# Require Open Source for Password Managers

**URL:** https://discuss.privacyguides.net/t/require-open-source-for-password-managers/12480
**Category:** Site Development
**Created:** 2023-04-24T23:43:32Z
**Posts:** 440

## Post 1 by @moonwriting — 2023-04-24T23:43:32Z

> [@Skiff Pages/Drive (Productivity Tools)](https://discuss.privacyguides.net/t/skiff-pages-drive-productivity-tools/11758/13):
>
> We require both productivity tools and notebooks to be open-source

This is interesting requirement considering that you recommend 1Password, a closed source password manager that arguably protects even more sensitive data. So, your stricter requirement for these categories makes little sense to me.

---

## Post 2 by @anon43879818 — 2023-04-25T02:44:35Z

We could discuss that in a new thread.

---

## Post 3 by @jonah — 2023-04-26T13:29:14Z

I think we could re-evaluate this once Proton Pass is out and there are multiple open-source cloud-based password managers, **if** Proton Pass turns out to be good.

> [@Proton Pass (Password manager)](https://discuss.privacyguides.net/t/proton-pass-protonmail-password-manager-service/12416):
>
> [https://proton.me/blog/proton-pass-beta](https://proton.me/blog/proton-pass-beta) Today, we’re happy to announce another significant milestone in the growth of the Proton ecosystem with the launch of the Proton Pass beta for Lifetime and Visionary users. Invites will roll out over the next week, and you’ll receive an email from us at your Proton Mail email address when you’re eligible. […] A password manager has been one of the most common requests from the Proton community ever since we first launched Proton Mail. However, while Pr…

Right now there weren’t really good options in this category other than Bitwarden, and 1Password provides advantages over Bitwarden in some respects. If Proton Pass ends up providing the same advantages then it could take its place and we could make this change, but time will tell. I’m also not thrilled with 1Password potentially adding telemetry anyways, no matter how “privacy respecting” it’s claimed to be, but that is a future change.

---

## Post 4 by @BionicBison — 2023-04-27T16:30:36Z

Bitwarden claims to use Google Analytics. Is that not also a concern?

---

## Post 5 by @matchboxbananasynergy — 2023-04-27T16:38:01Z

EDIT: The reply by Bitwarden is **not** deleted, I’m just a dum-dum. Disregard that part.

In a now seemingly deleted Mastodon post ([Bitwarden: "@Jo3@mastodon.social Hey there, Firebase Cloud Me…" - Fosstodon](https://fosstodon.org/@bitwarden/109636825700482007)), Bitwarden said (this is not the entirety of their reply, just the part that I was able to quote from another reply I made elsewhere):

> Hey there, Firebase Cloud Messaging (often mistaken for a tracker) is used only for push notifications related to sync and performs absolutely no tracking functions. Microsoft Visual Studio App Center is used for crash reporting on a range of mobile devices.

Now, I don’t know whether they removed that post because what is stated there is incorrect, but Bitwarden having a library in the app doesn’t necessarily mean they use the analytics portion of said library.

Someone could reach out and request more specific and up-to-date information.

---

## Post 6 by @BionicBison — 2023-04-27T16:39:22Z

From their privacy policy:

> We use data for analytics and measurement to understand how our the Site and Bitwarden Service are used. For example, we analyze data about your visits to our Site to do things like optimize product design. We use a variety of tools to do this, including Google Analytics. When you visit the Site using Google Analytics, we and Google may link information about your activity from that site with activity from other sites that use Google Analytics services.

---

## Post 7 by @matchboxbananasynergy — 2023-04-27T16:42:13Z

> [@BionicBison](#):
>
> We use data for analytics and measurement to understand how our the Site and Bitwarden Service are used. For example, we analyze data about your visits to our Site to do things like optimize product design. We use a variety of tools to do this, including Google Analytics. When you visit the Site using Google Analytics, we and Google may link information about your activity from that site with activity from other sites that use Google Analytics services.

They’re not quite clear if Google Analytics are used on the service, they say they use a variety of tools including Google Analytics, but yeah, you’re right, I would assume they do.

Whether that’s relevant to them being listed or not, I don’t know.

---

## Post 8 by @BionicBison — 2023-04-27T16:44:49Z

I’m just pointing out that if first-party analytics are a point of concern regarding 1Password, then Bitwarden is also affected. I’m not thrilled with analytics either but I’d prefer a first-party approach over Google Analytics any day.

---

## Post 9 by @moonwriting — 2023-04-27T17:05:36Z

Bitwarden only uses Google Analytics on its website, not on the apps. So, this is not a huge concern, in my opinion. The same goes for 1Password, which also uses Google Analytics on its website. However, 1Password has also recently [stated](https://blog.1password.com/privacy-preserving-app-telemetry/) that they will soon start using telemetry on their apps, which is another thing to consider. But if we are talking about website analytics, it is actually next to impossible to find a product that wouldn’t use them. For example, KeePassXC uses cloudflareinsights, and Strongbox uses plausible but also tries to access Canvas. So, there really isn’t a perfect solution in this regard. But then you could also ask how many people have to even revisit these websites in the first place after creating their account or downloading the app. I would assume not many times, if at all.

---

## Post 10 by @anon46880256 — 2023-04-27T18:00:52Z

The difference is that a lot of account settings with Bitwarden are only available through the web vault. This means that people are far more likely to visit the Bitwarden website than they would if they were using another password manager.

Settings such as changing the KDF, enabling/changing 2FA settings, changing the master password, etc., are all only available through the Bitwarden web vault.

---

## Post 11 by @moonwriting — 2023-04-27T18:31:54Z

And still, if you use any of the browsers PrivacyGuides recommends, this isn’t really a problem, as those trackers would get blocked.

---

## Post 12 by @anon43879818 — 2023-04-27T18:54:32Z

Woah hey. Now this is branching off again, from open source to the use of analytics

---

## Post 13 by @anon48875053 — 2024-04-23T05:45:28Z

Since Proton Pass turned out to be an amazing product and was finally added to Privacy Guides, I think it’s time to require open source for password managers and get rid of 1Password.

Bitwarden:

- Client and server code is open source.

- Can be self-hosted.

Proton Pass:

- Clients are open source.

- Provides built-in hide-my-email alliases.

1Password:

- Both the client and the server code are proprietary.

- Can’t be self-hosted.

- Doesn’t offer any private payment methods.

- Embeds tracking pixels in their newsletters.

- More expensive than Proton Pass and Bitwarden.

- Doesn’t even have an integration with SimpleLogin, only with Fastmail.

---

## Post 14 by @jonah — 2024-04-23T06:00:41Z

Yeah, I’m not really opposed to adding a FOSS criteria to this category.

---

## Post 15 by @anon48875053 — 2024-04-23T06:47:26Z

This change would close this thread and also this one: [Remove 1Password](https://discuss.privacyguides.net/t/remove-1password/13921)

---

## Post 16 by @id_privat — 2024-04-23T07:44:55Z

Voted. Proprietary software has no guarantee that it is doing what claims

---

## Post 17 by @anon59474973 — 2024-04-23T07:52:49Z

Not necessarily. And 1Password has been around for nearly 2 decades with no serious issues. With that being said, I can’t really say 1Password does anything better than Bitwarden, KeePassXC (well, maybe UI) or Proton Pass. 1Password does have a discount for journalists which is about the only good thing if you were required to use it. Otherwise KeePassXC and Bitwarden are what I’d prefer if I was a journalist.

---

## Post 18 by @anon73886004 — 2024-04-23T08:01:35Z

Proton apps have started open source and fall out of date. (calendar). Since this change was hinged on the fact that Proton pass was released open source, what would happen if the repo saw no updates after some period of time?

---

## Post 19 by @eqrlzo8t — 2024-04-23T10:12:51Z

1Password does have a Secret Key feature so your account won’t be accessed even when someone else somehow knows your account and password:

> **[About your Secret Key | 1Password Support](https://support.1password.com/secret-key-security/)**
>
> Your Secret Key keeps your 1Password account safe by adding another level of security on top of your 1Password account password.

But it’s practically similar to Keepass’ keyfile so it does not affect me much.

---

## Post 20 by @BionicBison — 2024-05-01T17:07:43Z

I understand the rationale behind this, but I think it still deserves full community input and careful deliberation. As others have mentioned, 1Password has been pretty much unproblematic on the security front for its entire existence (regular audits, great security model, etc.) and I think this continues to make it worthy of recommendation. Additionally, Proton Pass definitely doesn’t have feature parity yet, a notable difference being all the item types that 1Password supports, making it easy to adopt secure practices for more than just credentials.

---

## Post 21 by @jonah — 2024-05-01T17:11:17Z

The SSH agent in particular is kind of a killer 1Password feature for me, although _in general_ that’s probably too niche for most people to care about.

---

## Post 22 by @purplecactus — 2024-05-02T00:58:10Z

oh wow. I didn’t know of this. so glad you mentioned it, looks super useful.

i have been paying for a 1password family account just for my other family members but maybe now i’ll finally really use it lol.

---

## Post 23 by @anon60350980 — 2024-05-13T07:53:05Z

It’s UI and clients are leagues and bounds beyond what Bitwarden offers, especially for families. I don’t think it’s fair to disregard all of its advantages for making good digital hygiene accessible to so many and probably continuing to do so for the foreseeable future just because it’s proprietary.

---

## Post 24 by @anon48875053 — 2024-05-13T08:23:09Z

Proton Pass UI and UX are very good, and as far as I know, Bitwarden is rewriting their Android client in Kotlin, so the UI and UX will probably improve too. Just look at Bitwarden Authenticator.

Also, if it’s not fair to disregard software just because it’s proprietary, then I guess let’s recommend proprietary solutions in all the categories? Not only in the Password Managers category.

---

## Post 25 by @anon48875053 — 2024-05-13T08:27:25Z

It’s also very important to understand why 1Password is proprietary. 1Password is VC funded, and open sourcing their clients, etc. wouldn’t be a good business idea, and VC investors probably wouldn’t be too happy about it.

I don’t see a reason to recommend a service that prioritizes profit and their VC investors over their users when there are better alternatives like Proton Pass, which is fully independent and whose business model is selling services to customers, which leads to a situation where customers are the priority because the customers are the ones keeping the company alive.

---

## Post 26 by @anon60350980 — 2024-05-13T10:37:08Z

> Proton Pass UI and UX are very good, and as far as I know, Bitwarden is rewriting their Android client in Kotlin, so the UI and UX will probably improve too. Just look at Bitwarden Authenticator.

Proton Pass is moving in the right direction, I’ll give it that. When both are on par with 1Password, I’d be the first one championing its removal from the site, but as of now, their feature set is frankly laughable in comparison to 1Password, especially the implementation. If Proton Pass in particular didn’t carry the same price tag as 1Password, it’d be easier to stomach its many shortcomings. There is also no way to get a family subscription for Proton Pass without also paying for their entire suite of apps.

