Password Manager Roundup
If you can remember all of your passwords, they're not good passwords.
I used to teach people how to create "good" passwords. Those passwords needed to be lengthy, hard to guess and easy to remember. There were lots of tricks to make your passwords better, and for years, that was enough.
That's not enough anymore.
It seems that another data breach happens almost daily, exposing sensitive information for millions of users, which means you need to have separate, secure passwords for each site and service you use. If you use the same password for any two sites, you're making yourself vulnerable if any single database gets compromised.
There's a much bigger conversation to be had regarding the best way to protect data. Is the "password" outdated? Should we have something better by now? Granted, there is two-factor authentication, which is a great way to help increase the security on accounts. But although passwords remain the main method for protecting accounts and data, there needs to be a better way to handle them—that's where password managers come into play.
The Best Password Manager
No, I'm not burying the lede by skipping all the reviews. As Doc Searls, Katherine Druckman and myself discussed in Episode 8 of the Linux Journal Podcast, the best password manager is the one you use. It may seem like a cheesy thing to say, but it's a powerful truth. If it's more complicated to use a password manager than it is to re-use the same set of passwords on multiple sites, many people will just choose the easy way.
Sure, some people are geeky enough to use a password manager at any cost. They understand the value of privacy, understand security, and they take their data very seriously. But for the vast majority of people, the path of least resistance is the way to go. Heck, I'm guilty of that myself in many cases. I have a Keurig coffee machine, not because the coffee is better, but because it's more convenient. If you've ever eaten a Hot Pocket instead of cooking a healthy meal, you can understand the mindset that causes people to make poor password choices. If the goal is having smart passwords, it needs to be easier to use smart passwords than to type "password123" everywhere.
The Reason It Might Work Now
Mobile devices have become the way most people do most things online. Heck, Elon Musk said that we've become cybernetic beings, it's just that the bandwidth to our cybernetic components is really slow (that is, typing on our phones). It's always been possible to have some sort of password management app on your phone, but until recently, the operating systems didn't integrate with password managers. That meant you'd have to go from one app into your password manager, look up the site/app, copy the password, switch back to the app, paste the password, and then hope you got it right. Those days are thankfully in the past.
Both recent Android systems and iOS (Apple, not Cisco) versions allow third-party password managers to integrate directly into the data entry system. That means when you're using a keyboard to type in a login or password, in any app, you can pull in a password manager and enter the data directly with no app switching. Plus, if you have biometrics enabled, most of the time you can unlock your password database with a fingerprint or a view of your face. (For those concerned about the security of biometric-only authentication, it can, of course, be turned off, but remember how important ease of use is for most people!)
So although password managers have been around for years and years, I truly believe it's only with the advent of their integration into the main operating system of mobile devices that people will actually be able to use them widely. Not all Linux users will agree with me, and not all people in general will want their passwords available in such an easy manner. For the purpose of this article, however, a mobile option is a necessity.
A Tale of Two Concepts
Remember when "the cloud" was a buzzword that didn't really mean anything specific, but people used it all the time anyway? Well, now it very clearly means servers or services run on computers you don't own, in data centers you don't control. The "cloud" is both awesome and terrible. When it comes to storing password data, many people are rightfully concerned about cloud storage. When it comes to password managers, there are basically two types: the kind that stores everything in a local database file and those that store the database in the cloud.
The cloud-based storage isn't as unsettling as it seems. When the database is stored on the "servers in the sky", it's encrypted before it leaves your device. Those companies don't have access to your actual passwords, just the highly encrypted database that holds them—as long as you trust the companies to be honest about such things. For what it's worth, I do think the major companies are fairly trustworthy about keeping their grubby mitts off your actual passwords. Still, with the closed-source options, a level of trust is required that some people just aren't willing to give. I'm going to look at password managers from both camps.
I picked five(-ish) password managers for this review. Please realize there are dozens and dozens of very usable, very secure, password managers for Linux. Some are command-line only. Some are just basic PGP encryption of text files containing user name/password pairs. Today's review is not meant to be all-encompassing; it's meant to be helpful for average Linux users who want to handle their passwords better than they currently do. I say five(-ish), because one of the entries has multiple versions. The list is:
- KeePass/KeePassX/KeePassXC: this is the one(-ish) that has multiple variations on the same theme. More details later.
I highlight each of these in this article, in no particular order.
