I use it currently, but I’ve seen a few people say it’s bad for privacy or something? Is this true? If so, what alternatives do you suggest?

  • quaver@lemmy.ml
    link
    fedilink
    arrow-up
    2
    ·
    edit-2
    4 years ago

    LessPass and Spectre are really bad ideas. They sounded cool to me too until I thought about it more.

    If your password for one site is compromised, you can’t change it, ever, which is already a dealbreaker. Moreover, the algorithm for creating the password is very fast - which means that if someone finds out your password for one service, they can brute force your master password extremely fast relative to other password managers. And they don’t even need access to your vault. Keep in mind, I’m not a security expert at all so I might be wrong about this.

    Bitwarden and Keepass XC are the only password managers I recommend because attackers need access to your vault/database to be able to crack anything, and the cryptography used is intentionally slow as to make brute forcing less practical. The most ideal is to self host or use an offline database like Keepass does, which makes the risk of your database being compromised practically zero unless you’re some high profile target.