# Bitwarden or Proton Pass

**URL:** https://discuss.privacyguides.net/t/bitwarden-or-proton-pass/14727
**Category:** Questions
**Created:** 2023-10-30T12:33:55Z
**Posts:** 50

## Post 1 by @privacyyy — 2023-10-30T12:33:55Z

What yall thoughts on this ? :thinking:

---

## Post 2 by @Private_Plan — 2023-10-30T13:02:01Z

Proton Pass if you pay for Proton Unlimited. Otherwise, Bitwarden.

Don’t put all your eggs in the same basket.

---

## Post 3 by @pika — 2023-10-30T13:06:10Z

Hands down Bitwarden . I haven’t used proton pass much but definitely bitwarden would by my first choice. They have been around for a long time now and are excellent for security in cloud password manager space. Their support is also good.  
Their free plan inlcudes unlimited passwords , yubikey support which is the most a free password manager is offering in the market.

---

## Post 4 by @ph00lt0 — 2023-10-30T13:51:10Z

Proton Pass is a lot more user-friendly, much easier to sort passwords and a really nice much better working integration with SimpleLogin for random alias _username_ email addresses.

Proton Pass however does not allow you to set up a legacy plan like Bitwarden has in case of death or emergency. Proton really should introduce that option.

Proton does not have support for biometrics authentication on desktop, so you will rely on a pin in your browser or no authentication at all.

Neither have fully launched passkey syncing support, but it seems that Bitwarden is further in the works on this, so that is something to consider.

---

## Post 5 by @anon54160479 — 2023-10-30T15:55:05Z

> [@pika](#):
>
> Hands down Bitwarden . I haven’t used proton pass much but definitely bitwarden would by my first choice. They have been around for a long time now and are excellent for security in cloud password manager space. Their support is also good.  
> Their free plan inlcudes unlimited passwords , yubikey support which is the most a free password manager is offering in the market.

sign  
Tested also Proton but in the end it’s all about the many small differences that make Bitwarden

---

## Post 6 by @anon90831229 — 2023-10-30T15:56:49Z

I would never trust any cloud service with this kind of data, regardless of whatever encryption or other methods they would use. So, Bitwarden **as long as** you’re self-hosting.

---

## Post 7 by @anon54160479 — 2023-10-30T16:13:36Z

> [@anon90831229](#):
>
> I would never trust any cloud service with this kind of data, regardless of whatever encryption or other methods they would use.

Why? Can you go more in detail?

---

## Post 8 by @pika — 2023-10-30T16:55:39Z

> [@anon90831229](#):
>
> So, Bitwarden **as long as** you’re self-hosting.

How is self-hosting gonna make it more “secure” according to you. If you don’t trust cloud , it doesn’t matter where and how you host it.  
I am not sure what are people worried about as everything is zero-knowledge encrypted.  
Also bitwarden code is open source , you can compile app yourself. Using their cloud service would be much better than hosting yourself unless you are a business.

---

## Post 9 by @anon21060844 — 2023-10-30T16:58:19Z

According to this website, the Bitwarden agreement you make when you say “I agree” states that you agree they can:

[You are tracked via web beacons, tracking pixels, browser fingerprinting, and/or device fingerprinting](https://edit.tosdr.org/points/26866)

[https://tosdr.org/en/frontpage#ratings](https://tosdr.org/en/frontpage#ratings)

No info on Proton Pass, but they do show what we agree for with ProtonVPN, which I assume is similar.

---

## Post 10 by @Regime6045 — 2023-10-30T16:59:22Z

I agree with you, I guess the main benefit would be getting the premium features (like TOTP 2FA and emergency contact/dead-man’s switch) for free.

---

## Post 11 by @privacyyy — 2023-10-30T17:27:16Z

Is this website providing legit information ?

---

## Post 12 by @Tech-Trooper — 2023-10-30T18:29:41Z

> [@Private_Plan](#):
>
> Proton Pass if you pay for Proton Unlimited. Otherwise, Bitwarden.

