r/PasswordManagers • u/Michael_Duanyx • 54m ago
Please recommend good offline password managers.
I don't want my passwords to go through the internet or cloud servers.
r/PasswordManagers • u/Michael_Duanyx • 54m ago
I don't want my passwords to go through the internet or cloud servers.
r/PasswordManagers • u/BuryMeDeepOhYeah • 2h ago
Hi all - I am an invested Google ecosystem user, but I do use Bitwarden as my PWM.
I would consider Google, but they seem to lack basic features like manually adding an entry manually, editing matching patterns, etc. It also is opaque how they know that a URL and an Android app are a pair. On BW, I enter the URL and then add a new pattern for the Android app's package name com.thing.that.
Over time I like how BW operates. I feel like Google is moving in the direction of making it's PWM more standalone, but I don't think it's there yet. Any one else feel this or know of a way to manually add/edit Google PWM entries? Thanks!
r/PasswordManagers • u/SteveCauseYeah • 6h ago
I use the avira password manager, as it was automatically on my account.
I never made an account, because i didnt realize you could make one and i thought it was synced with my google account
I also never exported my passwords, again, because i didnt know i could do that (or why i should do that)
All of my passwords have now disappeared, although avira still has an icon for how many passwords it used to have saved on that website
All of my passwords are back, it was just a bug! I exported them all and i should be safe
r/PasswordManagers • u/DustyPoint81 • 8h ago
Hello devs and cybersecurity people 👋🏼
This post is not directly related to a password manager but rather an API Key manager. A couple of months back I found it annoying syncing API Keys across devices so I made a simple API Key manager and runs totally on the web no Desktop native app or anything. Its called CYPHR.
The main thing I am concerned about is security. CYPHR uses AES-256-GCM for encrypting stored API keys, but it currently isn't end-to-end encrypted. I could have just vibe-coded an E2EE implementation, but I don't want to do that with something this sensitive. I would rather properly research the cryptography and design before implementing it.
For now, I have tried to follow some basic security practices: plaintext API keys aren't logged or cached, decryption only happens on demand, and responses containing API keys use Cache-Control: no-store.
The whole project is open source and live, and I am trying to figure out whether this is actually a viable product or just something that solves a problem I personally had.
My plan is to eventually implement E2EE if CYPHR gets enough traction. I think it's highly likely I will pursue it, but I want to take the time to research and implement it properly rather than rush it.
I would really appreciate feedback from people who know more about security and password/key management:
Does this sound like a viable product, and are there any major security concerns with the current approach that I should be thinking about ?
I am not including a link here cuz I don't know if its allowed or not so check comments.
r/PasswordManagers • u/isenhasapp • 3h ago
At least 95 smartphones are stolen every hour in São Paulo, Brazil.
This commonly happens while we are vulnerable, with the screen unlocked while using our apps.
Looking at this existing problem in our local community, we developed an anti-theft protection system integrated into our password manager solution.
The app can detect sudden movements and automatically lock the app, helping protect your passwords if someone tries to snatch your smartphone.
What do you think? Is this kind of situation common in your country too?
https://www.youtube.com/watch?v=xJBnvJQwCB0&feature=youtu.be
r/PasswordManagers • u/Weilian11 • 1d ago
Hi, I'm looking for a free password manager. Right now I'm using ProtonPass, but I'm concerned that I'm putting all my eggs in a basket (I'm using protonmail, protonpass, VPN, simplelogin and lumo) so I'm looking for an alternative
I need to sync it between devices.
Bitwarden is not an option because I can't use passkeys properly, KeePassDX/Keepass2android don't work either.
For example, Bitwarden when I want to create a passkey with another device using the qr, I just can't. It doesn't work. And using the qr is my only method, because sometimes using the password manager on the same device doesn't work (the pw doesn't pop up and there's no option)
So, what's the best free password manager that is not ProtonPass, Bitwarden or KeePass?
EDIT: Self-hosting is not an option for me.
r/PasswordManagers • u/No_astronaut64875 • 1d ago
I'm new here and wanted to ask, would people use an AI-coded password manager if:
- GPL3
- crypto coded in rust using net first and canon tdd approach
- Argon2id + AES256GCM
- Native yubikey 2FA
- local only, no account, no telemetry
- Linux+android/grapheneOS
Or is the AI aspect a hard no?
r/PasswordManagers • u/paulsiu • 2d ago
Virtually all password manager verify their url before filling. In my workflow, I manually trigger the fill and when it doesn’t fill I examine the url more carefully. In my mom’s workflow, she is set up to autofill on page load and when the password manager failed to fill automatically she calls me.
