9 ms·
I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of di
by prettyStandard 4y ago
I wasn't quite ready to self promote this but I will go ahead anyway, since people are probably researching alternatives now. I'm working on a comparison of different password managers.
https://password-manager.soft-wa.re/ https://password-manager.soft-wa.re/
At this point it's mainly a fork&merge of some previous work.
If you find any issues with the data please submit a PR.
Edit: I am standing on the shoulders of giants. Take a look at the contributors page. I am taking what was previously a blog post, and giving it some extra attention with the current going-ons. https://blog.kamens.us/head-to-head-comparison-of-password-managers-with-interactive-grid https://blog.kamens.us/head-to-head-comparison-of-password-m...
Some of y'all have already found a few issues, I will work through them, and submit a "Show HN" once I get it to that point. So take everything here with a grain of salt. And if you do know better, please submit a PR here:
https://github.com/Soft-wa-re/password-manager-comparer https://github.com/Soft-wa-re/password-manager-comparer
- neontomo 4y agoHigh value comment. Thanks, this is awesome.
- gleenn 4y agoI don't think 1Password has any free tier, at least pretty sure it doesn't have free syncing across devices anymore or even ever.
- mdaniel 4y agoIt depends on how one views "free tier," since if one doesn't pay when requested (whether from the end of a trial, just normal expiry, or if there's a separation event from the "free family for business") the vault remains yours and active, but goes read only. I don't know what would lead you to believe there's any syncing restriction from 1Password, but if that is your experience it's almost certainly a bug, since to the very best of my knowledge 1Password doesn't engage in hostage-taking like that
- ChrisMarshallNY 4y agoCool stupfh. Minor bug: I unchecked “CLI,” and still got this row: > CLI export includes attachments
- prettyStandard 4y agoFixed: https://github.com/Soft-wa-re/password-manager-comparer/commit/ec3f5294e4b909589604be835db26a75244e8b97 https://github.com/Soft-wa-re/password-manager-comparer/comm...
- linuxlizard 4y agoThank you for this work! Could you add Bruce Schneier's PWSafe? https://pwsafe.org/ https://pwsafe.org/
- A4ET8a8uTh0 4y agoSimple. Portable. Works across platforms. Local. If that is a selling point for you, password safe just works. I apologize if it sounds like an ad, but I am a very happy user.
- linuxlizard 4y agoThose are all good selling points for me. Thank you! I'm building the Linux version now.
- prettyStandard 4y agoYou can submit a PR here: https://github.com/Soft-wa-re/password-manager-comparer https://github.com/Soft-wa-re/password-manager-comparer
- linuxlizard 4y agoSorry. You did say that already. I will. Thank you!
- burkaman 4y agoBitwarden has a useful status page that you can subscribe to with RSS: https://status.bitwarden.com/ https://status.bitwarden.com/ Would be happy to submit a PR, but I couldn't find a link to a repo and couldn't find the code on GitHub.
- prettyStandard 4y agohttps://github.com/Soft-wa-re/password-manager-comparer https://github.com/Soft-wa-re/password-manager-comparer
- RubberSoul 4y agoGreat overview! I think 1Password's Linux support has been improving [0]. I use 1Password with an Ubuntu desktop and have been happy with it. [0]: https://support.1password.com/explore/linux/ https://support.1password.com/explore/linux/
- softskunk 4y agoagreed. linux desktop is absolutely fine for me.
- prettyStandard 4y agoYou can submit a PR here. https://github.com/Soft-wa-re/password-manager-comparer https://github.com/Soft-wa-re/password-manager-comparer
- rdhyee 4y agoThanks for providing the detailed comparison among the many password managers. I think it's more accurate to describe 1Password's CLI as "yes" rather than "yes?poor" and submitted a PR for consideration: https://github.com/Soft-wa-re/password-manager-comparer/pull/2 https://github.com/Soft-wa-re/password-manager-comparer/pull...
- m-p-3 4y agoone thing I wish Bitwarden did is conditional username for URI I have some internal tools at work where you need to specify the domain, and some where you don't. Having two separate entries for these scenario is annoying, as I gotta update the password on both when I change it.
- Hackbraten 4y agoIt’s hardly working at all under Wayland. Copying to clipboard has been broken for at least 18 months. AgileBits doesn’t seem to care. [0] There are also sync issues (items created in the desktop app won’t appear in the browser extension unless I restart my browser), which aren’t occurring under Windows nor macOS. „Poor“ Linux support absolutely does the situation justice. [0]: https://1password.community/discussion/comment/667970 https://1password.community/discussion/comment/667970
- grahamplace 4y agoI’d be curious to know which one you personally use given all the research into the topic?