> Also, if it’s not fair to disregard software just because it’s proprietary, then I guess let’s recommend proprietary solutions in all the categories? Not only in the Password Managers category.

I never argued for it to this degree, but since we’re on the topic: If they’re clearly better than the FOSS alternatives, then why not? I don’t like the religious obsession with stuff having to be FOSS. Use the right tool for the right purpose, that’s my policy.

> It’s also very important to understand why 1Password is proprietary. 1Password is VC funded, and open sourcing their clients, etc. wouldn’t be a good business idea, and VC investors probably wouldn’t be too happy about it.

That’s a valid point, but until they act up - and let’s be honest, their track record does not point in that direction - we should keep them on the site.

> like Proton Pass, which is fully independent and whose business model is selling services to customers, which leads to a situation where customers are the priority because the customers are the ones keeping the company alive.

I personally don’t like how they try to push you into buying into an ecosystem. I’m out here trying to avoid vendor lock-in as much as possible and definitely don’t wanna be locked into using their apps. They employ way too many dark patterns for me to simply skip over them and act like they’re so benevolent in comparison to the VC-funded alternative.

Just yesterday, I gave Proton a chance. Seeing how they are VERY intransparent about what feature is paid and which isn’t, in addition to their less than favorable marketing with regards to competitors and the ability of their products as of late, I would not bet on them still prioritizing their users in 5 years. But obviously this is all speculation and I’d be more than happy to be wrong (otherwise we’d be fucked), just like with 1Password. Until then both should stay up, and the FOSS requirement scrapped for the time being.

My point is: there is no good or bad company. They’re all exploitative dip-shits, only vary by degree. If the product is good, it should stay up, if it isn’t anymore, we should take it down. The FOSS requirement in the password manager space is IMO too hasty when the FOSS alternatives aren’t mature enough or have feature parity with their proprietary counterparts.

---

## Post 27 by @ph00lt0 — 2024-05-13T10:41:51Z

I gave my vote to this. Not because I think 1password is a bad place to store your passwords, I certainly don’t, but I do have more faith in Proton and Bitwarden in this case.

I am not sure if it even should be a requirement. I think PG should always recommend the best option(s) and not every other solution that is available. Now of course 1password has come along way and has been on the site for a while, I guess those who use it might not even need to change that. It’s more if you would recommend a service today, for me that’s Proton Pass. It’s most user-friendly IMHO and I have more faith in it.

---

## Post 28 by @anon48875053 — 2024-05-13T14:28:38Z

> [@anon60350980](#):
>
> Proton Pass is moving in the right direction, I’ll give it that. When both are on par with 1Password, I’d be the first one championing its removal from the site, but as of now, their feature set is frankly laughable in comparison to 1Password, especially the implementation. If Proton Pass in particular didn’t carry the same price tag as 1Password, it’d be easier to stomach its many shortcomings. There is also no way to get a family subscription for Proton Pass without also paying for their entire suite of apps.

1Password is actually more expensive than Proton Pass. Proton Pass is 1.99 per month, and 1Password is 2.99 per month. Proton Pass also had a lifetime deal, which reduced the price to only 1€ per month, and for those who have Proton Unlimited, they already get access to Proton Pass.

With Proton Pass you get:

- Unlimited hide-my-email aliases

- Access to the Proton Sentinel high-security program

- Pass Monitor

1Password:

- Proprietary

- Doesn’t offer any private payment methods. (Proton does)

- Doesn’t even have an integration with SimpleLogin or other email alliasing services, only with Fastmail.

Also, I’m not sure what features 1Password has that Proton Pass doesn’t.

> [@anon60350980](#):
>
> I never argued for it to this degree, but since we’re on the topic: If they’re clearly better than the FOSS alternatives, then why not? I don’t like the religious obsession with stuff having to be FOSS. Use the right tool for the right purpose, that’s my policy.

I’m not going to explain why FOSS movement is important because that would be highly off-topic.

If all of us would use the “right” tool for the “right” job, then we would all be deep into Google’s and Apple’s ecosystems because, let’s be honest, they make some of the best, most usable software out there.

Fortunetly, most of us in here care about security, privacy, FOSS, etc., not only about using the best tool for the job.

> [@anon60350980](#):
>
> I personally don’t like how they try to push you into buying into an ecosystem. I’m out here trying to avoid vendor lock-in as much as possible and definitely don’t wanna be locked into using their apps. They employ way too many dark patterns for me to simply skip over them and act like they’re so benevolent in comparison to the VC-funded alternative.

I’m sorry, but this is Proton and not Apple. Proton doesn’t try to push or lock users into their ecosystem.

Most Proton customers, including me, want an ethical, private, and secure ecosystem as an alternative to bad ones like Apple’s.

---

## Post 29 by @Feradin — 2024-05-13T15:17:03Z

Both Bitwarden and Proton Pass are missing basic features which 1Password has, so I’ll continue to use it for another year at least.  
Examples for Bitwarden: No other sorting options than A-Z, no tags, although people have been asking for these features for ages. The UI of the installed client is visually outdated and some features (security reports) are only available on the website.  
Proton Pass can’t auto-fill information from custom fields, which the other two can, that’s a feature I don’t want to live without.

---

## Post 30 by @anon60350980 — 2024-05-13T15:41:25Z

> 1Password is actually more expensive than Proton Pass. Proton Pass is 1.99 per month, and 1Password is 2.99 per month. Proton Pass also had a lifetime deal, which reduced the price to only 1€ per month, and for those who have Proton Unlimited, they already get access to Proton Pass.

You completely disregarded my argument and assumed I would only choose a service for myself. Some of us got families; mind-boggling right?? Proton Pass doesn’t have a family plan unless you pay for the entire Proton suite, which is a no-go for me. I’m not leaving Apple’s walled garden just to be locked into using everything another company uses.

Also judging the affordability of a service by it’s yearly cost divided by 12 months is disingenuous at best. That’s not how much Proton Pass costs a month and you know it. It’s one Euro/US Dollar more than 1Password. And the only reason it costs so little when billed yearly is because Proton is desperately trying to push a mediocre product that has nothing of value that other password managers don’t have already.

> Doesn’t offer any private payment methods. (Proton does)

This depends on your threat model.

> Also, I’m not sure what features 1Password has that Proton Pass doesn’t.

If you’re not sure, then please (!!!) educate yourself on that before you start a thread about removing a very outstanding product. As @Feradin said, 1Password can autofill custom fields which Proton Pass (and last I checked Bitwarden) can’t do, yet. It also has collections so you can group/hide vaults depending on your needs, lets you attach files to login items, works great for families because of the ability to have shared vaults, and lastly what’s probably its best feature: Travel Mode, potentially a life-saving measure for a variety of people, especially journalists.

Basically, you can choose a vault to be “safe” or not and those who you deem to be “unsafe” get hidden when you enable Travel Mode, so that if you’re forced to unlock your password manager by authorities, you can dupe them by serving them dummy accounts.

> If all of us would use the “right” tool for the “right” job, then we would all be deep into Google’s and Apple’s ecosystems because, let’s be honest, they make some of the best, most usable software out there.

No, because deciding if a tool is right depends on many variables that go beyond the optics. They might be convenient, but that doesn’t make them good. The reason I’m having this discussion with you right now, isn’t because 1Password is convenient, but because it’s genuinely an all-around good product with a great track record and one that is regularly externally audited.

> I’m sorry, but this is Proton and not Apple. Proton doesn’t try to push or lock users into their ecosystem.

They very much do. Their pricing scheme which pushes you to go all in and pay 12 to 24 months upfront (a dark pattern). Also, you can’t use their products with other clients unless you use their “bridge” - and that is reserved for desktops. On mobile, you’re out of luck and have to find peace with their randomly updated (proprietary) mobile clients. No, thank you.

---

## Post 31 by @anon48875053 — 2024-05-13T16:26:37Z

> [@anon60350980](#):
>
> You completely disregarded my argument and assumed I would only choose a service for myself. Some of us got families; mind-boggling right?? Proton Pass doesn’t have a family plan unless you pay for the entire Proton suite, which is a no-go for me. I’m not leaving Apple’s walled garden just to be locked into using everything another company uses.

This is literally what you said:

> If Proton Pass in particular didn’t carry the same price tag as 1Password, it’d be easier to stomach its many shortcomings.

Which is false, Proton Pass doesn’t carry the same price tag as 1Password, Proton Pass is cheaper.

And you just became passive aggresive and assumed that I don’t have a family:

> [@anon60350980](#):
>
> Some of us got families; mind-boggling right??

This is pretty yucky.

> [@anon60350980](#):
>
> Also judging the affordability of a service by it’s yearly cost divided by 12 months is disingenuous at best. That’s not how much Proton Pass costs a month and you know it. It’s one Euro/US Dollar more than 1Password.

Who in their right mind would pay 4.99 for a month, which is 59.88 per year, when they can just pay 1.99 per month, which is 23.88 per year?

The reason why I compared prices when paying annually is because 1Password can’t be bothered to even show me how much their service costs per month while not paying annually:

> **[Pricing Plans for the Best Password Manager | 1Password](https://1password.com/pricing/password-manager?currency=usd)**
>
> Choose a 1Password plan for your small business, family or enterprise. Start a free trial and enjoy password management, data breach protection, and more.

And Proton Pass costing 1 Euro/US Dollar more is probably justified by the fact that Proton Pass offers unlimited hide-my-email alliases.

> [@anon60350980](#):
>
> And the only reason it costs so little when billed yearly is because Proton is desperately trying to push a mediocre product that has nothing of value that other password managers don’t have already.

Saying that the password manager that hasn’t even been around for a year and is completely user funded has nothing of value because it doesn’t yet have all the features that a password manager that has been around for about 16 years and has **received a total of $920 million in VC funding** is completely nuts.

Because Proton puts users above profit, users can suggest or vote for features that they want to be implemented:

> **[Proton Pass: Hot (387 ideas) – The Voice of the Proton Community](https://protonmail.uservoice.com/forums/953584-proton-pass)**

Some of the missing features are already started or are planned.

---

## Post 32 by @anon80779245 — 2024-05-16T11:20:52Z

1. I personally think we should put a **warning** :

> 1 Password is a paid, proprietary service. Always back up your data.

That being said : [Security audits of 1Password | 1Password Support](https://support.1password.com/security-assessments/)

1. **Why is there no criteria for the password manager section**? We should at very least require open-source clients OR audited clients.

2. There clearly is a discrepancy with the notebook category which requires open-source clients. While this make sense for online, collaborative notebooks, it doesn’t for local notebooks like Obsidian. At least if we follow the narrow view of Privacy (and we forget that Privacy should enable Freedom)

---

## Post 33 by @Bhaelros — 2024-05-16T13:35:29Z

1Pass individual costs 36 USD year, and Proton costs 24 USD / year, but that is the promotional price for the first year. Normal price is 60 USD / year.