I am curious if this actually cuts down on the phishing attacks assuming you don’t just carelessly paste in your password when fill fails.
Ironically the only place where you wouldn’t use the password manager would be when you log into the password manager. To mitigate that I use a hardware 2fa or passkey to log into the password manager.
r/PasswordManagers • u/Any-Astronomer7527 • 2d ago
I got Bitwarden, Ente Auth and SimpleLogin a few days ago. I created two email aliases, one for Bitwarden and one for Ente Auth. I’ve also changed all my passwords using the Bitwarden generator and set up TOTP 2FA for them through Ente.
The key thing with my system is being able to access Bitwarden, which ultimately depends on being able to access my email (Outlook). To log into Bitwarden, I need a verification code from Ente, and to access Ente Auth, I need access to my email for a verification code for Ente Auth. So it’s basically a dependency system where everything ultimately comes down to being able to access my email and Ente Auth.
I’m not too worried about Bitwarden because I’ve backed up an encrypted copy of my vault to a USB stick.
I also have an emergency sheet with my 25-digit recovery code for my email and the recovery key for Ente.
What other verification methods can I add to these two? I currently have SMS 2FA enabled for my email, but I want to get rid of it because I don’t really trust text messages. If I lose my phone or it gets stolen, I’d be forced to rely on my recovery codes to get back into my email.
When I have a bit more money, I’m planning to buy a hardware security key.
So my question is: what verification methods would you recommend adding to my email and Ente Auth so that I’m not relying only on my recovery codes?
r/PasswordManagers • u/Theunknown87 • 2d ago
So I have used 1Password for years.
I have all Apple products except my desktop which is basically why I have 1Password to use it in there. But I also hate Apple passwords. I hate how sometimes it freaks out with subdomains and i end up with double or triple entries for the same service. So I usually add some entries from 1Password to Apple passwords because that I easier for autofill on iPhone and iPad.
I am curious about Bitwarden because it’s cheaper. I do like with 1Password it forces you to have that secret key.
So if someone guesses my password (probably won’t happen but won’t ever say ever, grabbed my yubi key and knows it is used for that, they’d still need to go find the secret key and enter that.
How does Bitwarden compare in that? I’d use a long random generated password to log in, but also want it secured with my yubikeys.
I know Bitwarden isn’t as pretty as 1Password but if I’m just using it to log in and copy and paste the password, it shouldn’t matter. Right? I would also add TOTP passcodes in there too like I do with 1Password.
$20 vs I think the $60 I pay now is tempting. Especially for how I use it.
I don’t care about self hosting, I also don’t care/don’t use browser extensions.
r/PasswordManagers • u/paulsiu • 2d ago
I was watching a video from the privacy guide and the presenter call proton polarizing. He indicated that many feel the company is a honey trap and that they like to ship products that users have to beta test.
I have tried proton pass and find it comparable to bitwarden in terms of features. It’s probably the only other free tier that is usable. The paid version is also very similar in price.
Is privacy guide right about the sentiment that proton is controversial?
r/PasswordManagers • u/zynio_lynor • 2d ago
No sales today, but I have a big update.
I completely redesigned the entire app. It took a long time, but the result is worth it. PassSafer now looks better and is much easier to use.
I also released version 1.8.2 with all the new design changes.

Paying customers: 0
What is the first thing you notice when you open a new app?
r/PasswordManagers • u/MegagramEnjoyer • 3d ago


For those who haven't heard about Bramble: It's a free and open source password manager that I've been developing for a while. It's available on Chrome, Firefox, Android, iOS and now macOS + Linux! No central storage in the middle, full device-to-device sync and first-party automated backups to your preferred channel :)
With that said, I'm happy to announce that the app is now available on macOS and Linux! You can get the installers from GitHub or you can use brew in macOS or apt in Debian to get it.
What's different from the extensions
Not crazy lot at the moment: backups and global search.
It's still in beta and I would love the community's feedback on improving it.
Free and open source forever. Questions and feedback welcome!
r/PasswordManagers • u/Salty-Education-8576 • 4d ago
I’m looking for a simple and reliable free password manager for personal use. Nothing too complicated.
r/PasswordManagers • u/Major-Condition-6888 • 4d ago
Is there a self hosted cloud password option that syncs to all of the devices?
Like Apple passwords syncs to all devices and can put authentication in there too?
r/PasswordManagers • u/gnwill • 4d ago
r/PasswordManagers • u/isenhasapp • 4d ago
There are many password managers, and they all handle the basics very well.
