Time for new Password Manager

Status
Not open for further replies.

Solarlynx

Level 15
Verified
Top Poster
Well-known
Apr 30, 2012
711
Great advantage of BitWarden and KeePass is that they are open source. Lastpass is not an open source, but has available in freemium attractive options like country restriction and cloud backup for their authenticator app.
 

Unknownxoxo

Level 1
Verified
Sep 10, 2017
16
I'm currently using 1Password. It is no problem that you don't have 2FA because with a 1Password membership you got a secret key.

Security - 1Password

It works flawlessly on all my deviced. I'm using an iPhone an Macbook and a Windows PC. It also supports TOTP which is great
 

reystar

Level 3
Thread author
Verified
Feb 4, 2014
105
Great advantage of BitWarden and KeePass is that they are open source. Lastpass is not an open source, but has available in freemium attractive options like country restriction and cloud backup for their authenticator app.
Whats bad about not being open source?
 
  • Like
Reactions: Solarlynx

codswollip

Level 23
Content Creator
Well-known
Jan 29, 2017
1,201
Well you could not be sure if they dont have a backdoor in it.
Theoretically. But who does that (besides those who would seek to exploit a flaw). And how long would it take?

Not to overlook, but if you're using Windows/Mac/iOS/etc., your OS isn't open source. Even the most "secure" program is no better than its underlying OS.
 

mlnevese

Level 26
Verified
Top Poster
Well-known
May 3, 2015
1,540
I'm using Sticky Password and I'm quite satisfied with it. The browser plugins and Android client work quite well. I'd like them to add a share password feature though.
 
  • Like
Reactions: Garzaman
F

ForgottenSeer 58943

Hello folks :)

i feel the need to move to a new password manager after couple years of using Lastpass, not because that Lastpass is not good enough, it's that i need a change...

I have been looking a few ones like

BitWarden, 1Password, Dashlane so far are the ones i liked the most..

What do you recommend?
BitWarden is new and open source, seems really nice.
1Password is also nice, but i have concerns about the fact that there is no 2FA
Dashlane is also nice (lol)

The bad;
Dashlane - over the top logging/telemetry that makes me uncomfortable. Expensive. Shoddy support. Uses AWS.
1Password - no true TFA. Expensive. Several exploits found. Uses AWS, AWS API and AWS Cryptos.
PasswordBoss - buggy (back when I tried it), expensive, poor support, very buggy phone apps. AWS, AWS API, AWS Crypto.
Lastpass - No.. Please no.
Roboform - major security issues that have been well documented. Otherwise I like it and it doesn't use AWS or AWS keys.

The good;
Stickypassword - no compromises/exploits in their history. Stable, reliable and cheap with decent support. Uses AWS but not the AWS API and Cryptos.
Bit Warden - fantastic reliability/function, amazing support. Avoids AWS for security reasons, uses Azure but not Azure Crypto libraries. Zero Knowledge. OPENSOURCE.

Also don't overlook location/jurisdiction;

1Password - Canada
LastPass - USA (VA no less, wink)
Roboform - USA (VA again..)
StickyPassword - Czech Republic
Bit Warden - USA (Oklahoma) - but Opensource, review the code/libraries yourself.
Dashlane - USA (NYC)
PasswordBoss - USA (Minnesota)
 
Last edited by a moderator:

R2D2

Level 6
Verified
Well-known
Aug 7, 2017
267
What about 1password or dashlane? nobody uses them?

I use Dashlane Premium (among others) and have a 1Password account that was retained after a family account trial expired. But 1Password is not as good as the other password managers I use. However, my brother swears by 1Password on his Apple MacBook and iPhone. He is not willing to try another PM.

LastPass is introducing a family account this summer which should be interesting.
 

codswollip

Level 23
Content Creator
Well-known
Jan 29, 2017
1,201
Stickypassword - no compromises/exploits in their history. Stable, reliable and cheap with decent support. Uses AWS but not the AWS API and Cryptos.
Optionally, you can sync SP over your local LAN and avoid the 'net altogether. Works for me. I'm not a big fan of having my passwords stored in the cloud.
 
  • Like
Reactions: Garzaman

Unknownxoxo

Level 1
Verified
Sep 10, 2017
16
1Password - no true TFA. Expensive. Several exploits found. Uses AWS, AWS API and AWS Cryptos.

It uses a secret key which is the same with high entropy. Even if you are using a password like 1234 a hacker can't access your vault because they still need the secret key which is only on your device.

Could you explain the exploits and AWS etc a little bit more? I only know that 1Password has never been hacked compared to services like Lastpass.
 

vinylmeister

Level 2
Verified
Jan 29, 2015
96
I will always recommend KeePass. Free, open source, hostable on Google Drive, FTP a.s.o. Really no need to look elsewhere nor to spend money for a password manager.
 
  • Like
Reactions: Garzaman

Unknownxoxo

Level 1
Verified
Sep 10, 2017
16
I will always recommend KeePass. Free, open source, hostable on Google Drive, FTP a.s.o. Really no need to look elsewhere nor to spend money for a password manager.

True but it is not as comfortable as services like Enpass or 1Password. Also, iOS apps are not that good and setting it up so that you can use it in your browser is also not that easy.
 

vinylmeister

Level 2
Verified
Jan 29, 2015
96
True but it is not as comfortable as services like Enpass or 1Password. Also, iOS apps are not that good and setting it up so that you can use it in your browser is also not that easy.

Can't speak for Mac or iOS. But use the browser addons over all my workstations, hassle free. No matter if firefox or chrome...
 

VeeekTor

Level 5
Verified
May 16, 2017
197
Just an opinion:
1). I don't like web control of my passwords, so I choose to use ones that are confined to the desktop insted of on line.
2). If the password manager doesn't do autofill on web forms. I don't want it.
3). If the GUI is kinda funky, or hard to use...Just say no.
4). I don't need synch, so my choice will probably cost nothing.

***SO this leaves me with 2 choices... Dashlane (Which I love).... And Sticky Password (Which is my 2nd choice)
 

reystar

Level 3
Thread author
Verified
Feb 4, 2014
105
thing about stickypassword is that its new compared to the other ones and doesnt seem that popular
 
  • Like
Reactions: mlnevese
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top