When you are self-hosting, you assume the daunting task of protecting your data. Still, you are dependent on the same encryption methods provided by Bitwarden or Proton, unless you are devising your own cryptography.

> [@ph00lt0](#):
>
> Proton does not have support for biometrics authentication on desktop, so you will rely on a pin in your browser or no authentication at all.

Indeed. It is also annoying that Proton Pass does not have option to lock itself on browser restart, unlike Bitwarden. So, you have to enter your pin like every hour.

> [@privacyyy](#):
>
> Is this website providing legit information ?

It depends on the apps and services, there might be missing information for some apps. Keep in mind that the review is based on the **Terms of Service,** not the underlying technology of the apps.

For instance, Telegram has a score of C, while whatsapp is given D. If I had to choose between the two, I would opt for whatsapp, since Telegram does not have E2EE for group messages and individuals (for default). Therefore,

---

## Post 13 by @anon21060844 — 2023-10-30T18:37:11Z

As with everything we research, we rely on the many to inform us of scams.

The website claims that they read those legal agreements that we all sign when we use someones “free” software or websites, then they parse out the good and bad in what we have agreed to. It is a window into how they use claim to use our information.

---

## Post 14 by @ph00lt0 — 2023-10-30T18:41:23Z

it’s community run, so take things with a grain of salt and see what is actually going on. It can possibly help you to understand things but I would just read the actual policy instead. The TOSDR project tries to reduce complexity but I am not sure that it really does. This specific line was copied from the privacy policy section in the part about the website, not about the product itself. The marketing website of Bitwarden surely leaves things to be desired, but this isn’t part of the policy for the product itself. Take that for what you will.

---

## Post 15 by @anon90831229 — 2023-10-30T19:43:24Z

> [@anon54160479](#):
>
> Why? Can you go more in detail?

Sure. While I trust the math behind encryption in general, you still rely on the cloud service to almost never make mistakes. Sometimes mistakes happen: [#1](https://www.hackread.com/lastpass-hacked-this-time-for-good/), [#2](https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/), [#3](https://www.heise.de/news/Einbruch-bei-Passwort-Manager-OneLogin-3733572.html), [#4](https://www.heise.de/news/Datenleaks-durch-Cloudflare-Fehler-1Password-gibt-Entwarnung-3634496.html). Now, some services definitely are better than others making it less likely for a single mistake in isolation to actually lead to compromise of any interest data. I just like to have another step here, call it defense in depth if you will: hosting the data on my own infrastructure.

> [@pika](#):
>
> Also bitwarden code is open source , you can compile app yourself. Using their cloud service would be much better than hosting yourself unless you are a business.

Regarding open source: Yes, it is. Otherwise I wouldn’t consider it in the first place. Regarding their cloud service: I haven’t said that “I don’t trust cloud” and I also haven’t said anything about the “zero-knowledge encrypted” state of the data in my initial comment. I simply stated my preference. You have not really made it clear why their cloud service is better “unless you are a business”. There are definitely downsides to hosting things yourself, including a password management solution. But I think that it’s a bit too much of a blanket statement to say that individuals cannot and should never host things themselves. Especially if I’m **not** specifically targeted for being a PEP or similar, then self-hosting can work fine.

However while I do incidentally actually self-host Bitwarden, my initial comment also was only an answer to the question “Bitwarden or Proton Pass?” from the OP. If we’re generally talking about password management, I would recommend KeePassXC to most people. It’s fine though if you use something different, all is better than using the same password everywhere.

---

## Post 16 by @bee — 2023-10-31T06:19:17Z

I’m thinking of switching to proton pass if there’s a sale for cyber monday/black friday soon for usability and UX, but I had a question for more technically inclined users.

Is there a tangible difference in the security or reliability of Proton and Bitwarden’s encryption and data protection protocols? Is there a substantial enough difference to warrant using one over the other for an average user?

I’ve read through documentation for both services, but when it comes to encryption protocols and diagrams, I start having trouble following along. I’d appreciate some clarity from someone here on this :slight_smile:

---

## Post 17 by @PrivadoQ — 2023-11-01T00:12:46Z

I don’t’ know if my MacBook is the problem, but Proton Pass has been pretty bad in my experience. For over a month it didn’t work on the Mac, Passwords wouldn’t open. I downloaded the iPad app to it, and it wouldn’t save entries there either.