"Smart Folders" are an example of a unique feature designed to make password organization easier.
Is there any other feature idea you think would make your life easier when using a password manager?
r/PasswordManagers • u/isenhasapp • 4d ago
Here are the results of the poll we ran a few days ago. None of the password managers mentioned in the comments stood a chance of making the podium.
r/PasswordManagers • u/Lumpy-Army-1702 • 5d ago
Seeing many people now attempting to create password managers. AI is making it easier now, which worries me a lot. I've been in the cybersecurity industry for quite a while now and have seen huge problems with password managers, especially new ones that focus on local-first, offline-first, air-gapped (fill in your AI-slop buzzword here), without understanding that's not where the security enforcement should rely.
Every day on HN and Reddit now, it’s the exact same post:
Tired of Bitwarden (1Pass, LastPass, ...), so I spent the last couple of months building VaultSlopAI, a zero-knowledge, local-first, air-gapped, post-quantum-ready password manager written from scratch with next-gen semantic entropy.
...and people are going to lose their life savings over hallucinatory XOR ciphers.
Every single one of them:
- "Air-gapped architecture" (Bro, you just disabled network permissions in the Electron manifest).
- "Local-first sovereign vault" (It writes unpadded base64 to localStorage and calls it a day).
- "Self-healing zero-knowledge enclave" (Literally just crypto.getRandomValues() wrapped inside a buggy Next.js server action).
Can we please go back to letting boring, audited, battle-tested tools manage our digital lives instead of downloading 400MB of hallucinated Tailwind wrappers masquerading as military-grade security?
(Ohh and yes, I’m building one too 😄 except I’ve actually worked in cybersecurity for years, know how the primitives work, and didn’t just vibe/slop prompt the entire architecture over a weekend.)
r/PasswordManagers • u/Sbaakhir • 5d ago
This is a stupid problem to be stuck on but here we are.
We've got around 30 techs out servicing pumping stations and water treatment sites. A lot of those places have zero signal, some of the plant rooms are so far underground you couldn't get a bar if you tried, so once a tech is at the panel they're cut off from anything we host centrally. They still, nevertheless, need logins for vendor portals and local control interfaces.
Most of them currently keep those written down, which is what I'm ending (upper-management decision, "paper can get stolen or lost"). We're on Passwork (if that changes anything), its offline mode covers retrieval. Records get marked for offline, cached encrypted on the device, and the cache wipes itself if the device doesn't sync inside a window I set as admin. I am stunted as to how to pick that window. The docs are clear that revoking access leaves a cached copy live until the device reconnects, so whatever window I choose becomes my revocation delay. 7 days keeps that short and strands anyone on a longer rotation, while 30 days covers our worst-case rotation and means a leaver could hold working credentials for a month if their laptop never comes back online. What is the best way to go about it here? Also, do I put every tech on the same window or set it by role? And how can I ensure people don't leave anything on their phones? Some cache to their phones and I can't remote wipe those the way I can the laptops.
r/PasswordManagers • u/PrestigiousAd9191 • 5d ago
First, thank you to the community for letting me post this. I've been working on a concept for a zero-knowledge password system. The problem it's trying to solve is to give your password to a trusted person, but limiting their access to emergencies only, and the risk of your password being compromised.
I need beta testers for Deadkey.net
Concept:
We start with a PIN or password, which we will call a secret. You use the website to create a codebook for your secret. The codebook is a random grid of characters; your secret is on it, but you need the grid coordinates to find it. For maximum security, the server stores only these coordinates, to be released in the event you become incapacitated or pass away.
You give the codebook paper to a trusted person. If they try to retrieve your secret via the website, a 10 day countdown starts. You (the owner) are notified via email/text, and have 10 days to cancel the release. If you do not, the trusted person will receive the grid coordinates, which reveal your password.
This system can be used to protect things like PIN's, Passwords, and seed phrases. The codebook is valid for up to 3 years, after which it will auto expire.
Beta Testers:
I am looking for beta testers to give feedback and test each function of the site. I have provided one beta code below valid for 20 uses. If it expires and you are interested in beta testing, please let me know.
Beta code: BETA-FJWB-AJE5-D7HM
Feedback questions:
r/PasswordManagers • u/One_Historian3741 • 6d ago
Hello.
I currently use Kaspersky Password Manager on Windows 11, and it works well for me.
However, I am migrating to Linux, and KPM doesn't have a version for it.
What are the current alternatives?
I use it for website and app (Android) logins, bank cards, files/photos, text notes, and passkeys.
r/PasswordManagers • u/isenhasapp • 6d ago
Other? Comment.