Your Browser's Password Database
Most people don't consider using their browser as a password manager a good idea. I'm one of those people. Depending on the browser, the version and the settings you choose, your passwords might not even be encrypted. There is also the problem of using those passwords in other apps. Granted, if you use Chrome, your Android phone likely will be able to access the passwords for you to use in other apps, but I'm simply not convinced the browser is the best place to store your passwords.
I'm sure the password storage feature of modern browsers is more secure than in the past, but a browser's main function isn't to secure your passwords, so I wouldn't trust it to do so. I mention this option because it's installed by default with every browser. It's probably the most widely used option, and that breaks my heart. It's too easy to click "save my password" and conveniently have your password filled in the next time you visit.
Is using the browser's "save password" function better than using nothing at all? Maybe. It does allow people to use different passwords, trusting the browser to remember them. But, that's about it. I'm sure the latest browsers have the option to secure the passwords a bit, but it's not that way by default. I know this, because when I sit at my wife's computer, I simply start her browser (Chrome), and all her passwords are filled in for me when I visit various websites. They've almost made it too easy to use poor security practices. The only hope is to have better options that are even easier—and I think we actually do. Keep reading!
The KeePass Kraziness
First off, these password managers are the ones that use a local, non-cloud-based database for storing passwords. If the thought of your encrypted passwords living on someone else's servers offends your sensibilities, this is probably the best choice for you. And it is a really good choice, whichever flavor you pick.
The skinny on the various programs that share similar names is that originally, there was KeePass. It didn't have a Linux version, so there was another program, KeePassX, that used an identical (and fully compatible) database. KeePassX runs natively on Linux, along with the other major OSes. To complicate issues, KeePass then released a Linux version, which runs natively, but it uses Mono libraries. It runs, and it runs fine, but Mono is a bit kludgy on Linux, so most folks still used KeePassX. Then KeePassXC came around, because the KeePassX program was getting a little long in the tooth, and it hadn't been updated in a long time. So now, there are three programs, all of which work natively on Linux, and all of which are perfectly acceptable programs to use. I prefer KeePassXC (Figure 1), but only because it seems to be most actively developed. The good news is, all three programs can use the exact same database file. Really. If there is a single ray of sunshine on a messy situation, it's that.
Figure 1. KeePassXC has a friendly, native Linux interface.
- Local database file, with no syncing mechanism.
- Database can be synced by a third party (such as Dropbox).
- Supports master password and/or keyfile unlocking.
- Very nice password generator (Figure 2).
- Secure localhost-only browser integration (KeePassHTTP).
- No cloud storage.
- Command-line interface included.
- 2FA abilities (YubiKey).
- Open source.
- No "premium" features, everything is free.
- No cloud storage (yes, it's a pro and a con, depending).
- Brand confusion with multiple variations.
- Requires third-party Android/iOS app for mobile use.
- More complicated than cloud-based alternatives (file to sync/copy).
Figure 2. The KeePassXC password generator is awesome. I don't even use KeePassXC for my password manager, but I still like the generator!
The KeePass family of password managers is arguably the most open-source-minded option of those I cover here. Depending on the user, to handle syncing/copying the database rather than depending on an unknown third party to store the data has a traditional Linux feel. For those folks who are most concerned about their data integrity, a KeePass database is probably the best option. Thankfully, due to third-party tools like KeePass2Droid (for Android) and MiniKeePass/KyPass for iOS, it's possible to use your database on mobile devices as well. In fact, most apps handle syncing your database for you.
I didn't know the Bitwarden password manager even existed until we did a Twitter poll asking what password managers LJ readers used. I have to admit, it's an impressive system, and it ticks almost all the "feel good" boxes Linux users would want (Figure 3). Not only is it open source, but also the non-premium offering is a complete system. Yes, there is a premium option for $10/year, but the non-paid version isn't crippled in any way.
Figure 3. Bitwarden is very well designed, and with its open-source nature, it's hard to beat.
Bitwarden does store your data in its own cloud servers, but since the software is open source, you can examine the code to make sure the company isn't doing anything underhanded. Bitwarden also has its own apps for Android/iOS and extensions for all major browsers. There's no need to use a third-party tool. In fact, it even includes command-line tools for those folks who want to access the database in a text-only environment.
- Cloud-based storage.
- Decent password generator.
- Native apps for Linux, Windows, Mac, Android and iOS.
- Browser extensions for all major browsers.
- Options to store logins, secure notes, credit cards and so on.
- One developer for all apps.
- Cloud-based access.
- Works offline if the "cloud" is unavailable.
- Free version isn't crippled.
- Browser plugin works very well.
- Database is stored in the cloud (again, it's a pro and a con, depending).