These issues got fixed and it worked until about a couple of weeks ago. Now iPrroton Pass doesn’t work on Safari. When it tries to enter the password, the Proton Pass text box goes all black and it can’t be closed. I have to force quit Safari and start all over again.

Plus, I go to a client site that somehow has a firewall on ProtonMail/Pass, so I can’t open it there. They have put firewalls around VPNs as well, so haven’t been able to get around it yet.

IMHO, Proton Pass is really a half baked product. I love Proton Mail, but can’t recommend Proton Pass. I moved over from 1Password, and really regret it.

---

## Post 18 by @sha123 — 2023-11-01T07:36:49Z

> [@PrivadoQ](#):
>
> IMHO, Proton Pass is really a half baked product

Many products of Proton feel this way, especially if you use them cross-platform (e.g. on Linux). They really should focus on doing a few things, but these properly, not developing something new again and again, which no-one asked for and are better alternatives out there anyway.

---

## Post 19 by @anon62252234 — 2023-11-01T08:00:56Z

Couldn’t agree more. My [Proton disappointments](https://discuss.privacyguides.net/t/proton-disappointments-and-alternatives/14810) (have been moved to a new thread).

---

## Post 20 by @anon62252234 — 2023-11-01T08:17:40Z

As for the original question of this post, I have not used Proton Pass personally, and have not used Bitwarden recently.

Regardless, I would recommend you use the best tool for you personally. If you find Bitwarden nicer to use than Proton Pass, or the reverse, then use what works for you.

But more generally, I have to agree with this:

> [@Private_Plan](#):
>
> Don’t put all your eggs in the same basket.

You should really use the best service for each one of your singular needs, and not use the same one for everything.

While Proton’s (still developing) ecosystem is nice, you should really evaluate Proton Mail, Calendar, Drive, Pass, and VPN as separate products. It’s fine to use them all, if they’re genuinely the best options for you (and they are pretty good).

But, if Bitwarden works better for you, or Mullvad works better for you, etc., then you should use them. Using the whole ecosystem is not required, and not really recommended (if it makes sense for your use case to use other products), since you’ll be relying on them for a lot of your stuff.

* * *

[My personal setup](https://discuss.privacyguides.net/t/my-personal-setup/14808) (has been moved to a new thread).

---

## Post 21 by @anon21489307 — 2023-11-01T08:26:46Z

> [@anon62252234](#):
>
> There is no Proton Drive sync client for Linux - although there’s [rclone](https://rclone.org/protondrive)

If you’re using Proton Drive, you can also use **[Celeste](https://github.com/hwittenborn/celeste)**.

I don’t use it myself since it [doesn’t support S3 yet](https://github.com/hwittenborn/celeste/issues/4).

---

## Post 22 by @anon62252234 — 2023-11-01T08:28:27Z

I know. I hesitated mentioning it.

It uses rclone underneath, but, when I tried it, it seemed to be very slow. I think it may be because of [this issue](https://github.com/hwittenborn/celeste/issues/36) (I have 16 cores, so…).

---

## Post 23 by @Regime6045 — 2023-11-01T13:29:31Z

> [@anon62252234](#):
>
> - It doesn’t support syncing contacts to your phone (so you have to manually download and import them, and then do the reverse to upload new ones)
> - The Android calendar app is still not open source (I know they will do it, so I’ve been ignoring this, but it’s still unfortunate)
> - The desktop bridge doesn’t support contacts syncing either, but also don’t support calendar syncing, and there’s no calendar app for desktop (which is good, because they should really just add this to the bridge)

I don’t know why they won’t just add calendar and contacts to the Bridge, and port the Bridge to mobile devices too. That’s basically what [Etesync](https://www.etesync.com/) does: end-to-end encrypted contacts, calendars and tasks (!) that just appear as normal CalDAV/CardDAV on the local device and hence can be used with any calendar/tasks/contacts app.