There is no family plan for Proton Pass unless buy Proton Family (which I did btw for my mails). Cheapest option is to buy it for 2 years and pay 480 USD.

I wrote many times on this and other platforms about the basic missing features.

- No sorting by name which persists.
- No biometric login
- No connection between desktop app and browser extensions.
- No Passkey, File and item history import from other password managers
- No custom field import, like ID cards, Passports, Software License and SSH keys
- No multi item select, like you can do with 1Password.
- No tags
- No predefined fields and items
- Autofill and field recognition is broken on many sites
- It is also not working in Firefox Private Window  
and many more.

It is a new product and it needs to mature, that is why they are selling it for so cheap, but it will take years to mature it to get closer to 1Password level.

---

## Post 34 by @bee — 2024-05-16T15:36:10Z

> [@Bhaelros](#):
>
> but that is the promotional price for the first year.

Mmm nope, that’s the recurring price. They reduced the prices a little while ago, and 1.99 is the standard price now, not just promotional.

> [@Bhaelros](#):
>
> - No sorting by name which persists.
> - No biometric login
> - No connection between desktop app and browser extensions.
> - No Passkey, File and item history import from other password managers
> - No custom field import, like ID cards, Passports, Software License and SSH keys
> - No multi item select, like you can do with 1Password.
> - No tags
> - No predefined fields and items
> - Autofill and field recognition is broken on many sites
> - It is also not working in Firefox Private Window  
> and many more.

- Fair.
- Biometrics work fine on mobile, and I don’t think they’re common enough on laptops/desktop to really be a major problem.
- I’m not sure what kind of connection you’re looking for. They both sync just fine, and aren’t limited in functionality.
- Yeah not being able to import those things could be inconvenient, that’s true.
- No set custom ID fields, but notes exist, which can put those things down just fine. It’s not like you really need to worry about autofilling a license key often, so just having it in a note to copy paste it from is perfectly acceptable imo. Having the dedicated feature might be nice for organization, but I don’t think it’s really missing functionality for not having it.
- Multi item select is implemented.
- Yeah, no tags is annoying for larger vault sizes. I augment this by using different vaults for organization, but tags could be nice.
- Predefined fields and items? I’m not quite sure what you mean by this.
- In my experience, autofill has been far better than Bitwarden’s (on mobile especially), so I’ve actually been quite happy with it. I think there are broken sites for autofill for every password manager.
- Interesting that it doesn’t work there. I’ll have to test it myself later. Not excusing it if it doesn’t actually work there, but as an aside, why use private windows in FF over regular windows with sanitize on close? It just seems like an extra step when you could implement similar functionality into regular windows.

All of this to say I don’t think Proton Pass is quite as bad as your impression makes it out to be. I don’t use it myself, but I am against removing 1password at the moment because I see the value it offers; just made this reply to clear up some things about Pass so everything is kept fair.

---

## Post 35 by @Bhaelros — 2024-05-16T16:01:12Z

I hope they will continue to provide services with that price. It is good for a single user but they should provide something for the family accounts.

- Biometrics work fine on mobile, and I don’t think they’re common enough on laptops/desktop to really be a major problem.

It is common. I am using Windows Hello on many applications, not just password manager but with Proton Pass I am forced to use only six digit PIN.

- I’m not sure what kind of connection you’re looking for. They both sync just fine, and aren’t limited in functionality.

When I unlock desktop app, it should unlock all browser extensions. 1Password is using browser’s native messaging protocol to do that.

- No set custom ID fields, but notes exist, which can put those things down just fine. It’s not like you really need to worry about autofilling a license key often, so just having it in a note to copy paste it from is perfectly acceptable imo. Having the dedicated feature might be nice for organization, but I don’t think it’s really missing functionality for not having it.

When you import your logins from another password manager, and you have hundreds if not thousands of entries in your vault, you can’t check everything manually to see if they are imported correctly or not. For example, if a site has two password or two username fields, Proton Pass skips one field. For example PIN codes for my credit cards and bank accounts.

- Multi item select is implemented.

Nope, not implemented. Yes, you can select one by one if you call that multiselect. Try to select items by using Shift key or Ctrl key, or even Ctrl+A. Such basic technology doesn’t exist in Proton Pass. Simple test, open your vault and select all items with first letter of A to D.

- Predefined fields and items? I’m not quite sure what you mean by this.

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/1/10ab1f23321e4702a9ce50f852bd1019427c2147.png)

---

## Post 36 by @anon60350980 — 2024-05-16T16:34:25Z

I’ve given it quite a few chances and it’s simply not there yet which is totally fine - don’t get me wrong! It’s a young product, which is why we need to keep 1Password on the site until Proton Pass has like more than 80% of its features and a standalone family subscription separate from Proton Unlimited.

---

## Post 37 by @anon55464882 — 2024-05-26T06:43:41Z

I generally concur that open-source software is preferable to proprietary alternatives. However, a nearly flawless track record spanning almost two decades, as exemplified by 1Password, holds greater significance than the open-source nature of a password manager, particularly when the latter has only been available for just over a year.

In addition to Proton, Bitwarden, and 1Password, PG also recommends Psono. I do not believe Psono is a superior option to 1Password for the majority of users, especially in terms of functionality. Furthermore, 1Password has undergone more security audits since 2019 [[1](https://support.1password.com/security-assessments/)] than Bitwarden [[2](https://bitwarden.com/help/is-bitwarden-audited/)], Proton Pass [[3](https://proton.me/blog/pass-open-source-security-audit)], and Psono [[4](https://psono.com/blog/security-audit-2022)] combined.

While open-source providers are generally preferable, this preference should not result in the exclusion of highly reliable and well-established proprietary providers. For instance, YubiKey [[5](https://www.privacyguides.org/en/multi-factor-authentication/)], which is also proprietary, is also recommended by PG, also there are open source alternatives, e.g., Nitrokey. And many here would still argue that YubiKey is a better choice than Nitrokey despite the fact it is proprietary.

---

## Post 38 by @anon48875053 — 2024-06-29T15:13:44Z

> [@anon55464882](#):
>
> For instance, YubiKey [[5](https://www.privacyguides.org/en/multi-factor-authentication/)], which is also proprietary, is also recommended by PG, also there are open source alternatives, e.g., Nitrokey. And many here would still argue that YubiKey is a better choice than Nitrokey despite the fact it is proprietary.

YubiKey situation is vastly different. You should read this: [https://www.yubico.com/blog/secure-hardware-vs-open-source/](https://www.yubico.com/blog/secure-hardware-vs-open-source/)

YubiKeys are proprietary because they have no choice, 1Password is proprietary because their VC investors wouldn’t be too happy if they went open source.

NitroKeys aren’t open source too, there is no secure element in existence that is entirely open source, and you need one to have a secure key.

---

## Post 39 by @anon48875053 — 2024-06-29T20:36:46Z

> [@anon48875053](#):
>
> 1Password is proprietary because their VC investors wouldn’t be too happy if they went open source.

Also, you know why you can use SimpleLogin with Proton Pass or SimpleLogin, [addy.io](http://addy.io), Forward Email, DDG, Firefox Relay, and Fastmail with Bitwarden but you can only use Fastmail with 1Password? Moneyyyyyyyyyyyyy.

You get 25% off Fastmail when registering through this link:  
[https://www.fastmail.com/signup1password/](https://www.fastmail.com/signup1password/)

---

## Post 40 by @anon48875053 — 2024-08-13T06:53:45Z

Proton Pass has received quite a lot of features in a short amount of time, especially considering that they aren’t VC-funded.

The biggest new feature is probably this one: [https://proton.me/blog/proton-pass-identities-biometric-authentication](https://proton.me/blog/proton-pass-identities-biometric-authentication)

Where are we on this? I think it’s time to enforce this criteria.

---

## Post 41 by @anon49578468 — 2024-08-13T07:34:10Z

+1 to the idea. No reason to not have this requirement now that there are good options all around.

---

## Post 42 by @Rasta — 2024-08-13T18:11:30Z

I’d like to see a bit more feature parody first myself.

---

## Post 43 by @donutfreak — 2024-08-14T02:23:21Z

> [@Rasta](#):
>
> a bit more feature parody first myself.

Parity or parody? :slight_smile:

---

## Post 44 by @anon48875053 — 2024-08-14T09:10:34Z

Parody would probably be a better fit. Bitwarden or Proton Pass features are probably enough for 99% of users.

---

## Post 45 by @redoomed1 — 2024-08-14T15:20:30Z

6 posts were split to a new topic: [Denote source availability for recommended tools](/t/denote-source-availability-for-recommended-tools/20060)

---

## Post 51 by @redoomed1 — 2024-08-14T15:22:12Z

3 posts were merged into an existing topic: [Denote source availability for recommended tools](/t/denote-source-availability-for-recommended-tools/20060/8)

---

## Post 52 by @ikelatomig — 2024-08-15T10:41:52Z

> [@anon60350980](#):
>
> “bridge” - and that is reserved for desktops

And requires a Premium account too to use that bridge.

---

## Post 53 by @anon48875053 — 2024-08-16T06:53:04Z

One more reason to remove 1Password and enforce this criteria:

> [@Mention that 1Password is not working correctly on GrapheneOS without GAPPS](https://discuss.privacyguides.net/t/mention-that-1password-is-not-working-correctly-on-grapheneos-without-gapps/20073):
>
> Hey there, I’ve been using Bitwarden on my GrapheneOS for years, without any issue. Since 1Password is recommended on PG, I gave it a try, particularly because I enjoy Large Type feature and UX of 1Password. Unfortunately, it has a numerous problems on GAPPS-free environment: App can be only obtained via Google Play, therefore Aurora Store is needed; QR scanner is not working without GAPPS - issue reported multiple times on 1Password forum, it does not let you scan anything. Seems like GAPPS…

---

## Post 54 by @anon49578468 — 2024-08-16T08:15:06Z

Hey, just saw this response and a bunch of questions came up.

> [@anon60350980](#):
>
> On mobile, you’re out of luck and have to find peace with their randomly updated (proprietary) mobile clients. No, thank you.

Do you have a source for their mobile clients being proprietary?

> [@anon60350980](#):
>
> Also judging the affordability of a service by it’s yearly cost divided by 12 months is disingenuous at best. That’s not how much Proton Pass costs a month and you know it. It’s one Euro/US Dollar more than 1Password. And the only reason it costs so little when billed yearly is because Proton is desperately trying to push a mediocre product that has nothing of value that other password managers don’t have already.

I understand affordability is a big issue, but its “Privacy” guides, and a lot of recommendations (Pixel phones, Yubikeys) are not always affordable. If affordability is a criteria, lets reexamine a bunch of our tools then. Maybe recommend One Drive or Google Drive with Cryptomator for free storage?

