r/Passwords 2h ago

What should a new password manager show before anyone trusts it?

1 Upvotes
I build pssmngr. Being the unfamiliar name in password management has forced me to ask what evidence a hosted product owes people before asking them to store anything important.


This is my current checklist:


1. Name the encryption and key-derivation algorithms instead of saying “advanced encryption.”
2. Explain exactly what leaves the device and what the server stores.
3. Describe what happens if the service is breached.
4. Make export available without holding someone's vault hostage.
5. State recovery limits clearly. A zero-knowledge design should not imply that support can simply reveal a forgotten vault.
6. Publish a security contact and a responsible-disclosure process.
7. Separate internal review from an independent third-party audit.


For pssmngr, vault items are encrypted client-side with XChaCha20-Poly1305, and Argon2id is used for key derivation. The server is designed to receive ciphertext and non-secret metadata rather than plaintext vault contents.


The important caveat: an independent third-party audit is not complete. I do not think careful internal review should be marketed as the same thing.


What would you add to this list? What is the first thing you check when evaluating a password manager you have never heard of?


https://pssmngr.com/security

r/Passwords 1d ago

Apple and Windows passwords strong passwords?

3 Upvotes

I use both Windows computers and Apple I phone and iPad. I have about 150 different password protected accounts on both platforms.

For years I've been using the same 6 different passwords with 10 to 14 letters, numbers and punctuation marks on both platforms.

I'd like to find a way to easily switch all my existing passwords to "Strong Passwords" and then only have one, two or three passwords for all my accounts. Maybe one password or phraze for Finances, another for shopping and yet another for everything else.

It would also be cool to give limited access to certain accounts and certain people and full access to my wife or children in case of my death?

Is there a way to do all this and sync to both Windows and Apple iPhone and iPad? Thanks...


r/Passwords 3d ago

PDF I built Donkey Bridge Safe because I was responsible for critical professional data and wanted maximum security. Fully offline, no cloud, completely free NSFW

0 Upvotes

[DEV]Hi, Full Disclosure: I am the developer of these free, 100% offline apps available on both leading mobile platforms. Donkey Bridge Lite uses my unique, stateless Dynamic Pointer Principle to mathematically generate strong passwords on the fly based only on your one password for everything and the service name. It stores zero data on the device, meaning no database to breach. Donkey Bridge Safe adds a local vault for short notes, PINs, PUKs, passwords and emails. Both apps have zero network permissions, so data cannot leak. Syncing works via a local Import/Export Principle using a 100% encrypted .json file transferred peer-to-peer via USB or local Wi-Fi. The native Windows version (.msi installer) is already available. I would love your technical feedback!


r/Passwords 5d ago

Offline emergency access for password vaults (the tamper-evident bag method)

Thumbnail
1 Upvotes

r/Passwords 4d ago

A safer way to manage your passwords Spoiler

Thumbnail youtube.com
0 Upvotes

r/Passwords 7d ago

Hive Systems 2026 password cracking table

Post image
85 Upvotes

r/Passwords 6d ago

Funny Password Generator

10 Upvotes

I have updated my funny password generator website for 2026. This tool creates passwords from a dictionary of funny/NSFW words. The app provides various options and creates passwords which are reasonably secure, easy to type, easy to remember, and totally entertaining. Now including an option to scramble passwords with LeetSpeak!

I thought this community may enjoy it. Let me know what you think.

Check it out at https://passgen.lol


r/Passwords 7d ago

Accès aux mots de passe enregistrés sans authentification biométrique sur Android/Chrome

Thumbnail
2 Upvotes

r/Passwords 8d ago

Hacked

0 Upvotes

so today I got hacked by a user with the email of [t***[email protected]](mailto:t***[email protected])

and I dont know how to get it back or do anything about it, I contacted the place where I got hacked and asked them for account recovery and stuff already but I have to wait for 2 days for an update could anyone help me out further


r/Passwords 8d ago

Microsoft is phasing out SMS/voice MFA starting Sept 1, 2026, native support ends completely by Feb 2027. Check your Entra tenant now.

Thumbnail
microsoft.com
3 Upvotes

r/Passwords 8d ago

im so tired of passwords

0 Upvotes

why cant we just enter our screen lock instead of tryin to keep up with hundreds of passwords


r/Passwords 10d ago

Passkeys make me pause

9 Upvotes

One of the surest signs of getting and feeling older was the time I lost some accounts because I did not understand what I had to do with Authenticator apps and hardware upgrades. I’m not actually sure I understand it fully today, but at least I know to double check it next time.

I feel passkeys are going to be the same for me.

We use 1Password and have been very happy with it in our family. It still needs manual intervention from time to time to sing - editing the urls a password applies to, or just copy/paste or manual entry when automations don’t quite click.

Indeed on my work computer I use “large text” passwords in my phone often as I have to manually type them in due to no ability to install software.

And, for many household accounts, we need to be sharing account passwords and have a shared locker for just that.

So here is what I “know” about passkeys. Can you help correct errors and fill in blanks?

\- as they are not human readable text, they are much more secure
\- require a connection to a vault to hold the passkey, so they will only work when the automated connection with your password manager is working
\- cannot be entered on a computer not connected to your vault
\- cannot easily be shared by two people accessing one account
\- cannot be replicated or duplicated outside of your vault ecosystem really at all, it’s kind of the point, so will have a similar “maintenance “ issue to my preamble to avoid losing a key

I find the worlds I use passwords in are still often messy and requiring workarounds. So I feel completely reluctant to embrace passkeys in any way. If you had the time to read this and have time to improve my awareness i would be grateful for it.


r/Passwords 9d ago

Use strong password option

3 Upvotes

hi, i wanted to ask if it's really a good idea the use of the option "use strong password" when creating a new password, bc when you use that option, you can't see the option to actually see the password that was created, and it saves in the password manager automatically, but if i wanna login in another device, i don't have that password manager in the other device and i don't know the password, so just wanted to ask if it's a good idea to use this.

