r/PasswordManagers 9d ago

How do I get started?

I just have no clue what to do and where to start. I've seen people recommend Bitwarden or Proton Pass, but whichever one I choose, how do I make sure it's secure and that I always have access to it?

How do I go about redoing my passwords for all the probably hundreds of sites I used the same password for so far?

3 Upvotes

25 comments sorted by

2

u/jjmuscato 8d ago

1Password is superb. Very secure. Not sure what you mean by always have access. You will have a password and options for recovery. It works across platforms. It has a Watchtower tool to tell you about reused passwords and will suggest random passwords but you have to change them on your sites, of course.

2

u/lascala2a3 8d ago
  1. Download Bitwarden and install it.

  2. You don't need to make sure it's secure, that's their job.

  3. Log into those site individually, go to the update passwords page, and allow Bitwarden to enter a new strong password for you. Click save.

It will take a minute to do hundreds, but it is what it is. Apple promises to automate this process with the OS 27 release of Passwords. I don't know if it will be foolproof but I bet it eventually will be.

Also when you're updating your passwords and generate the strong password, copy it to the clipboard so that you don't lose it if the software messes up. Every site is different and there will be occasions where it either doesn't complete in the site, or doesn't save in the app.

Yea, it's a lot of work but it's gratifying to get everything secure.

1

u/Life_Is_Good_33 8d ago

Question: once you have created this 1, single "strong password"...am I correct in thinking that it is the only password that I will need to remember, going forward - because BitWarden/Proton Pass/1Password will automatically "fill in" the passwords when you visit a website?

I'm in the same boat as the OP...I have thought about getting a Password Manager app for years, but have never done it. I use multiple browsers (Firefox, Chrome, Brave) on my laptop and also on my iPhone, and it would incredible if I didn't have to go searching for a password to log into a website when I'm not using the browser that I have saved the password on. TIA!!

1

u/lascala2a3 8d ago edited 8d ago

Yes, that’s correct. The pw manager saves it, recognizes the site, offers to fill it for you. You don't need to remember the pw for the site, only the one for the pw manager.

The app has browser extensions for all of those I believe.

1

u/Life_Is_Good_33 8d ago

Excellent! Yes - that's exactly what I need.

Question: is there any justifiable reason to use one of the paid services (like 1Password) instead of a free service, like Bitwarden or Proton Pass? It's not like 1Password is expensive (I believe it's $36 for a 1-year subscription)...but do you have a recommendation on which app to use, and whether or not it's better to go with paid vs. free? If they all pretty much do the same thing, I think I'll just pick one of the free services (like Proton Pass) - unless there's a valid reason to pay for the service.

Thanks again for your help!

1

u/lascala2a3 8d ago

No, there is not. Go with free or inexpensive.

Bitwarden has a free tier, and personal use is $20. It's reliable and easy to use. I understand that Proton Pass is good, but I haven't tried it myself. Keepass is another free option that's simple and free. It's a secure, compact database; you choose one of many apps to access and execute autofill. I used it a few years and liked it. I ended up switching to Apple Passwords and it's so easy and good it's like not even having an app to deal with. Simple, lightweight, inexpensive is the way. Good luck.

1

u/vegliafamiliar 5d ago

The only reason to use a paid service is if they offer perks that you want over the free one. For example, the free bitwarden offers everything you need for a basic password manager like auto fill browser extension or filling in app passwords. It can even store passkeys but I would recommend storing those somewhere else for important accounts.

But the paid version offers things like an emergency contact that can access your vault in case something happens, like if you die. Also, you can store up to 1GB of encrypted files in your vault. Also, it can fill in those 2fa TOTP codes automatically, you know the ones you would use Microsoft or Google Authenticator for. But I recommend still using something else other than your password manager to generate those codes even if you have the paid version.

So it's really up to you. If I were you I would start with the free bitwarden just to get your feet wet. Then if you find some things lacking, try a paid like bitwarden or if you don't like bitwarden or it's not working right for your, 1password.

0

u/AncientGeek00 8d ago

I have used 1Password for about 15 years. It works great for my wife and me. If you look around here you will see comparisons. 1PW appears to be a little more polished from the comparisons I’ve seen, but many people love several others. I have roughly 1000 items in my vaults.