> [@anon60350980](#):
>
> If you’re not sure, then please (!!!) educate yourself on that before you start a thread about removing a very outstanding product.

Is feature availability a privacy criteria? Then I guess most of the recommendations with bad UIs and UXs are out? Lets recommend Gmail or even Microsoft email for the feature laden set of apps and consistent security records?

Ultimately I don’t think PG recommendation would stop you from using whatever software you want to. But it does reflect on the ideals PG wants to push for. I think its always good to remember that PG not listing a tool doesn’t mean you cant use it, it just means PG doesn’t feel it fits the criteria, or promotes practices that PG does not like (for example- being closed source).

If these are the only blockers to adding an open source requirement (none of them privacy based objections), then we should ideally enforce this condition.

And if open source cannot be enforced for password managers, lets start recommending MacOS, iOS, Windows, etc. which are better designed, have more featyres, and sometimes reasonably more secure than the recommended Linux distros and Mobile OSs

---

## Post 55 by @anon48875053 — 2024-08-21T08:37:45Z

> [@Grayjay (Frontend)](https://discuss.privacyguides.net/t/grayjay-frontend/14616/45):
>
> Edit 1: Idk why they’d recommend 1Password though

That’s the whole point.

We have Proton Pass, Bitwarden, Psono, and all the KeePass clients both with and without sync. There are enough options already.

---

## Post 56 by @anon39565454 — 2024-08-21T08:39:49Z

> [@anon48875053](#):
>
> That’s the whole point.
> 
> We have Proton Pass, Bitwarden, Psono, and all the KeePass clients both with and without sync. There is enough options already.

Yeah, It is more understandable when it comes to note taking app. But the password manager recommendation confuses me

---

## Post 57 by @Niek-de-Wilde — 2024-08-21T14:02:47Z

A note here is that we only recommend it because it provides a very good UX for for nontechnical people. We are looking to replace it with with Proton Pass soon as that product continues to mature, and tighten the criteria to require open source.

The side wide policy is that that opensource is preffered, but that close source alternatives are allowed if they provide genuin UX or security improvements.

---

## Post 58 by @Bhaelros — 2024-08-21T15:52:35Z

I can understand if an app doesn’t go through regular audits, has unclear and non-privacy friendly policies, but in 1Password that is not the case.

Yes, being open-source is the ideal scenario, because it lets people to inspect the code, but many other people who doesn’t have deep coding knowledge trusts on audits. In 1Password’s case they are having frequent audits, so I don’t understand why some people are against it.

Yes, there are open source alternatives, but none of them are having functionalities, security features and audits like 1Password.

---

## Post 59 by @TrashPanda — 2024-08-21T17:47:15Z

> [@Bhaelros](#):
>
> Yes, there are open source alternatives, but none of them are having functionalities, security features and audits like 1Password.

But they do have - all other managers listed on PG are going through regular audits, are feature-rich and are open source. However, I’m with you regarding keeping 1Password listed on PG, since it has good reputation and is indeed private.

---

## Post 60 by @Pragmatic — 2024-08-21T17:53:25Z

What about Bitwarden and Keepass?

---

## Post 61 by @Bhaelros — 2024-08-21T18:06:02Z

Both are already open source but their features are not on par with 1Password. As for audits 1Password has the most audits compared to Bitwarden and Keepass.

Ref:

> **[Awards/Ratings - KeePass](https://keepass.info/ratings.html)**

> **[Compliance, Audits, and Certifications | Bitwarden](https://bitwarden.com/help/is-bitwarden-audited/)**
>
> Review information about third-party security audits, our open source codebase, and our zero knowledge encryption model.

> **[Security audits of 1Password | 1Password Support](https://support.1password.com/security-assessments/)**
>
> 1Password products have been reviewed by multiple independent security firms.

@TrashPanda I agree with you. 1Password is the only exception closed source password manager app which I can consider for PG. I don’t trust rest of the apps unless they prove that they are safe and privacy friendly.

---

## Post 62 by @anon48875053 — 2024-09-14T05:20:16Z

Bitwarden has rewritten some of their apps to have an improved UX and especially UI. Just tried their new Android client, and it’s awesome!

---

## Post 63 by @anon23293884 — 2024-09-14T15:40:51Z

> [@jonah](#):
>
> The SSH agent in particular is kind of a killer 1Password feature for me, although _in general_ that’s probably too niche for most people to care about.

Perhaps I’m approaching this topic in a unique way because I’m still learning and exploring it.

Could it be possible that if a large proportion of users don’t utilize Secure Shell (SSH), it could potentially present challenges for those who are new to the product, as it could be susceptible to misuse by those with malicious intent?

---

## Post 64 by @fria — 2024-11-20T23:51:06Z

Need to revisit this. There are so many open source password managers available now there’s no reason not to make it a requirement.

---

## Post 65 by @mentalfoss — 2024-11-21T00:22:29Z

Revisit what?

18 votes already to something really obvious that should not needed to be voted on.

Password managers are probably the most sensitive apps out there.  
Not having an open source criteria for them is just laughable.

---

## Post 66 by @fria — 2024-11-21T00:24:10Z

Yeah I agree it’s a long time coming I think. There didn’t used to be as many good open source options as there are now and they’re only getting better over time.

---

## Post 67 by @mentalfoss — 2024-11-21T00:42:48Z

I believe there were good enough options at all times.  
Keepass was always there, or even Password Safe back then.

The problem is the criterias like cross-platform, syncing, online-local, with iOS being the main problem with their restricted and expensive ecosystem.  
These criterias, are important, but should never overcome the open source one, especially for password managers.

---

## Post 68 by @xe3 — 2024-11-21T03:04:31Z

I have mixed feelings,

IMO for a password manager–because this is often _the very first step_ less technical people take towards improving security or privacy–very easy/intuitive UX, and very hard to screw up UX, and easy/reliable backups are paramount for at least one of the recommendations.

I have helped a handful of relatives transition from Lastpass to Bitwarden, and among my less technical relatives, the feedback I’ve received is mostly positive, but common complaints about autofill, about inconsistent auto-recognition of new logins, and just general minor confusion with UI/UX. From what I’ve heard, most people on this forum who have used both Proton Pass and Bitwarden Premium say that Pass is not yet on par with Bitwarden, so I assume Pass wouldn’t be an improvement for this demographic at this point in time.

So my concern is that a _premature_ requirement for open-source only may be a case of “letting great be the enemy of good” because we would arguably be ruling out the option that is most appropriate for the broadest audience. (I say premature, because I expect both Bitwarden and Proton Pass to continue the steady course of improvement).

With that said, I could probably just as easily make the opposite argument (that open source or at least source available clients is mandatory) and for my own personal choices, I consider open source clients to be a hard requirement for a password manager. And just as a general value, I prefer to highlight and promote FOSS projects over proprietary ones.

---

## Post 70 by @fria — 2024-11-21T04:15:02Z

The requirements are different for different types of software and services. It’s not really ideal to try and force a single set of requirements for everything. Some things are specific to the type of software, some software might be able to run fully offline while others can’t like search engines. Sometimes there aren’t very many options for software, sometimes there’s an abundance of great options so the requirements can be tightened. It’s an ever evolving thing. Generally we try to tighten the requirements over time because usually there are more options and the offerings improve over time as well.

---

## Post 72 by @mangomango — 2024-11-21T05:24:14Z

> [@fria](#):
>
> many open source password managers

Can you explicit ? What are those ? I only know of Proton, Bitwarden and KeePass

---

## Post 74 by @anon48875053 — 2024-11-21T06:18:21Z

Thanks for bringing this up, it was long overdue.

---

## Post 75 by @Niek-de-Wilde — 2024-11-21T07:45:54Z

The reason was that stuff like keepass is to difficult for certain users, even Bitwarden wpuld be too difficult for some older folks. This criteria allowed for some password managers that were closed source, but had a good UX.

That said, currently I do think that Protonpass has grown into a fully fledged password maanger that has a good enough UX, so I too think we can go ahead and merge this new criteria.

---

## Post 76 by @anon80779245 — 2024-11-21T08:49:03Z

Just for clarity, do we want to implement a full open-source requirements, or just FUTO-like “Source - first”?

I am asking this because if we say open-source, then we must be ready and willing to remove Bitwarden if they start again with SDK license shenanigans.

---

## Post 77 by @anon48875053 — 2024-11-21T09:16:23Z

In my humble opinion, source first is better than open source.

> **[Source First](https://sourcefirst.com/)**

---

## Post 78 by @Regime6045 — 2024-11-21T10:20:53Z

While I’m personally an advocate for FREE (better term than open source) software, I think “source available” is good enough because that’s what matters the most if you want to be (theoretically) able to check if the application is actually protecting your passwords.

---

## Post 79 by @Niek-de-Wilde — 2024-11-21T10:24:54Z

See: [What does Privacy Guides see as OpenSource?](https://discuss.privacyguides.net/t/what-does-privacy-guides-see-as-opensource/20230)

---

## Post 80 by @sha123 — 2024-11-21T11:59:41Z

> [@fria](#):
>
> Need to revisit this. There are so many open source password managers available now there’s no reason not to make it a requirement.

Don’t make unnecessary requirements, just because there are alternatives.

---

## Post 81 by @xe3 — 2024-11-21T20:34:23Z

For those who want to change the criteria, I think there are two primary questions to answer:

1. should the minimum criteria require: _source-availability_, or _free and open source?_
2. should the criteria apply only to _client side software_ (the “apps” and browser extension) or should it apply to _all the code necessary to use the service (both client and server side)_?

> [@anon80779245](#):
>
> I am asking this because if we say open-source, then we must be ready and willing to remove Bitwarden if they start again with SDK license shenanigans.

If the criteria weren’t specifically limited to open source (or source available) _clients_ Proton Pass would be eliminated long before Bitwarden. _IF_ the criteria is to be changed, It’d be worthwhile to consider unintended consequences that could impact Proton Pass now (or a hypothetical future Bitwarden).

* * *

* * *

> **[example criteria from other sections]**
>
> The VPN criteria or the RTC criteria are two examples of sections where the Criteria is crafted in such a way that availability of FOSS _clients_ is mandatory but the requirement is limited to to client-side-software only.
> 
> - RTC keeps it short and sweet:
> - 
> 
> > Criteria: Has open-source clients.
> 
> - VPN gives a bit more explanation: \*
> - 
> 
> > Criteria: If VPN clients are provided, they should be [open source](https://en.wikipedia.org/wiki/Open_source), like the VPN software they generally have built into them. We believe that [source code](https://en.wikipedia.org/wiki/Source_code) availability provides greater transparency about what your device is actually doing.\*

---

## Post 82 by @jonah — 2024-11-21T20:39:59Z

Another thing I will point out is that if we agree with the arguments being made in this thread, then logically we must also require open-source for security keys as well, which play the same role in many people’s workflows.

