also in the comments here someone said there are no tests. Does anyone have any info about that? I am interested in the software but no tests would be worrying. (Had no time to browse the code yet.)
- scndthe2nd 8y agoThis SAAS bias is untenable. "Use a big target" they say. "Store them with a big company" they say. "Give your data to someone, let them worry about it" they say. Meanwhile, breach after breach tells us that regardless of security, the likelihood of successful attack comes closer and closer to 1 as the size and exposure increases. It's likely that these services have already been zerodayed, and we're just waiting for the shell to drop on an upswing.
- deleted 8y ago[deleted]
- tialaramex 8y agoYeah, no. I used to (in my old job) see the raw data. They're breaching crappy third rate sites regardless of your "size and exposure" metric. Huge volumes every day. Breaking into fifty PHP forum sites running buggy old versions is easy. Figuring out how to get anything from (picking at random since I use pass personally) Lastpass is hard work, and you're more likely to get caught, not worth it.
- ozim 8y agoTake in mind the whole evaluation was from company perspective. What those services are solving is company employees slacking passwords around, sending those via emails and using generic passwords like 'CompanyName123' or 'CompanyName!!!'. Personally I am also not going to use cloud based solution.
- yinyang_in 8y agoNo mention of enpass.io, i found their method to be completely safe. Encrypted sqlite files, shared across Dropbox/onedrive/Google-drive. Apps used for Mac, Linux, windows, browser integration also works fine. All boxes are checked, don't know why isn't it popular among masses or nerd community.
- puttycat 8y agoWe use enpass too, and it has worked really well for us.
- h1d 8y agoEnpass is not sexy but got things right. But do note that backing up on cloud means, 1 password combination and you'll let your encrypted files infinite local crack attempt.
- jik 8y agoWe did not set out to evaluate every single password management product. We set out to evaluate the products which where enough "in the ballpark" of what our company needed that there was a chance we would end up using them. There was never any chance that we would use a product which required every user to set up their own cross-device synchronization. Turnkey synchronization across devices as a first-class feature is a hard requirement for us. Also, as far as I can tell, Enpass doesn't support sharing credentials between users, another hard requirement for us. The family of password managers like KeePass and Enpass have their place, but they aren't good solutions to password management for businesses.
- moulidorai 8y agoHi folks, That's a thorough comparison. I just wanted to make an attempt on why someone should consider using Zoho Vault for password management. Zoho Vault is an online password manager for teams, used by more than 20,000 small and medium sized companies across the globe. We offer client-side encryption, multi-platform support, auto-fill, auto login websites and cloud apps, fine-grained password sharing, bulk folder sharing with user groups, audit, reports, two-factor & multi-factor authentication, US/EU data centers, browser extensions (Chrome, Firefox, Safari), and mobile apps (iOS, Android, Windows), option to maintain personal vault. Integrations: G Suite, Microsoft Office 365, Zoho Mail, Zoho Desk, OKTA, OneLogin, Single Sign-On for 90+ Cloud Apps, Windows Active Directory/LDAP, Azure Active Directory Disclaimer: I work for Zoho Vault. If you need a comparison document of Zoho Vault with any product, drop an email to support@zohovault.com.
- jik 8y agoI've added Zoho Vault to the comparison grid.
- sakisv 8y agoI only found out about Bitwarden a few weeks ago and it got me to change from KeepassXC and I'm overall very happy with the change. The main selling points for me were that it's open source and they allow you to host it yourself. Apart from these, I really enjoy the browser addons which don't require any jumping through hoops[1] and that they provide their own Android client and you don't have to play Play Store Columbus to find a decent one. It can also be used as an autofill service which allows it to interact with other apps which is incredibly useful. But because nothing in this world is perfect, the downsides so far are: 1. Lack of shortcuts to copy only the username or only the password and forcing me to reach for the mouse. That's really annoying. 2. With KeepassXC you could have a keyfile that you was necessary to unlock your database while Bitwarden doesn't have that option. They do provide 2FA[2] but only TOTP and email for the free version (although $10/year for the premium subscription, arguably, is not much). 1: https://keepassxc.org/docs/keepassxc-browser-migration/ https://keepassxc.org/docs/keepassxc-browser-migration/ 2: https://help.bitwarden.com/article/setup-two-step-login/ https://help.bitwarden.com/article/setup-two-step-login/
- ekianjo 8y ago> The main selling points for me were that it's open source and they allow you to host it yourself. KeepassXC is open source too. And it does not require hosting. You can simply store your db onto a synced folder between devices and that's about the same anyway. As for your comment regarding browser addons, I am not sure what "hoops" you are referring to. I installed the browser addons for KeePassXC and it took 5 minutes to setup and I have had no issue since. And the link you refer to is pretty self explanatory. Maybe Bitwarden makes that even more simple, but it's not that KeePassXC is utterly complex in the first place either. On Android, KeePassDX is a good client that works with KeePassXC databases.
- sakisv 8y agoYou are right about the synced folder, and that's pretty much the approach that I was using. But I was keeping my DB in one provider and my keyfile in another, which means that I had to remember (or have otherwise access to) a total of 3 passwords to unlock my db. It worked, but when I recently had to change phones two times in a period of a few days it was increasingly annoying. Of course I could have kept my keyfile and the DB in the same provider, but still that's one password too many for me. Thanks for the recommendation for KeePassDX, I will take a look.
- xte 8y agoMy personal password manager: GNUPG-encrypted text file (org-mode). No extra fuss. Reason? I have too much code to look/trust to add more and I do not keep log-in anywhere during my day, I do my best to avoid web-(cr)app as much as I can and try to live asynchronously connects via Emacs, being capable of operate as much as I can offline...
- tejado 8y agoAs I want to protect all my passwords offline at one place but have them also available mobile, I developed Authorizer. It is an Android password manager based on PasswdSafe with USB HID keyboard support to enter paaawords automatically on any device. Also stores TOTP/HOTP. The idea is, to have a complete offline device (hardend android without network stack/always flight mode on, baseband overwritten, ...). https://github.com/tejado/Authorizer https://github.com/tejado/Authorizer