- dariusm5 4y agoI don't see any mention of local vaults on the page. Is there any password manager out there besides keepass that isn't cloud based?
- hjuutilainen 4y agoThere’s also Enpass (https://www.enpass.io/ https://www.enpass.io/) which markets itself as an offline password manager.
- eric-burel 4y agoI use and like it
- rkagerer 4y agoTwo questions: 1) How's it do at syncing / conflicts? 2) In the Android app, do you know if there's a way to use the fingerprint feature without storing your master password or an encrypted derivative of it to non-volatile memory? For those scratching their heads at #2, it's motivated by my lukewarm trust of vendor-implemented components of Android Keystore. Some competing apps address it by making you authenticate with the full password the first time after boot (or after the app is closed by the user / memory management system / configurable timeout) and just tie your fingerprint to an "unlock" pin of sorts that only works when the database is "hot".
- neodymiumphish 4y agoWhich apps handle this better? I'm not supremely concerned about my password being pulled from memory, from an attack surface perspective, but I am curious which apps address this best and how.
- rkagerer 4y agoNot saying it's the best out there (and the UI is a little clunky as it often flashes a pin input screen that gets skipped over when using your fingerprint), but I like how Keypass2Android can be configured to do it. When you select "Enable Biometric Unlock for Quick Unlock" (and don't disable the PIN feature) you can use your fingerprint as long as the app is still in memory, without it storing your master password. I know the Android Lastpass client would often prompt for a Master Password if it hadn't been used in a while, then let Fingerprints unlock it. I assumed it did something similar but haven't deep-dived the implementation.
- paranoidxprod 4y agoThanks for posting this. I was about to post an "Ask HN" to see what password managers people here are using, but this seems very helpful to compare the various services.
- flipbrad 4y agoKeepass and syncthing.
- paranoidxprod 4y agoAfter doing some more research, I've pretty much come to the conclusion I should be using KeePass (or KeePassXC) but I wasn't really sure how I should go about syncing. I will definitely look into Syncthing, thanks!
- dgrin91 4y agoThis is a cool page. One thing that is important for me that is lacking here is emergency access (e.g. https://www.lastpass.com/features/emergency-access https://www.lastpass.com/features/emergency-access). It would be great to see side-by-side comparisons of that.
- poopypoopington 4y agoyou should add apple keychain
- prettyStandard 4y agohttps://github.com/Soft-wa-re/password-manager-comparer/issues/5 https://github.com/Soft-wa-re/password-manager-comparer/issu...
- mrstone 4y agoSeems like a great product, but something about the URL is reminiscent of those scammy websites that try to trick you into downloading scamware.
- DrewADesign 4y agoI'm admittedly a hammer seeing everything as a nail, but as a designer, I see so many opportunities in FOSS lost to basic, unnecessary branding and usability oversights. Developers shouldn't expect themselves to be able to do good design work any more than designers should expect themselves to be able to make scalable, reliable, maintainable, production-ready code. It's a specialty for a reason! Incorporating designers into FOSS projects from the beginning seems like a no-brainer, but design is nearly universally considered a superficial matter to be considered once the real work of back-end development is done (which is generally never.) It's one of the reason that open source alternatives will remain the alternatives rather than the standards. Good design takes a lot of up-front work, and once you get ignored or bikeshedded into oblivion with one design proposal, the liklihood of doing it again is pretty much zero. Definitely my white whale, but it kills me to see so many great projects that could have so much more impact if they enfranchised specialists to design the look and feel.
- waboremo 4y agoOne of the great difficulty of tackling that problem is often FOSS projects are averse to design decisions like that made by someone relatively fresh to the project - even if the problem is incredibly obvious to the designers and not the core development team. You would have to spend a lot of time gaining trust to then be able to present an idea like switching domains. The duality of putting off design decisions until later, and also feeling like your current design is extremely personal (I've seen some projects where the maintainer immediately disregards a lot of proposals design wise because it's "good enough", as if that person just called their baby ugly), can make trying to make any progress on FOSS project feel horrible. It's a very interesting problem space I feel. There's so much room for improvement.
- 4y ago
- jxm262 4y agoThis is absolutely great. Thanks for sharing!