I don’t agree with the need for this criteria, personally.

---

## Post 83 by @anon80779245 — 2024-11-21T20:45:49Z

> [@jonah](#):
>
> then logically we must also require open-source for security keys as well, which play the same role in many people’s workflows.

Not necessarily. Physical keys are very unlikely to ever screw you over with TOS changes.

Plus, there aren’t many security keys while there is plenty of password managers.

---

## Post 84 by @anon80779245 — 2024-11-21T20:48:52Z

> [@anon48875053](#):
>
> In my humble opinion, source first is better than open source.
> 
> [https://sourcefirst.com/](https://sourcefirst.com/)

This is out of subject, and lets not get drown away.

---

## Post 85 by @fria — 2024-11-21T20:56:38Z

I think those could be a separate discussion. The only open source keys I’m aware of are nitro keys, so I think with the limited selection it makes sense not to do that for security keys.

---

## Post 86 by @anon29374801 — 2024-11-21T21:25:33Z

Feels like this discussion should be tabled until people can agree on what they even mean by open source, which should probably be its own thread.

~~I know PG has its own definition but~~ I have seen others throw out their preferred definiton as well.

This whole things feels a bit ambigious, with no clear benefit other then people like open source stuff more then closed source.

---

## Post 87 by @phnx — 2024-11-21T21:28:52Z

PG already has an agreed-upon definition of open-source. Given that many other categories already require open-source (not source available and the like), I think it makes the most sense to stick with that definition throughout the site.

> [@Niek-de-Wilde](#):
>
> See: [What does Privacy Guides see as OpenSource?](https://discuss.privacyguides.net/t/what-does-privacy-guides-see-as-opensource/20230)

---

## Post 88 by @anon29374801 — 2024-11-21T21:30:37Z

I understand that but it I have seen people mention this should be source first or source available instead. The thread was created over a year ago, its unclear to me if the intent was to even use open source as defined by PG when it was created. ~~Considering that the definiton PG decided upon looks to have been finalized around Aug 2023 (based on the dates in the thread) and this thread was made in April 2023~~

EDIT: apparently PG has [no agreed upon definiton](https://discuss.privacyguides.net/t/require-open-source-for-password-managers/12480/93) of open source, which makes this criteria even more ambigious.

---

## Post 89 by @anon48875053 — 2024-11-22T05:49:58Z

> [@xe3](#):
>
> should the minimum criteria require: _source-availability_, or _free and open source?_

1. Users should be able to see the code.
2. Users should be able to build the app using the public source code.
3. Users should be able to modify and distribute their forks for non-commercial purposes.

> [@xe3](#):
>
> should the criteria apply only to _client side software_ (the “apps” and browser extension) or should it apply to _all the code necessary to use the service (both client and server side)_?

It should only apply to clients, but we could have a best-case criteria that also applies to servers.

---

## Post 90 by @anon55464882 — 2024-11-22T06:15:31Z

> [@xe3](#):
>
> should the minimum criteria require: _source-availability_, or _free and open source?_

I think from a pure privacy perspective source-availability should be sufficient.

---

## Post 91 by @anon48875053 — 2024-11-22T06:20:54Z

Why YubiKeys aren’t open-source:

> **[Secure Hardware vs. Open Source](https://www.yubico.com/blog/secure-hardware-vs-open-source/)**
>
> Explore Yubico's stance on OpenPGP implementation on the YubiKey 4, emphasizing their commitment to open-source software and robust security. Learn about their security strategy, product developments, and future intentions.

Why 1Password isn’t open-source:

> **[Mr. Krabs - I Like Money - Meme Source](https://www.youtube.com/watch?v=xW0IR3q0EvE)**
>
> Mr. Krabs - I like moneyMeme Source

---

## Post 92 by @anonfox — 2024-11-22T07:28:58Z

Open source is better. With a source available model, people won’t be as incentivized to look at the code since they can’t use it for their own purposes, while it’s the opposite with open source e.g. vaultwarden devs probably monitor a lot of changes in the bitwarden code. It will have more eyes looking at its changes this way.

---

## Post 93 by @Niek-de-Wilde — 2024-11-22T11:06:45Z

The thing is that we actually do not. We list open source as a requirement for a few things, but we have never exactly esthablished what that means.

This is because Open source means a lot of different things for a lot of different people, which is what that discussion is for.

In any case, it looks like we will be following the OSI model, but is has not been decided yet.

---

## Post 94 by @phnx — 2024-11-22T11:22:36Z

At the time your post [here](https://discuss.privacyguides.net/t/what-does-privacy-guides-see-as-opensource/20230/43) said “Our definition of Open-source follows the [OSI definition](https://opensource.org/osd)” but I see that pull request was recently closed.

If the project wants to evaluate whether the open-source criterion should be changed to source-available, that is one thing, but it makes little sense to change the agreed-upon definition of open-source (not to mention the confusion it would cause). Even projects like FUTO accept the OSI definition of open-source and instead market themselves as source-available or source-first.

---

## Post 95 by @Niek-de-Wilde — 2024-11-22T11:48:31Z

Again, we never had defined definition, which is what that thread is for. It came to light because of running issues with existing youtube clients in comparison to GrayJay.

And as an added note, nothing is official until its live on the site. :slight_smile:

---

## Post 96 by @phnx — 2024-11-22T12:07:01Z

I was only referring to the same topic that you originally linked. While I admit I was incorrect in saying that PG already had an agreed-upon definition of open-source, in practice, the OSI definition has been the [de facto](https://en.wikipedia.org/wiki/De_facto) definition.

Regardless, open-source is a word and PG is not a dictionary; the OSI definition is already widely recognised. If PG wants to abandon requiring open-source in favour of source-availability, that is a different question entirely.

---

## Post 97 by @anon29374801 — 2024-11-22T16:04:10Z

> [@phnx](#):
>
> the OSI definition has been the [de facto](https://en.wikipedia.org/wiki/De_facto) definition.

I don’t think its a great precedent to just claim something is de facto to sidestep a conversation you rather not have in a rush to create a criteria with no clear benefit. If you want the OSI definition to be the definition PG uses as its standard, get it approved.

Otherwise, there should be a discussion and agreement of what is meant by open source (if thats the term people even want to use) in terms of this criteria before its even considered to move forward.

---

## Post 98 by @mentalfoss — 2024-11-23T10:13:11Z

Well let’s just mini analyze the current case for the recommended password managers that are not open source and they are on the list.

**1Password**  
The product even as an online closed source password manager has endured in time. But it is and will probably always be an online closed source password manager. Only by that definition nobody will be surprised if something like what happened to LastPass happen also to 1Password.  
There are plenty online open source alternatives with good reputation already like Proton Pass and Bitwarden that keep listing 1Password makes no longer sense.

**Strongbox**  
That’s an one-man freemium project which source isn’t available to build the app, even some parts are posted on their GitHub page.  
Only because of that, should mark the project shady.  
The only reason is it listed it is because of the iOS + macOS support, compared to the real open source iOS password manager KeePassium which is also lately got audited by [Cure53](https://keepassium.com/blog/2024/11/independent-security-audit-complete/) that doesn’t have macOS support.  
Though, they both are using the KeePass protocol that it is cross-platform so it makes no sense to list an inferior password manager. (KeePassium with KeePassXC for iOS-macOS combo is more than enough for example)

Lastly about the talks to divert the topic of requiring also open source for hardware keys and what is the real meaning of open source is just whatever.  
Hardware keys are already in another section of the guide, they can have their own criteria as long as there are not enough options at the moment.  
And trying to solve in this thread the meaning of open source, just to keep a paid online closed source password manager and a shady freemium password manager on the recommendation list is just absurd.

---

## Post 100 by @Niek-de-Wilde — 2024-11-23T13:20:48Z

As i have repeated above PG, as in the Team, has not made a clear decision yet on what definition we will follow, this is why that thread is created, currently it is to vague, which is the problem we are now trying to fix.

---

## Post 102 by @Niek-de-Wilde — 2024-11-23T13:38:02Z

I know that this thread and that thread have different purposes. Its why that thread has to be complete before this one, in my opinion, as we already have an issue with requiring opensource when we have never defined what that means in the first place, which is problematic.

---

## Post 104 by @anon48875053 — 2024-11-23T14:08:50Z

> [@What does Privacy Guides see as OpenSource?](https://discuss.privacyguides.net/t/what-does-privacy-guides-see-as-opensource/20230):
>
> Continuing from this discussion: [https://discuss.privacyguides.net/t/grayjay-frontend/14616](https://discuss.privacyguides.net/t/grayjay-frontend/14616) Open source is a complex term with lots of different takes that depends on what kind of perspective one looks from. For some open source simply means that you can check the source code. For the other the exact license about what one can do with that code matters (FOSS vs open source). Another thing to keep in mind is whether we care about reproduceable builds, so a user can make sure that the source c…

---

## Post 106 by @Niek-de-Wilde — 2024-11-23T14:23:13Z

Wasn’t me, lol.

---

## Post 107 by @anon29374801 — 2024-11-23T16:41:42Z

> [@Anon47486929](#):
>
> People keep repeating this as if this is needed.

> [@Niek-de-Wilde](#):
>
> as we already have an issue with requiring opensource when we have never defined what that means in the first place, which is problematic.

It’s been concerning how many people in this thread refuse to see this as problematic.

> [@Anon47486929](#):
>
> There are multiple benefits

I will try and respond to the benefits you listed but, it seems like the point of these benefits, in this context, have been lost. I am questioning the benefits of why open source should be a criteria for password managers, not the benefits of open source in general.

> [@Anon47486929](#):
>
> continuity for users if the company ever shuts down

Not sure this should even be considered a benefit. There are still so many challenges in the way for this type of “continuity” to be successful that it makes the benefit improbable, including loss of expertise, fragmentation, and lack of financial support.

> [@Anon47486929](#):
>
> prevents company from using shitty encryption code

> [@Anon47486929](#):
>
> it prevents company from adding malicious client code to releases

This is why audits are already a criteria.

> [@Anon47486929](#):
>
> it allows people to understand the architecture and verify fundamental mistakes in DB orgs that can reveal users

You say this like there isn’t a massive expertise gap for the majority of users preventing them from realizing this benefit. This benefit is also a double edged sword, the availability of source code can create a false sense of security, potentially leading to less rigorous internal verification processes.

---

## Post 108 by @fria — 2024-11-23T17:26:58Z

> [@anon29374801](#):
>
> This benefit is also a double edged sword, the availability of source code can create a false sense of security, potentially leading to less rigorous internal verification processes.

I don’t really think that’s fair to say. There’s not any reason software developers would suddenly stop caring about security just because something is open source. They don’t even need to take contributions if they don’t want to.