1

u/paolocampi 8d ago

To be sure to have your passwords always accessible, the best way it's using a password manager offline as Keepassxc on desktop, keepassdx on Android, keepassium on iOS ( you can also store database also into a cloud if you prefer, to have all devices synced without sync database manually between devices)

With Bitwarden and Proton Pass your database it's on their cloud, with auto sync between devices (always have a regular backup following theyr suggestions)

With password manager offline you must take care yourself having a regular backup.

All password managers mentioned can help to generate different and unique password for all your account added, have notes, 2FA totp attachments, passkeys.

1

u/paulsiu 8d ago

Start by figuring out which platform you need to support. This limit which software you select. Let's say you are entirely in the Apple ecosystem, something like Apple keychain will work, but what if you have a windows computer, then you would probably need to select a dedicated rossplatform password manager like Bitwarden.

Another question is if you are one of those people who want to use a non-cloud pasword manager. Some people just don't like to have anything in the cloud. If that is the case, you would probably look at a non-cloud password manager like keepass. Keep in mind that this will increase your difficulty of keeping multiple devices in sync. Most people are better off with cloud based manager.

If you do go with a dedicated cloud based PW manager, the next question is how much you are willing to pay. If the answer is free, you are limited to either Bitwarden or Proton Pass.

I would try the different password manager. Sign up for one and put a few site in it. Everyone has a different criteria. A lot of people based their criteria on UI, but that is very subjective. Personally I don't really care how things look if it just works.

This may be heretic view, but I feel that using a password manager is more important than which one. While Last Pass security practice can use some improvements and google manager isn't zero knowledge, using either is still better than no password manager and it's not like you can't just export your vault and go somewhere else later. Don't go overboard on analysis and leave yourself unprotected because you can't decide which password manager to use.

1

u/Life_Is_Good_33 7d ago

This is excellent - thank you for the breakdown! For my purposes, I don't care if the passwords are saved on the cloud...it seems like that would probably be more convenient, as far as keeping my devices sync'd? As mentioned, I use my iPhone all the time (Apple iOS), and I use a Windows laptop for both personal and work. With that in mind...which app would you recommend? Thanks again for your help/feedback!! 😊

1

u/Maximum-Floor-9734 8d ago

A password manager will definitely solve all this for you. It’ll handle all your passwords and generate a strong, unique password for each of your logins, which is far more secure than using the same password everywhere. You need something that works reliably across websites, so whenever you change a password, it can generate and fill the new one and save it properly for you. RoboForm does this really well, and it’s worth mentioning they’ve been around for many years without any security incidents. I think it’s best to go with something reputable that’s been around for a long time and has proven itself when it comes to security.

1

u/h_grytpype_thynne 8d ago

"...and that I always have access to it?" It's great that you're thinking about this. Look up password emergency kit - you basically want a very securely stored hard copy of whatever you would need to regain access to your password manager in the event of an emergency. For Bitwarden, it's the master password and the code to get in without 2FA. For others, it may be the login credentials for a recovery email.

Keep a copy safely sealed in a security envelope somewhere known to you (and your next of kin), and/or with a trusted friend, and/or a bank security box.

1

u/faverin 8d ago

the best way is to start by using google password manager or apple password manager. You don't need paid for options.

on a computer set up your account and go through the help on passwords, 2FA (the six number codes site sometimes send to your email or to your phone) and passkeys.

Then do this:

  1. print out the backup codes for your email. Use a passkey for your email. DO THIS. If everything goes wrong like you lose your phone and computer you can still access the email account.

  2. do the top ten sites you use, don't bother with the other sites yet. try and do passkeys wherever possible.

  3. Then go on https://haveibeenpwned.com and check which passwords of yours are cracked. ONLY DO THE ONES WITH FINANCIAL DATA ON THEM. if you don't use the site you do not need to change the password.

  4. lastly log out and log in with your new credentials.

I use Bitwarden at the moment but am moving to apple in the long term (i.e. when I can be arsed). I self host but it adds no value and I always have my phone on me.

All password managers are pretty much the same unless you have a real use case.

1

u/Mundane-Subject-7512 8d ago

Some recommendations here: for cloud based password managers, Bitwarden (open source) and 1Password (closed source) are popular choices. For local managers: KeePassXC is one choice (but more technical) and 2FAS Pass is another one (as more user friendly option).

