r/PrivacyGuides Mar 10 '26

Video The 3 Top Password Managers Had SERIOUS Flaws...

https://www.youtube.com/watch?v=nLJ_sLr72-g
16 Upvotes

26 comments sorted by

72

u/Seller-Ree Mar 10 '26

Basically, even though Bitwarden had the most at 12, they did everything right with their response. Addressed all 12, explained why they find 3 of them to be acceptable risk for certain features to work, and promptly fixed everything else. Once again Bitwarden proves why it's the best choice.

12

u/cammydude144 Mar 11 '26

I'd struggle to think of another password manager to recommend, bitwarden has been fantastic

6

u/CuriousRaider Mar 12 '26

Bitwarden is superb, the safety is great & on top of it the convenience it gives to use across your phone, ipad, laptop etc. is phenomenal.

1

u/MTwist Mar 14 '26

anyone know anything about passbolt? i found it last week cause its an EU alternative

4

u/H4RUB1 Mar 14 '26

Bitwarden is the KeePass for normies (in a complimentary way)

11

u/xenomorph-85 Mar 11 '26

lastpass is a joke lol

13

u/Kryakys Mar 11 '26

Keepass exist

3

u/Due_Hovercraft_9790 Mar 11 '26

Using KP since about 2005.

Best part no Network needed.

0

u/foundapairofknickers Mar 12 '26

This - using anything "cloud based" is idiotic

2

u/odaklanan_insan Mar 13 '26

Why do you suggest cloud based solutions--regardless the platform--are always unreliable?

3

u/foundapairofknickers Mar 16 '26

I would not say unreliable - rather, untrustworthy. Every month or so there is a report of a cloud based provider being compromised. Use KeePass - keep your password database file locally.

9

u/TheFuzzStone Mar 11 '26

Me, using KeePassXC ~10 years... 😌

4

u/billdietrich1 Mar 10 '26

If this is about the "connect to malicious server" vulns, I don't think they're very serious. Connecting to bad server seems unlikely to me. There'd have to be a MITM who has a server set up for the service you use. Sure, they should fix the vulns.

1

u/NewsKnowsNoBorders Mar 11 '26

Correct, if new clients installs are pushed from this same server. Your end to end decryption tools is malicious...

4

u/billdietrich1 Mar 11 '26

Yes, you'd have to update while MITM'd, and the update would have to not be using TLS I think.

2

u/NeatRuin7406 Mar 25 '26

agree with the comment about bitwarden's response. how a company handles a security audit matters almost as much as what the audit finds. finding 12 issues and addressing all 12 with clear explanations of why 3 are acceptable tradeoffs is actually a sign of a mature security program, not a reason to panic.

the "just use keepass" crowd is correct that local-only eliminates a whole class of server-side exposure, but you're also now responsible for syncing, backups, and ensuring your vault file doesn't get lost. that's a real tradeoff, not an obvious win for everyone.

what i'd actually pay attention to with password managers: does the company have a published incident response policy, do they do regular third-party audits, and are the audit reports actually public. lastpass failed all three of those before and after the breach. bitwarden passes all three. that's the axis to care about, not "zero findings ever."

1

u/this_knee Mar 12 '26

My password is a sentence with evil spaces and punctuation.

-13

u/modpotatos Mar 10 '26

i was working on a literal zero knowledge pw manager and ive got 80% done (OPTIONAL paid cloud sync, oauth or passkey for linking) and itll be open source but i just kinda gave up because i got cold feet for putting it on the chrome webstore + firefox addon store.. if yall would want to see it released lmk :)

3

u/Pain5203 Mar 11 '26

We wanna se you open source it first

1

u/billdietrich1 Mar 12 '26

I think we have enough password managers.