This is would solve all three problems at once.

---

## Post 24 by @anon62252234 — 2023-11-01T14:33:20Z

> [@Regime6045](#):
>
> I don’t know why they won’t just add calendar and contacts to the Bridge

I think they will, in the future. [It’s certainly possible](https://github.com/emersion/hydroxide/tree/master#carddav).

> [@Regime6045](#):
>
> and port the Bridge to mobile devices too.

I don’t think they will do that though, and I don’t think they need to. They have a mail app, and a calendar app. A contacts app would be nice, but really just having them sync with the device from the mail app would work. [This is also planned](https://proton.me/support/proton-contacts-mobile#upcoming-features).

* * *

This is getting a bit off-topic though. I have made two new threads:

- [My personal setup](https://discuss.privacyguides.net/t/my-personal-setup/14808)
- My [Proton disappointments](https://discuss.privacyguides.net/t/proton-disappointments-and-alternatives/14810)

---

## Post 25 by @Dkama — 2023-11-02T02:22:03Z

I pay Proton Unlimited and still use free BW. As others said, Proton Pass is very half baked. The lack of data breach monitoring is the deal breaker imo, for now. There are a lot of other features that will still be missing even if they complete their roadmap:

> [@Proton Pass roadmap: 2023](http://discuss.privacyguides.net/t/proton-pass-roadmap-2023/13740):
>
> Looks promising. [https://proton.me/blog/pass-roadmap-2023](https://proton.me/blog/pass-roadmap-2023)

---

## Post 26 by @Dkama — 2023-11-02T03:14:24Z

I want to present @anon54160479 with a different _opinion_. I use the word because I don’t think any of what @anon90831229 said is wrong, but this is how/why I weigh things differently.

First, cloud does add another point of failure, but so does syncing. If you’ll selfhost, most likely you’ll want the passwords on your phone as well, so there’s that.  
Using reputed cloud-based software that go through serious audits (like Bitwarden, 1Password or Proton Pass) mitigates the cloud risk, as well as using reputable syncing solutions also mitigate syncing risks, but it’s much much more complex than simply using a cloud service.  
As a rule, self hosting requires tech savviness even if security is not an issue.

Second:  
@anon90831229 is probably right that your password manager cloud is more likely to be targeted than your selfhosted solution if you’re not yourself a high-value target. But the real danger here is neither, but rather malware in your computer/phone. A compromised OS will get you either way. It doesn’t matter where your passwords are hosted if the malware is looking at your keystrokes & clipboard or taking screen shots. Your mitigation here is having sound habits: use good (and few) software (&hardware if possible), update constantly, don’t use browser extensions other than uBO, don’t download sh\*t online, specially pirated software, etc.  
Of course, on the computer you can always compartmentalize by running VMs for different stuff (1 for browsing, 1 for password manager, 1 for documents and email, etc). On the phone you don’t have the same option. You do have UTM on iPhones, but then all pretense of privacy and security go out of the window when you use an iPhone.

Edit because I forgot the bottom-line: I don’t think you have a bigger risk if you use BitWarden, 1password or Proton Pass on the cloud. And given that BW has a free-tier cloud service and how hard it is to selfhost anything even if you’re tech savvy, it feels like a no-brainer to me. The risk is elsewhere.

---

## Post 27 by @pika — 2023-11-08T19:34:41Z

Bitwarden passkeys support is here now.  
So more reasons to make bitwarden a better choice than proton pass.  
I am sure there is plenty of features in pipeline for bitwarden including major ui changes.

---

## Post 28 by @Nostradamus — 2023-11-09T00:23:29Z

> [@pika](#):
>
> Bitwarden passkeys support is here now.

Desktop only tho

---

## Post 29 by @privacyyy — 2023-11-09T09:24:09Z

They need to change their damn UI real quick fr

---

## Post 30 by @Polymer7229 — 2023-11-09T09:55:57Z

I will give the arguments I have heard, although tilted toward BW.