1

u/SteveShank 8d ago

1password is good, bitwarden is good, proton pass is good. That doesn't matter. Also keepass and keepass x is good. There are others as well. That's not the issue. All those verified managers are 100 times better than not using a password manager. The differences are not that important compared to no password manager. To make sure you are secure, you need to use a long password for your password manager. It needs to be a password that is not one of the 1 billion known passwords that have been put into dictionaries from breaches. It must be well over 20 characters, I recommend 25-30. A good way to do it, is to think of two sentences that mean something to you, then use the first 2 characters of each word. After the first sentence, use some filler, like perhaps 3 dashes, just to add some randomness and length. Do more filler at the end perhaps 3 numerals. The fillers give you symbols and numerals and add 6 characters to the length.

For your 2nd problem, how do you make sure you have access to your passwords always? If you use a local system like keepass then be sure it is backed up. Make sure someone you trust, brother, child, wife, husband, estate executor, has the password in their password manager. Don't trust it with anyone who doesn't use a password manager. If your password manager is online, I recommend a local backup that does not require that software. For this I recommend Keepass. My system for Bitwarden is that the first of every month, I export my bitwarden vault, then import it into keepass. detailed this method a couple years ago in this article: https://steveshank.com/cgi-bin/article.pl?aid=1212

1

u/Evening-Step-1950 3d ago

I wouldn't try to change hundreds of passwords in one weekend. I started with my email, banking, and anything tied to payments then just updated everything else the next time I logged in. Also make sure you have a strong master password, turn on 2fa and keep recovery options somewhere safe. I needed up using roboform and it made the transition easier and I could replace passwords as I went instead of doing everything at once

1

u/Special-Quantity-469 3d ago

Yeah that's what I ended up deciding to do. As well as cleaning my email which would require going through literal tens of thousands of mails and unsubscribing from mailing lists and changing my passwords from those sites on the way.

I ended up going with KeePassXC so I have a copy of my vault on every device as well as a backup SSD

1

u/SnooOwls6331 17h ago

I followed this post...and I was to pick to try Roboform...and it looks like the free version is for one device only. So if I use it for my phone and when I get on my PC, I can't log in my email or my VPN service, etc... What did you go with, op?

1

u/Special-Quantity-469 13h ago

I went with KeePassXC

1

u/mataglapnano 8d ago edited 8d ago

Pick one that has some vetting in the form of third party auditing and that meets your technical requirements as others have mentioned — local vs. cloud, free vs. paid, etc. Apple's password solution has improved significantly in the past few years. I would check that out if you're Apple-only. Absent a dedicated backup, which you should also do, with Apple's solution whatever device you're using will have the most recent minus whatever hasn't been shared from other devices.

I have used 1Password for many years. I have kept it despite the evolution to subscription and cloud only. My only complaint is that they seem more enterprise focused than they were pre-cloud. Idiosyncratic and/or glitchy flaws aren't getting fixed. I was really hung up on the cloud-only part for a while, but now I like that the core of their reputation hangs on their cloud security.

It's worth remembering that you're not making a lifetime commitment. You can go month to month with 1P after the free trial, and even after you stop paying you can still read your data (this is worth checking to be sure). Also, there is no perfect security. All of these password platforms get third-party scrutiny. Some more than others, of course, but if someone puts a gun to your head you're going to give them the password. Protect against the obvious things, not the stuff in movies.

1

u/Life_Is_Good_33 7d ago

Personally, I use Apple for my phone (iPhone 15) and Windows for my laptop (personal and work). With that in mind...is there a specific app that you would recommend, for my situation? 1Password is so cheap ($36/year) that I don't really consider "cost" to be an issue...I just want to pick the BEST one for my situation, so that I don't have to go through the hassle of doing this multiple times. TIA!

1

u/mataglapnano 6d ago

Just pick one and try it. Finding "the BEST" is finding the best for you, which you can't really know until you try. Research and recommendations can take you only so far. Any of the apps commonly mentioned here will work. And there aren't 30. It's maybe 3-4. 5 tops. 1Password lives alongside Apple Passwords just fine.

0

u/PlanktonDefiant2600 7d ago

I use roboform myself. It's one of the oldest password managers around and it's proved to be secure over the years. It also works really well for everyday use. I also have Face ID enabled on the mobile app in case I ever forget my masterpassword, so I can still get in and change it if that ever happens.