- Some 2FA options require the Premium version.
Bitwarden Premium Version:
- Additional 2FA options.
- 1GB encrypted storage.
I'll admit, Bitwarden is very, very impressive. If I had to pick a personal favorite, it probably would be this one. I'm already using a different option, and I'm happy with it, but if I were starting from scratch, I'd probably choose Bitwarden.
1Password is a widely used program for password management. But honestly, I'm not sure why. Don't get me wrong; it works well, and it has great features. The problem is that I can't find any features it has over the alternatives, and there isn't a free option at all.
There's also no native Linux application, but the 1PasswordX browser extension works well under Linux, and it's user-friendly enough to use for things other than browser login needs. Still, although I don't begrudge the company for charging a fee for the service, the alternatives offer significant services for free, and that's hard to beat. Finally, 1Password utilizes a "secret key" that's required on each device to log in. Although it is an additional layer of security, in practice, it's a bit of a pain to install on each device.
- Cloud-based storage.
- Non-login data encryption (Figure 4).
- Printable "emergency kit" for recovering account.
- Cross-platform browser extension.
- Offline access.
- Easy-to-use interface.
- Very good browser integration.
- $3/month, no free features.
- Secret-key system can be cumbersome.
- No native Linux app.
- Proprietary, closed-source code.
1Password Premium Features:
- All features require a monthly subscription.
Figure 4. 1Password has a great interface, and it stores lots of data.
If there weren't any other password managers out there, 1Password would be incredible. Unfortunately for the 1Password company, there are other options, several of which are at least as good. I will admit, I really liked the browser extension's interface, and it handled inserting login information into authentication fields very well. I'm not convinced it's enough for the premium price, however, especially since there isn't a free option at all.
Okay, first I feel I should admit that LastPass is the password manager I use (Figure 5). As I mentioned previously, if I were to start over from scratch, I'd probably choose Bitwarden. That said, LastPass keeps getting better, and its integration with browsers, mobile devices and native operating systems is pretty great.
Figure 5. I seldom use anything other than LastPass's browser extension, unless I'm on my mobile device, but the app looks very similar.
LastPass offers a free tier and a paid tier. Not too long ago, you had to pay for the premium service ($2/month) in order to use it on a mobile device. Recently, however, LastPass opened mobile device syncing and integration into the completely free offering. That is significant, because it brings the free version to the same level as the free version of Bitwarden. (I suspect perhaps Bitwarden is the reason LastPass changed its free tier, but I have no way of knowing.)
- Cloud-based storage.
- Native apps for Linux, iOS and Android.
- Offline access.
- Cross-platform browser extension.
- Cloud-based storage.
- Very robust free offering.
- Smoothest browser-based password saving (in my experience).
- Data stored in the cloud (yes, it's a pro and a con, depending).
- Rumored to have poor support (I've never needed it).
- Proprietary, closed-source code.
- Gives 1GB online file storage.
- Provides the ability to share passwords.
- Enhanced 2FA possibilities.
- Emergency access granting (Figure 6).
Figure 6. This is sort of a "deadman's" switch for emergency access. It allows you to give emergency access to someone, with the ability to revoke that access before it actually happens. Pretty neat!
LastPass is the only option I can give an opinion on based on extended experience. I did try each option listed here for a few days, and honestly, each one was perfectly acceptable. LastPass has been rock-solid for me, and even though it's not open source, it does work well across multiple platforms.
Honestly, with the options available, especially those highlighted today, it's hard to lose when picking a password manager. I sort of picked the top managers, and gave an overview of each. There are other, more obscure password managers. There are some options that are Linux-only. I decided to look at options that would work regardless of what platform you find yourself on now or even in the future. Once you pick a solution, migrating is a bit of a pain, so starting with something flexible is ideal.
If you're concerned about someone else controlling your data (even if it's encrypted), the KeePass/KeePassX/KeePassXC family is probably your best bet. If you don't mind trusting others with your data-syncing, LastPass or Bitwarden probably will be ideal. I suppose if you don't trust "free" products, or if you just really like the layout of 1Password, it's a viable option. And I guess, in a pinch, using browser password management is better than nothing. But please, be sure the data is encrypted and password-protected.
Finally, even if none of these options are something you'd use on a daily basis, consider recommending one to someone you care about. Keeping track of passwords in a secure, sync-able database is a huge step in living a more secure online lifestyle. Now that mobile devices are taken seriously in the password management world, password managers make sense for everyone—even your non-techie friends and family.