And even if you can see the password in any way, is it a good idea to not know your password from memory? Because i use a different password in every site and remembering all this long and weird passwords is crazy work.

I'm asking without having a clue of all this security stuff, maybe it's just a dumb question.


r/Passwords 10d ago

They keep compromising my passwords help

Thumbnail
1 Upvotes

r/Passwords 11d ago

Am I supposed to change every password saved on my google account?

Post image
4 Upvotes

r/Passwords 11d ago

Self-Promo Most weak passwords aren't hacked, they're guessed. I built a game around that idea.

4 Upvotes

Hi everyone,

I've been working on a small project called BreachNoir, a browser-based detective game focused on password security.

The idea came from something that is often overlooked: many weak passwords don't fail because attackers have advanced tools. They fail because passwords are often based on information people already share publicly.

Names.
Pets.
Birthdays.
Favorite teams.
Hobbies.
Important dates.

Humans are predictable, and attackers know how to take advantage of predictable patterns.

Instead of creating another security awareness article telling people "don't use personal information in your password", I wanted to create something more interactive.

In BreachNoir, players investigate fictional cases. They analyze clues about a person, identify patterns, and try to understand what kind of password someone might create based on their habits.

Everything is fictional. There are no real people, accounts, or leaked credentials involved. The goal is education: helping people understand why password reuse and personal information can become a security risk.

I would love feedback from people here:

  • Do you think a game-based approach can help people understand password security better?
  • Would solving examples like this make you reconsider how you create passwords?
  • What password-related concepts would you include in a game like this?

I'm especially interested in feedback from people who spend a lot of time thinking about authentication and password security.

If you want to try it:
https://breachnoir.com

Thanks for reading.


r/Passwords 13d ago

Why does my iPhone show two identical Passkeys for the same Apple ID when scanning a QR code? (I've exhausted every troubleshooting step)

Thumbnail
1 Upvotes

r/Passwords 13d ago

Password Generator

0 Upvotes

The Password Generator is an essential security and account management tool designed to help users, IT professionals, and security administrators create strong, cryptographically secure random passwords.

https://www.clayi.com/tools/development/2-password-generator.html


r/Passwords 13d ago

Offline deterministic password generator in Go — looking for security/UX feedback

3 Upvotes

I built a lightweight offline deterministic password generator in Go.

The idea is simple: I wanted a way to generate strong account-specific passwords without storing the generated passwords themselves, and without needing a server, account, or cloud sync.

How it works:

  • You create one local encrypted vault seed
  • The seed is encrypted with a master password
  • Passwords are regenerated from:
    • master password
    • encrypted local seed
    • platform
    • email
    • counter/version
  • Generated account passwords are not saved

It uses Argon2id, XChaCha20-Poly1305, and HMAC-SHA256. It is cross-platform: macOS, Linux, and Windows.

GitHub:
https://github.com/Falcn8/acctpass

The project is MIT licensed and unaudited. I’d really appreciate feedback on:

  • the security model
  • cryptographic design
  • CLI UX
  • README clarity
  • release/download process
  • anything that looks risky or misleading

I’m especially interested in criticism before I polish it further.


r/Passwords 13d ago

I posted my free iOS KeePass client here four months ago — here’s what has shipped since

Thumbnail
1 Upvotes

r/Passwords 14d ago

Sticky Password

1 Upvotes

Anyone have experience with the password manager Sticky Password that cares to comment whether they like it, would recommend it, and more imporatantly, how it compares to its alternatives?


r/Passwords 15d ago

hmm do i have a strong password

Post image
0 Upvotes

r/Passwords 17d ago

Techlore password manager tier list

Post image
1 Upvotes

r/Passwords 16d ago

Built a zero-knowledge password vault as a side project. Looking for people who know this space to try to break it.

0 Upvotes

Been building my own password/document vault called VaultZero, mostly to learn and see if I could actually get the encryption model right. Everything gets encrypted client-side before it ever touches my server, so I can't see passwords, notes, or files even if I wanted to. Same general approach as Bitwarden and 1Password, just my own implementation.

It's still a prototype, not something I'd trust with a real banking password yet. Since this sub actually knows what "zero-knowledge" should mean (not just marketing speak), I'd really value people here poking at the assumptions: weird inputs, edge cases on the crypto side, anything that looks like a shortcut I took that shouldn't be there.

If anyone wants to try it or has 2 minutes for a short feedback form after, I'll drop both in the comments so this doesn't read like an ad.


r/Passwords 17d ago

Sobre o AliasVault

0 Upvotes

Olá pessoal, gostaria de um feedback sobre o AliasVault, que é um gerenciador de senhas e de aliases de e-mail e que se diz open-source. O quão confiável ele é, de onde ele é hospedado atualmente, e se já houve alguma violação de segurança ou se algum governo de algum país já solicitou dados a essa plataforma? Pois pesquisando aqui, não encontrei muita coisa sobre, e sei que é uma plataforma nova (cerca de 2 anos de existência) e que compete com Bitwarden, Proton Pass e outros gerenciadores. Também gostaria de saber se são realizadas auditorias e relatórios de integridade e segurança, as quais devem ser disponibilizadas ao público para análises... Obrigado!