---

## Post 109 by @anon29374801 — 2024-11-23T17:31:59Z

> [@fria](#):
>
> There’s not any reason software developers would suddenly stop caring about security

I did not say there was. The issue isn’t a lack of caring, the issue is a false sense that “if we do slip up, the community will catch us” which can lead to less rigorous verification. Which I think is fair to point out. I think this attitude is very prevalent in the open source community, that nothing bad can happen with the code because the community is always reviewing it.

---

## Post 110 by @fria — 2024-11-23T17:32:42Z

Well that’s why we require audits from reputable third parties. Which are much more important than the product being open source.

---

## Post 111 by @Niek-de-Wilde — 2024-11-23T17:33:09Z

/me Points frantically in the direction of Heartbleed

---

## Post 112 by @anon29374801 — 2024-11-23T17:33:53Z

> [@fria](#):
>
> Well that’s why we require audits from reputable third parties.

Which I pointed out.

> [@anon29374801](#):
>
> This is why audits are already a criteria.

Which goes directly to my point that

> [@anon29374801](#):
>
> it seems like the point of these benefits, in this context, have been lost. I am questioning the benefits of why open source should be a criteria for password managers

---

## Post 113 by @fria — 2024-11-23T17:34:33Z

> [@anon29374801](#):
>
> Which I pointed out.

But you were using that as a point against open source when it’s not.

---

## Post 114 by @anon29374801 — 2024-11-23T17:35:26Z

> [@fria](#):
>
> But you were using that as a point against open source when it’s not.

Its all the same. In that, we already have criteria covering these “benefits” that people are using as reasons why open source should be a criteria for password managers.

---

## Post 115 by @anon48875053 — 2024-11-23T17:39:18Z

Regarding audits being a replacement for FOSS, I will just quote a piece from GrapheneOS:

> The benefits of a group unfamiliar with the code spending a short time doing a shallow review are greatly overstated in marketing.

> **[GrapheneOS Frequently Asked Questions](https://grapheneos.org/faq#audit)**
>
> Answers to frequently asked questions about GrapheneOS.

---

## Post 116 by @anon29374801 — 2024-11-23T18:08:29Z

Honestly this feels more like an argument for why the criteria should be changed to be regular audits and not “a published audit”…

Obviously GOS is very proud of being open source but, I am not sure their commitment to easily reviewable code and having “relationships with security researchers and organizations” is apples to apples with how other open source projects operate.

I think if we are going to use GOS as a model then those two aspects, easily reviewable code and strong relationships with security researchers and organizations, would need to be met before we could truly say a company or tool has met the standard of open source.

---

## Post 118 by @xe3 — 2024-11-24T04:31:43Z

> [@Anon47486929](#):
>
> so I don’t think PG would need to disqualify Proton Pass. So the requirement for minimum would be open source clients, and best possible situation would be open source stack (client and back end both).

_If_ the criteria for PWMs are changed to include a requirement for open source, the above is inline with what I believe would make the most sense (open source _clients_ are mandatory minimum criteria, and open source client + server is best-case criteria).

For reference, what you’ve described is precisely how the criteria are currently written for the ‘Real Time Communication’ section:

> Minimum Requirements:
> 
> - Has open-source clients.
> 
> Best Case:
> 
> - Has open-source servers

The only thing I’d add is for best case, I think we could/should try to also acknowledge and recognize those services that go above and beyond simply open-sourcing server side stuff, by making an effort to really document, and support and empower users ability to self-host as an option/alternative (examples: Bitwarden, Addy, Adguard, Ente).

---

## Post 119 by @anon48875053 — 2024-11-24T07:28:43Z

Now that Jonah has [decided](https://discuss.privacyguides.net/t/what-does-privacy-guides-see-as-opensource/20230/91) that PG sees open source as defined by OSI, could we proceed with this requirement?

---

## Post 120 by @Niek-de-Wilde — 2024-11-24T08:43:45Z

It would seem so, we now have a proper term to work with.

---

## Post 121 by @ignoramous — 2024-11-24T08:55:00Z

> [@Niek-de-Wilde](#):
>
> Points frantically in the direction of Heartbleed

What?

The FOSS community did wise up and numerous forks and alternative implementations emerged in the wake of Heartbleed (for example, AWS switched to its own formally-verified, nimble TLS implementation). Not to mention the then poorly-resourced and under-funded OpenSSL managed to raise a substantial amount & directly lead to the creation of a well-financed initiative within the _Linux Foundation_ that now supports many such _critical_ FOSS projects.

If you follow the security scene at all, you’d know that each of the major setbacks have strengthened FOSS. Au contraire, with closed source shops, you only get “no comment” wrt breaches, most of the time.

---

## Post 122 by @Niek-de-Wilde — 2024-11-24T08:58:38Z

Do not take that comment to seriously, I was obviously joking around there. :wink:

---

## Post 123 by @jonah — 2024-11-24T09:09:19Z

Alright, coming back to this. I still don’t really understand the motivation behind removing well-regarded products _solely_ because of their source code licensing (or lack thereof).

Historically we have only removed recommendations when something happens that directly impacts people’s privacy negatively.

It seems like some people in this community [don’t think open source has any relation to privacy](https://discuss.privacyguides.net/t/what-does-privacy-guides-see-as-opensource/20230/78), so by that logic we shouldn’t feel the need to delist 1Password.

Some (many?) other people in this community think that open source is related to privacy, but in a more indirect/idealistic way ← [I am in this camp](https://discuss.privacyguides.net/t/what-does-privacy-guides-see-as-opensource/20230/90)

In either case it still doesn’t make sense for either of these camps to delist 1Password for source availability reasons _alone_, I don’t think.

As far as I see it, the only reason we would want to add this criteria is if we collectively believe that software being open source is a **requirement** for privacy/security. I believe this is a minority viewpoint, and it’s a point that we have explicitly tried to [downplay](https://www.privacyguides.org/en/basics/common-misconceptions/#open-source-software-is-always-secure-or-proprietary-software-is-more-secure) in our content, as we prefer to evaluate products based on our current best judgement of how they are _as-is_.

Therefore… I still continue to believe that we should not add this minimum criteria :slight_smile:

---

## Post 127 by @anon80779245 — 2024-11-24T09:31:30Z

Let’s do a Poll to help us decide. All votes are PUBLIC to prevent people from faking it with burner accounts.

_Poll: Poll (view on site)_

---

## Post 128 by @jonah — 2024-11-24T09:33:11Z

> [@Anon47486929](#):
>
> Instead of asking why open source for any category, the question should always start from the solid base of “Why not”. The reasons can be practicality, too bare bones solutions, etc. but the justification should always be why not open source.

We have **already** justified why not open source, [when we added 1Password](https://github.com/orgs/privacyguides/discussions/41), as all such recommendations are discussed within the community.

Now we are attempting to undo this discussion from 2 years ago based simply on a feeling that open source is always better?

To which I would reiterate everything I said here: [Require Open Source for Password Managers - #123 by jonah](https://discuss.privacyguides.net/t/require-open-source-for-password-managers/12480/123)

I am against unnecessarily undoing existing work.

---

## Post 129 by @Niek-de-Wilde — 2024-11-24T09:36:40Z

We can undo a decision that was made before, but only if new information or a new point of view came to light that we have not taken in before.

So far however, I do not really see any arguments mentioned here that were not mentioned before.

Edit to add on this: earlier in this thread I was on board with adding opensource as a requirement, my reason for changing my opinion where @ph00lt0 comments on the open source definition thread.

---

## Post 130 by @anon55464882 — 2024-11-24T09:42:31Z

> [@jonah](#):
>
> In either case it still doesn’t make sense for either of these camps to delist 1Password for source availability reasons _alone_, I don’t think.

I agree that proprietary software is inherently less privacy-conscious than open-source alternatives. However, I do think we should prioritize open-source services over their proprietary counterparts.

In my opinion, Privacy Guides should maintain a consistent approach regarding their recommendation criteria. If we set open-source availability as a minimum requirement for tools like Notebooks or Office Suites, and require source availability for MFA, we should also reassess whether we shouldn’t apply similar standards to much more sensitive tools like password managers.

---

## Post 132 by @jonah — 2024-11-24T09:45:38Z

> [@anon55464882](#):
>
> In my opinion, Privacy Guides should maintain a consistent approach regarding their recommendation criteria.

I am firmly against consistent _site-wide_ criteria across different categories for reasons we are currently discussing in this thread: [Should Privacy Guides require open-source, source-first or source-available as a criteria for all tools? - #4 by jonah](https://discuss.privacyguides.net/t/should-privacy-guides-require-open-source-source-first-or-source-available-as-a-criteria-for-all-tools/22684/4)

---

## Post 134 by @Niek-de-Wilde — 2024-11-24T09:50:12Z

Quickly hopping in here, 1password could be removed even without requiring open source, the listing of 1password and the change of the criteria are two seperate discussions.

---

## Post 136 by @jonah — 2024-11-24T09:59:10Z

> [@Anon47486929](#):
>
> So the question can be reframed to: Why not open source now. And this question should keep echoing as tech changes.

I don’t really think so, personally. Without an active/direct reason to change a current criteria I think the recommendations should be left as-is. In other words:

> [@Niek-de-Wilde](#):
>
> We can undo a decision that was made before, but only if new information or a new point of view came to light that we have not taken in before.

* * *

I don’t think we should start removing products with no clear deficiencies purely because other products improved themselves. This kind of churn is confusing to readers.

I see changes like this as promoting instability in the privacy space, which is a common complaint among people learning about the topic and seeking tool recommendations. This is why we add and remove tools cautiously.

Basically, the way I think about it is:

- When we **add** new tools, we need a strong justification on why they are substantially **better** than the alternatives.
- When we **remove** existing tools, we need a strong justification on why they are substantially **worse** than the alternatives.

I don’t think this second justification is met simply based on open source alone.

* * *

> [@Niek-de-Wilde](#):
>
> the listing of 1password and the change of the criteria are two seperate discussions.

Yes, but as far as I know there are zero reasons to delist 1Password given in the [Remove 1Password](https://discuss.privacyguides.net/t/remove-1password/13921) thread besides the desire to make the criteria change in this thread.

And on the other hand, making the proposed criteria change here would affect 1Password exclusively.

So these topics are related, this is just a more specific discussion.

---

## Post 137 by @jonah — 2024-11-24T10:01:12Z

A post was merged into an existing topic: [Should Privacy Guides require open-source, source-first or source-available as a criteria for all tools?](/t/should-privacy-guides-require-open-source-source-first-or-source-available-as-a-criteria-for-all-tools/22684/8)

---

## Post 138 by @phnx — 2024-11-24T09:59:34Z

There are alternatives to 1Password that are at least as good _while_ being open-source. I can understand that in some cases there is no better choice, but here we have competitive alternatives that are open-source. Favouring open-source apps is already the [existing policy](https://discuss.privacyguides.net/t/should-privacy-guides-require-open-source-source-first-or-source-available-as-a-criteria-for-all-tools/22684/5).