1. BW is a more mature product
2. BW is more focused on secret management products
3. Proton tends to be slow on feature development (you decide)
4. BW has functional interfaces but are due for major overhaul
5. BW is almost entirely free. A $10/year subscription will give you TOTP code generation, emergency access assignment, some additional 2FA for BW (like Yubikey TOTP, Duo, etc.) It’s also cheap for family subscription.
6. Personally, I think BW is still a technical product, meaning you have the watch the development cycle like a hawk; otherwise, the safety/accessibility requirements, maintenance, and releases will catch you off-guard. For example, they are releasing Passkey storage/usage in the desktop web browser’s extension now, but how they do this is upsetting quite a few people. It may be better to skip this first few versions which are not easy to do if you are a general user.
7. BW’s bread is from corporate customers. You might not like how they treat your consumer preferences of what features should be developed, what bugs should be fixed.

Personally, I’d recommend BW to anybody who needs a cloud-based PWM, but am somewhat reluctant to recommend to non-technical people unless I can directly help them.

---

## Post 31 by @filen — 2023-11-09T11:38:55Z

Imma go with Bitwarden. Tried Proton Pass for 2 weeks and got some bugs tho

---

## Post 32 by @bee — 2023-11-09T15:38:20Z

Until Bitwarden gets a UI/UX refresh, I will be using Proton Pass (only the free version as I already have a Simple Login subscription. Also, only your first 10 aliases will function if you stop paying for Pass which is a major turn off).

As much of a more mature product Bitwarden is, I’ve just found it very hard to look past their UI recently, so I think the change of pace with Pass will be quite nice for me. Even using it these past few days, I’ve found Pass to be a much more seamless experience on the web.

---

## Post 33 by @filen — 2023-11-09T17:22:04Z

Yeah agreed. Bitwardens UI is terrible. Heard there is a UI changing plan cookin bts

---

## Post 34 by @bee — 2023-11-09T18:53:04Z

It’s listed as under research on their roadmap ([Bitwarden Roadmap - Archive - Password Manager - Bitwarden Community Forums](https://community.bitwarden.com/t/bitwarden-roadmap/12865)), so there’s no telling how long it will take. I’ll just be keeping an eye on it from afar for the time being.

---

## Post 35 by @anon73250778 — 2023-11-10T11:27:40Z

I’d like to comment that BitWarden’s UI feels like its a PWA of sorts and it doesnt feel nice to use.

One thing that I notice that is significantly lacking from BitWarden is the autotype feature (to use in logins where pasting is weirdly disabled). With Linux’s X11 impending demise coming up, this function is going away because of some security in part of Wayland being incompatible with these AutoType (like in KeePassXC). I find that it is not these password managers that saves me from manually typing, but the browser itself with Brave’s force paste function.

In the end, they have to be functional and secure enough and both products seem to meet both expectations.

---

## Post 36 by @filen — 2023-11-10T16:48:48Z

Good to know

---

## Post 37 by @anon90831229 — 2023-11-15T17:16:57Z

> [@bee](#):
>
> Also, only your first 10 aliases will function if you stop paying for Pass which is a major turn off

Any source on this? I thought that aliases that have been created will keep working indefinitely, but you cannot create any new ones.

---

## Post 38 by @bee — 2023-11-15T18:32:30Z

This is the case for SimpleLogin, but I emailed Proton support before making this post, and they responded,

> “If you create more than 10 hide-my-email aliases and decide to downgrade your plan to the free Proton Pass, you will be able to use only the first 10 aliases, while the other ones will be disabled.”

In the end, this is what’s deterring me from paying for Pass atm.

---

## Post 39 by @jonah — 2023-11-15T19:20:26Z

Well you shouldn’t lose them, they’d just be disabled, so there’s no security risk of someone else claiming your old aliases.

---

## Post 41 by @ph00lt0 — 2024-01-03T16:46:42Z

I noticed another major downside to Pass. It appears that the amount of vaults (folders) you can have is limited to 20. Makes it basically impossible to structure your passwords here, too. Bitwarden at least allows for more folders, but the UI is not helping you with that.

---

## Post 42 by @landordragen — 2024-01-03T17:24:05Z

Can you elaborate on your specific use case?