- gregmac 4y agoI see a few things that might be worth adding, as some were explicitly why I switched from LastPass a few years ago: * Security model. What is stored server-side unencrypted? In what circumstances is the server-side encrypted data available on the server in plaintext? * Defaults: "parent-safe"? What trade-offs are made with the defaults picked? * Ability to edit (Android) app associations. Bitwarden has this, and it solved a huge problem I had with duplicates on LastPass. There's URI entries like androidapp://com.example.app that are easy to manually merge and keep together with corresponding web sites. * Domain matching. Bitwarden can do: base, host, exact, starts with, or regex. Lastpass had an "equivalent domains" managed from obscure settings, which never really worked the way I wanted. I used to have a billion entries for things in .mydomain.com, but bitwarden fixes this and by setting that flag properly I get only relevant things for each internal app. At the same time, for .myapp.com and .myapp.local I can get the default dev login, so when I deploy a new instance/tenant for dev, it "just works". Username generation. Can it do plus-addresses? Catch-all domains?
- rkagerer 4y agoThis is helpful. Would love to see KeePass and its variants on here.
- password1 4y agoPlease change your domain, looks like a phishing website. I would never clic on that anywhere else on the internet.
- HollywoodZero 4y ago+1. The URL is a huge red flag since it's exactly how scammers create fake links online.
- Sephr 4y agoClicking on a 'phishing' link can't hurt, and it's not like this person's website is ever going to be presented to you in a sensitive context (e.g. "download/install software from this site"). You should trust that your browser is secure enough to render random webpages. Excuse the self-promotion, but I take it that you're also too wary to click on this link to read my blog: https://dangerous.link/virus.exe https://dangerous.link/virus.exe
- nkrisc 4y agoAny URL on the web could host a browser exploit that requires no interaction beyond visiting, but if I had to guess which one were most likely to, I'd put phishing links up there. > You should trust that your browser is secure enough to render random webpages. I honestly don't. Is dangerous.link/virus.exe any more dangerous than nytimes.com? Probably not. However if some 0-day, no interaction browser exploit does exist, it's easier to put the exploit on the some lookalike phishing domain rather than additionally exploit some mainstream site. Of course I can't possibly know what URLs are "safe" to click on and which ones aren't, but I'm going to guess that URLs that look like they're intended for a phishing campaign are less likely to be safe than any other. If your blog is go0gle-com.net, and someone emails or messages it to me, I'm not clicking on it and deleting the message. Most often what happens is I click some sketchy looking link on my phone and it attempts to hijack the browser with popups and history modifications and whatever other shit they do to let me know my Android iPhone is infected and must be cleaned immediately.
- 4y ago
- traceroute66 4y agoWhat's with "MacOS" vs "macOS" in the toggle features ?!?
- prettyStandard 4y agoJust a typo, my original work on this was to merge two forks of this, and that slipped through. I have pushed a fix now.
- cshokie 4y agoI don’t see an issues tab so I can’t open a bug report. There are two redundant checkboxes for MacOS (differing by capitalization).
- notlukesky 4y agoNever seen a url like that for such a project. FYI
- FatActor 4y agoSweet. I've been looking for this. I decided to ditch my home-grown solution and switch to a real manager this week. One note: 1Password uses WebAuth for Yubikey and LastPass uses text input. This makes LastPass work across *remote terminals* where you don't have access to the physical machine. Now, there might be a vulnerability lurking in there, but I often find myself working on a remote windows machine and need to log into something. Maybe this should be a footnote in your Yubikey row? Or its own row, if it isn't already in there and I missed.
- KomoD 4y agoBroken as hell for me. "no?yes" "unknown?yes" "1 undefined" "2 undefined" "3 undefined"
- notlukesky 4y agoI would second the change in the url. Good job though.
- fluidcruft 4y agoOne of the major features I'm looking for is the ability to easily list passwords by age. The use case is "I want an easy access "todo list" of all passwords to update that are older than (x months|specific date)" I would use this after notification of a breach or on my own schedule. Having to manually inspect each item is not acceptable. Bonus points if I can specify a "policy" for items (using tags and groups is acceptable if they can be incorporated into the search without too much effort). Super bonus points if the tool generates notifications and todo list automatically. Why these features are not standard boggles the mind. LastPass used to have this feature but removed it for who-know-why reasons.
- KennyBlanken 4y agoKeepassXC does this, probably other keepass clients too. There are columns for creation, modification, expiration, and last-access, all of which can be sorted on. Each entry can have an expiration date/age.
- wlll 4y agoFor some reason "MacOS" appears twice for me in the "options" section. I'd love for some more options. - Doesn't require a subscription - Doesn't require a web login - Allows local vaults
- deleted 4y ago[deleted]
- swyx 4y agomaybe one thing to add is "number of HN results above 50 points in the past 3 years" as a proxy for potential security issues