Some people may point out that 1Password has a superior UI, but they are also seriously lacking in some important areas like Email Aliasing, so in my opinion, the alternatives are more competitive than some people think.

> **off topic voting**
>
> Requiring a trust level would prevent burner accounts from voting which was Encounter5729s concern.

---

## Post 139 by @jonah — 2024-11-24T10:00:36Z

> [@jonah](#):
>
> Basically, the way I think about it is:
> 
> - When we **add** new tools, we need a strong justification on why they are substantially **better** than the alternatives.
> - When we **remove** existing tools, we need a strong justification on why they are substantially **worse** than the alternatives.

Another way to put this is: Would I agree with adding 1Password to the list today if it wasn’t on there already? Probably not.

However, is there a substantial reason to remove 1Password from the list today given that it is already on there? No, I don’t think this is the case either.

Therefore, no changes needed.

---

## Post 141 by @xe3 — 2024-11-24T10:15:54Z

I’d only point out that this isn’t a binary. It isn’t a choice between _dynamic_ recommendations, and _static_ recommendations. Its a question of what is the right point on the spectrum between very stable, and always-changing. Lots of space between those two extremes for there to be a happy middleground

---

## Post 142 by @jonah — 2024-11-24T10:15:57Z

See we are still talking about something significantly different here.

I am saying that just because Proton Pass **caught up to** 1Password, doesn’t mean we should remove 1Password.

In your example with IRC, that is a case of IRC **falling behind** Signal.

IRC falling behind Signal (and therefore being delisted) is not an equivalent situation to Proton Pass catching up to 1Password (which shouldn’t inherently imply 1Password should be delisted).

So this example is _supporting_ my overall point, which is that in order to remove 1Password I think we need to prove that 1Password has **fallen behind** the alternatives, and I don’t think that is the case.

> [@Anon47486929](#):
>
> If the fundamentals are equal, open source IS the major difference.

So we agree that open source is the only major difference, and what I am saying is that this difference alone is not a substantial enough reason to change our criteria.

---

## Post 143 by @phnx — 2024-11-24T10:18:31Z

You know what, I think your post has inadvertently changed my mind.

We shouldn’t forget that those of us who are active on this forum are probably not very representative of the average user who relies on PrivacyGuides recommendations.

There is certainly an implication (intentional or not) that recommendations which are removed are no longer trustworthy. Given the important role of password managers, I do think it warrants extra caution to avoid giving people the impression that they must switch ASAP.

Moreover, the other options like Bitwarden have been embroiled in their own controversies recently, and it would really be a worst-case scenario for PGs’ reputation to push people from 1Password to Bitwarden only to once again tell them to switch.

* * *

All that being said, I would personally support encouraging those users who have not yet switched to one of PGs recommended password managers to choose one of the open-source options.

---

## Post 145 by @phnx — 2024-11-24T10:28:11Z

> [@Anon47486929](#):
>
> This is also something PG needs to shed. It is not realistic to get the team to review every single option, and thus non-recommendation should not imply recommendation against. It is the same issue keepassium highlighted. PG is not comprehensive review of tools, its curation of reasonable ones. But I can empathize with this viewpoint.

Sure, but a non-recommendation is very different from a withdrawn recommendation. If I have selected a tool based on a recommendation here and it is suddenly gone, I will be concerned, especially when the tool is something as important as a password manager. The information on why tools are removed often isn’t very accessible without digging deep on this forum, which isn’t a realistic expectation of the average user.

---

## Post 147 by @jonah — 2024-11-24T10:36:47Z

> [@Anon47486929](#):
>
> But if the well known benefits of open source are not compelling enough to the PG team, then any further arguments would not be useful, since I can’t change individual perspective.

Well, this is something that many people within the community and on the team have strongly rallied against historically. And still do.

Personally _I_ could be convinced that open source is a very significant factor when it comes to privacy, but as a steward of this community I also know and can accept that the _general consensus_ is that it **isn’t** substantial enough for us to require it. It’s a consensus that has been pretty long established now.

So in order to maintain consistency with our past decisions and to implement what I believe the general consensus still overall is, I am going to continue maintaining that no change is necessary here.

---

## Post 149 by @phnx — 2024-11-24T10:42:23Z

> [@Anon47486929](#):
>
> And again, its particularly unfair to impose worse tools on new users just because old users are using it.

I agree, and I’m not opposed to requiring password managers to be open-source. I would generally be in favour of such a change, but it needs to be done with special care.

---

## Post 150 by @jonah — 2024-11-24T10:58:04Z

> [@Anon47486929](#):
>
> Different lenses ig. For me, the delta (difference) should always be considered. IRC to signal is increasing delta in favor of Signal so Signal is recommended, 1Pass vs Proton Pass or BW is decreasing delta in favor of Proton Pass (and positive delta in some cases), so the latter should be recommended.

This is what is being considered though. Bear with me, I feel like I have to diagram this but maybe this will make no sense lol

If we are in this imaginary world where we recommend IRC on the site and it’s the only option out there, we’re in a situation like this:

 ![2024-11-24 at 04.41.15](//forum-uploads.privacyguidesusercontent.com/original/2X/3/3111a24a96eac039e85e48e0f596f792564b3fb6.png)

Then Signal comes along and the delta between the two products is highly significant, and very obviously warrants a criteria change. We make a criteria change and delist IRC as a result:

 ![2024-11-24 at 04.41.15](//forum-uploads.privacyguidesusercontent.com/original/2X/b/beacc0be370ea84d54ecf9d14f29923ab7dce148.png)

* * *

Now… when it comes to our current password manager criteria, I consider our recommendations originally were along these lines:

 ![2024-11-24 at 04.41.15](//forum-uploads.privacyguidesusercontent.com/original/2X/3/32e69e383212f2a6f33abcfcda4b94c4b6eadd5a.png)

Eventually Proton Pass and/or Bitwarden caught up in feature-parity to 1Password[[1]](#footnote-68424-1), and are maybe even slightly ahead, but the delta between **all** of our current password manager recommendations including 1Password is quite insubstantial:

 ![2024-11-24 at 04.41.15](//forum-uploads.privacyguidesusercontent.com/original/2X/a/a1479a0a9dbed3dd960a95e1e3841d9a60a24195.png)

From my perspective, this :arrow_up: is the situation now, and the delta between our current recommendations is clearly not enough to warrant any sort of criteria change.

The only reason we’d want to raise the bar right now, I think, is if a brand new password manager came on the scene that was clearly **worse** than our existing recommendations, call it X:

 ![2024-11-24 at 04.41.15](//forum-uploads.privacyguidesusercontent.com/original/2X/6/6a63c69183248ddec182fd771317dbc517cd1a14.png)

If we were in _this_ situation, I would say a criteria change _is_ warranted in order to ensure “X Password Manager” isn’t added to the website, in turn maintaining the quality of our recommendations.

* * *

1. although in reality they haven’t because 1Password still has power-user features like an ssh-agent, but that is besides the point [↩︎](#footnote-ref-68424-1)

---

## Post 151 by @jonah — 2024-11-24T11:10:07Z

Now that I have looked at it I guess I could have just summed it up as:

- I am looking at the difference _between_ our recommendations as they currently stand
- You are looking at the amount Proton Pass has improved relative to where it began

…which I don’t think is a useful way of determining what our criteria should be, really.

---

## Post 152 by @redoomed1 — 2024-11-24T21:00:51Z

3 posts were merged into an existing topic: [Remove 1Password](/t/remove-1password/13921/51)

---

## Post 156 by @Bhaelros — 2024-11-24T12:15:57Z

If you are saying open source software is safer than closed source software, then I can point several Linux kernel bugs which existed for several years.

Being open source doesn‘t mean bugs and vulnerabilities will be fixed overnight. And yes having the most audits with remediations mean it is more secure than the others, as well as bug bounty programs.

---

## Post 158 by @Bhaelros — 2024-11-24T12:24:39Z

On every new audit you can see if the previous vulnerabilities and bugs are fixed or not. So, they are making the software more secure

---

## Post 160 by @fria — 2024-11-24T13:03:26Z

> [@Anon47486929](#):
>
> This is also something PG needs to shed. It is not realistic to get the team to review every single option, and thus non-recommendation should not imply recommendation against.

Yeah I never really saw it as anything not listed is an anti-recommendation, privacy is so dependent on your particular threat model that different tools are going to be best for different people. There’s so many great products out there, just because it’s not listed on PG doesn’t make it bad. I guess I always saw the recs on PG as more “highlights”, like here’s some criteria and the best tools that meet that criteria, why we set that criteria, etc so that the reader can see the process involved in picking out software that they want to use and be able to decide their own criteria that they want to go on. I don’t think anyone should view the recs on PG as gospel especially when the definition of what’s private varies so much from person to person.

---

## Post 161 by @moonwriting — 2024-11-24T13:14:47Z

Requiring open source software in the password manager section makes sense, considering how sensitive data these services are storing. I also think that Privacy Guides should attempt to encourage companies to offer open source solutions instead of signaling that closed source is just fine, which is what we are doing by continuing to recommend 1Password and Strongbox. So yes, if we would require this, we would have to delist 1Password, but we would also need to remove Strongbox, which I think is quite overdue and we haven’t been able to remove it otherwise. But I think this change has more to do with improving the section criteria instead of being a quest to remove any of the current recommendations.

The current open source options for the password manager category are already more than good enough for a majority of people and having some niche features such as SSH keys isn’t enough to justify the 1Password recommendation. I would argue that people who need this are capable of finding another solution that offers it. One reason for listing 1Password was also its superior UI and UX, especially when compared to Bitwarden, but at the moment, I would argue that Proton Pass has the more straightforward and easier to use UI/UX and Bitwarden is currently improving this as well.

And if we change the site criteria as follows, I doubt people would become concerned or confused about this because they could see in the requirements that Privacy Guides now only accepts open source software for this category, so 1Password wouldn’t just disappear from the site without a clear explanation that anyone can find.

---

## Post 162 by @anon80779245 — 2024-11-24T14:00:43Z

> [@anon80779245](#):
>
> Let’s do a Poll to help us decide. All votes are PUBLIC to prevent people from faking it with burner accounts.
> 
> - Votes
> 
> - 42% Keep the status-quo (proprietary allowed)
> 
> - 28% Require source-first as a minimum
> 
> - 14% Other
> 
> - 14% Require open-source

[@team](/groups/team) would it be possible to pin the Poll so more people weigh-in?

---

## Post 163 by @fria — 2024-11-24T14:12:46Z

We don’t make decisions based on polls they’re just for fun.

---

## Post 164 by @ph00lt0 — 2024-11-24T15:04:23Z

Idk I thi k they are a good way to help us decide after all we run based on the community.

Anyway we cannot pin a poll afaik.