I’m only asking this to maybe improve my experience, because I only have three vaults: Personal, Work and Family (shared).

I see no need (for me, of course) to have more than 3 or maybe 4 vaults.

---

## Post 43 by @ph00lt0 — 2024-01-03T17:40:34Z

Well, besides that I share passwords with already 6 people for which you need a vault. I work for many organisations and I want to keep that organized, so I can remove the credentials and find an overview of them easily when needed.  
Also, I prefer to organize my credentials in folders like banking, insurance, newsletters, entertainment, gaming, temporary stuff, shopping to name a few.

As might you understand, I would also prefer to have structured vaults with subfolders, essentially.

Due to the nature of my work, I probably have way more credentials than any “normal” user. Just keeping them in one vault lacks any overview, which complicates compliance and also good habits of removing accounts you do not need any more.

To give you some idea, in Bitwarden I have over 2500 login items stored. (yes I want to move manually to proton pass, I am crazy ikr) but sorting needs to happen. In Bitwarden I lost track of it ini recent year slightly because the UI is a pain.

---

## Post 44 by @redoomed1 — 2024-01-03T17:49:14Z

I’m not the person to whom you responded, but after having just checked my Bitwarden vault because of your reply, I notice that I have 27 folders.

Some of these folders were intended for short-term categorization. For example, I have a “Reused” and “Exposed” folder for logins with non-unique passwords and logins with passwords exposed in known data breaches, respectively. (I checked this using Bitwarden’s [vault health reports](https://bitwarden.com/help/reports/) for premium users.) These folders just stuck because, after having gone through these logins, I couldn’t change the credentials for some of them.

> [@ph00lt0](#):
>
> organize my credentials in folders like banking, insurance, newsletters, entertainment, gaming, temporary stuff, shopping to name a few

Same here.

* * *

> [@ph00lt0](#):
>
> the UI is not helping you with that

This is what frustrates me about the browser extension. On the desktop app, you can easily organize folders using the left sidebar. Meanwhile, you can’t manage folders in the “Vault” tab of the extension – the most intuitive location for that, I would imagine. I have to navigate to `Settings > Folders` to make any changes to them.

---

## Post 45 by @landordragen — 2024-01-03T18:09:04Z

Thank you so much for taking the time to explain. It does make perfect sense now. We all have different needs indeed.

---

## Post 46 by @TheG — 2024-12-05T11:17:06Z

If you do not login to your Proton account for 1 year the account will be deactivated and all of its data will be deleted. Meaning, all of your passwords will be GONE.

However, this is not the case for Bitwarden. Your data is safe with Bitwarden whether you do not login for a long time or not.

---

## Post 47 by @ph00lt0 — 2024-12-05T11:22:34Z

If you haven’t made backups in that one year you are doing it wrong. And generally a password manager is really a multiple times per day usage.

I am actually happy to know they will clean up the data at some point. On email i think this is a different story as you might need that old email some day. But

---

## Post 48 by @anon48875053 — 2024-12-05T11:30:05Z

3-2-1.

---

## Post 49 by @Astatine — 2024-12-05T11:43:37Z

That’s not entirely [true](https://proton.me/support/inactive-accounts). Only the accounts of _free_ users are deactivated. Additionally, I’m a bit skeptical about Bitwarden, especially due to them being [VC-backed](https://techcrunch.com/2022/09/06/open-source-password-manager-bitwarden-raises-100m/). While it’s not horrible, Bitwarden **has** to make **profit** for the investors.

---

## Post 50 by @xe3 — 2024-12-06T06:53:48Z

I just want to point out that early on, Proton also received VC funding. They no longer depend on VC backing (and haven’t for some time) and they recently reorganized as a hybrid non-profit structure. But I’m just pointing it out as a counterexample to show that VC money doesn’t _always_ lead to bad outcomes.

I look at VC backing as a real vulnerability with a greater likelihood of misaligned incentives, but not an _inevitably_ bad situation always. I think the risk is considerably higher when there is the combination of: _VC money **and** no clear or sustainable business model_