---

## Post 165 by @anon73250778 — 2024-11-24T16:02:57Z

Guys seriously wrap this up. Normies that seek our guidance don’t really care about the nitty gritty of licensing: they just want a good enough solution that is preferably not a paid product.

If we cannot settle on a technical merit of the recommendation, maybe we can look at this in another way?

What does a “first, do no harm” solution look like?

---

## Post 167 by @anon29374801 — 2024-11-24T16:09:20Z

> [@Anon47486929](#):
>
> It does capture the point well. All this in consideration, would you allow Nordpass as a recommendation?

This such a tired argument that is reused all the time. PG does not allow tools just because they meet the min requirement. The tool would never pass community scrutiny, something i think you know.

> [@jonah](#):
>
> Basically, the way I think about it is:
> 
> - When we **add** new tools, we need a strong justification on why they are substantially **better** than the alternatives.
> - When we **remove** existing tools, we need a strong justification on why they are substantially **worse** than the alternatives.
> 
> I don’t think this second justification is met simply based on open source alone.

This. Nobody has gotten close to coming up with a reason why open source meets that justification. Nobody has come close to justifying why open source should be a criteria. Honestly a majority of comments should probably just be moved to the 1password thread.

At this point we seem to be spinning our wheels.

---

## Post 169 by @anon29374801 — 2024-11-24T16:15:06Z

Not sure how a direct quote can be a misquote. Nothing about the context you provided changes that other then the logic you don’t seem to understand is that criteria is not the only barrier to being recommend.

---

## Post 171 by @anon29374801 — 2024-11-24T16:23:24Z

So i was right.

Nord would never get recommended because it would not pass community scrutiny. This would not require a criteria change to prevent.

This seems to be what you misunderstood.

Hopefully we are both more clear on the issue. Thanks!

EDIT: always nice when the example were arguing over [happens](https://discuss.privacyguides.net/t/nordpass-password-managers/22705) and I am again proven right.

---

## Post 173 by @win11.shading291 — 2024-11-24T21:12:27Z

I agree 100% with @Anon47486929.

If we put a point system (I put score on my personal beliefs, but it could be different)

[General criteria page](https://www.privacyguides.org/en/about/criteria/):

- **Security** +2
- **Source Availability** : +2
- **Cross-Platform Availability** : +1
- **Active Development** : +4 (this should even be a minimum requirement IMO)
- **Usability** : +2
- **Documentation** : +1

[Password manager minimum criteria](https://www.privacyguides.org/en/passwords/#criteria) (no points here, since its a minimum to enter the category):

- Must utilize strong, standards-based/modern E2EE.
- Must have thoroughly documented encryption and security practices.
- Must have a published audit from a reputable, independent third party.
- All non-essential telemetry must be optional.
- Must not collect more PII than is necessary for billing purposes.

Best-Case criteria:

- **Telemetry** should be opt-in or not collected at all: +2
- Should be **open source** and reasonably self-hostable: +2

Some people argued that open-source should not solely be the criteria into determining if a an option is recommended or not. I believe nobody’s saying that. Open-source, though is clearly a plus for the only reason that it brings _ **trust** _ to that option. It is clearly a plus, but not the only criteria.

Based on that logic, if there are already 3-4 password managers that are on par with 1password feature wise, audit, wise, usability wise, security wise, etc. BUT onepassword is the only one not open-source, then IMO it should be removed.

I’m not arguing this is the case though.

Edit: I’m not suggesting a point system be in place. This was just for the sake of demonstration.

---

## Post 174 by @jonah — 2024-11-24T21:17:07Z

> [@Anon47486929](#):
>
> The criteria will remain unchanged unless a tool you don’t wish to approve reaches it

I guess the answer is yes. The criteria would remain unchanged unless one of the following is true:

1. The community wants to add something that is clearly so much worse than our recommendations (like Nordpass) that increasing the criteria is necessary to avoid confusion about why Nordpass isn’t recommended.
2. One of the recommendations falls so far behind the others that it no longer makes sense to list.
3. The community wants to add something that is so much radically better than our existing recommendations that it necessitates delisting the existing tools.

None of these 3 three things really apply.

And again, the argument that you and @fria are making is that situation #2 _does_ apply, and I’m countering this argument by saying that source code licensing doesn’t create enough of a quality “delta” between 1Password and the others to say that “it has fallen behind.”

Is this an accurate assessment of where we’re at?

---

## Post 176 by @anon80779245 — 2024-11-26T18:55:16Z

I encourage everybody that hasn’t done it yet to VOTE [here](https://discuss.privacyguides.net/t/require-open-source-for-password-managers/12480/127) on whether to require Source-First, Open-Source or keep allowing proprietary password manager.

So far, it’s a **tie between source-first/open-source and proprietary**

---

## Post 177 by @anon48875053 — 2024-11-26T19:02:16Z

> [@anon80779245](#):
>
> So far, it’s a **tie between source-first/open-source and proprietary**

It’s sad to see that it’s a tie between freedom and proprietary.

One thing to note is that this proposal has 28 votes, the proposal with the highest votes ever has 30 votes.

---

## Post 178 by @asanyan — 2024-11-26T19:42:45Z

> [@jonah](#):
>
> As far as I see it, the only reason we would want to add this criteria is if we collectively believe that software being open source is a **requirement** for privacy/security. I believe this is a minority viewpoint, and it’s a point that we have explicitly tried to [downplay](https://www.privacyguides.org/en/basics/common-misconceptions/#open-source-software-is-always-secure-or-proprietary-software-is-more-secure) in our content, as we prefer to evaluate products based on our current best judgement of how they are _as-is_.

Then why do you have this criteria in other categories at all? Password management is as mission critical as it possibly gets and therefore it should have the strictest criteria, _specially_ when it comes to anything “cloud-based” and/or that has to connect to the internet.

> [@jonah](#):
>
> However, is there a substantial reason to remove 1Password from the list today given that it is already on there? No, I don’t think this is the case either.

If that’s the concern, then how about still mentioning it, but separating it from the other recommendations like what you do with e-mail providers? I understand the reason for Tuta being the “3rd option” is different, but I believe such a division would be warranted if you believe that FOSS is an improvement.

---

## Post 179 by @phnx — 2024-11-26T19:50:51Z

> [@asanyan](#):
>
> Then why do you have this criteria in other categories at all? Password management is as mission critical as it possibly gets and therefore it should have the strictest criteria, _specially_ when it comes to anything “cloud-based” and/or that has to connect to the internet.

This is what I think a lot of users find strange. Obsidian could in many ways be considered the ‘1Password’ of digital notebooks, yet it is not recommended due to being closed-source despite being able to be used fully offline (with lower stakes in general), unlike 1Password.

---

## Post 180 by @anon80779245 — 2024-11-29T12:03:06Z

> [@anon80779245](#):
>
> Let’s do a Poll to help us decide. All votes are PUBLIC to prevent people from faking it with burner accounts.
> 
> - Votes
> 
> - 13 votes Keep the status-quo (proprietary allowed)
> 
> - 9 votes Require source-first as a minimum
> 
> - 5 votes Require open-source
> 
> - 3 votes Other
> 
> 30 voters
> 
> 30 total votes

With 14 votes against 13 votes, the Privacy Guides community slightly favor open-source/source-first.

I am wondering why the 3 who voted Others choose this?

---

## Post 181 by @anon55464882 — 2024-11-29T12:56:23Z

> [@anon80779245](#):
>
> I am wondering why the 3 who voted Others choose this?

In my opinion “source available” should be the minimum criterion, so I voted for “Other.”

---

## Post 182 by @anon48875053 — 2024-11-29T15:03:17Z

Am I the only one who sees an obvious issue with other voters knowing what the entire PG team voted for? It might just be me.

Another issue is that some voters love 1Password’s UI and UX and are clearly biased against requiring open-source because their favorite password manager will get removed, but I disgress.

---

## Post 183 by @anon80779245 — 2024-11-30T09:03:02Z

> [@anon55464882](#):
>
> In my opinion “source available” should be the minimum criterion, so I voted for “Other.”

I am unaware of source-available password manager. I think this is unlikely. Source-available will be something you can’t even build yourself (I think?).

So if you are OK with it, please vote for source-first :wink:.

> [@anon48875053](#):
>
> Another issue is that some voters love 1Password’s UI and UX and are clearly biased against requiring open-source because their favorite password manager will get removed, but I disgress.

As Proton Pass catches up with 1 Password, things might change, so that’s a silver of hope.

I am a bit sad PG is ok with proprietaryware.

---

## Post 184 by @anon55464882 — 2024-11-30T09:23:30Z

> [@anon80779245](#):
>
> I am unaware of source-available password manager. I think this is unlikely. Source-available will be something you can’t even build yourself (I think?).

Just because something doesn’t exist now doesn’t mean it won’t in the future. I find minimal privacy advantages in source-first or open-source compared to source-available, other than the increased chance that more people have reviewed the code. That is my personal opinion.

> [@anon80779245](#):
>
> So if you are OK with it, please vote for source-first :wink:.

Ultimately, my vote supports changing the current criteria, but I have a different opinion on how extensive those changes should be.

Regardless, I don’t believe this poll will have a major impact on the outcome of our discussion, even though I had hoped it would. The staff seems stuck in their decision, despite what most of their community is expressing.

---

## Post 185 by @win11.shading291 — 2024-12-03T05:23:00Z

> [@anon80779245](#):
>
> I am wondering why the 3 who voted Others choose this?

On my end, I voted for “other” because the criteria should change with time, as discussed in this thread.

For instance, if at one time, there are only 2 open source softwares in that category, it doesn’t make sense to require open-source in the criteria.

So my “other” vote = change depending on the maturity of the category.

---

## Post 187 by @jonah — 2024-12-03T08:36:58Z

> [@Anon47486929](#):
>
> Clearly shows the community consensus

Privacy Guides gets like 8,000 unique visitors every day, and this forum has over 3,000 members. One poll which has 34 votes and is split between 41% / 49% is unfortunately not the _clear consensus_ you are imagining. On the contrary it proves that we can’t proceed too quickly here.

If only it were that easy! :slight_smile:

[Much like Wikipedia](https://en.wikipedia.org/wiki/Wikipedia:What_Wikipedia_is_not#Wikipedia_is_not_a_democracy), Privacy Guides is not a democracy, rather we make our decisions based on **discussion** and consensus. A poll is not a discussion, and this one frankly has hindered this discussion a bit as we are now all talking about the poll itself rather than the merits and drawbacks of this proposal. The polarization here as a result of the poll has really only _slowed down_ the possibility of us making this change.

Do not worry, because we are considering the opinions shared here in this thread, in that poll, and across the wider community as we carefully chart out the best course of action here :slight_smile:

---

## Post 189 by @anon48875053 — 2024-12-03T08:59:38Z

> [@jonah](#):
>
> Privacy Guides gets like 8,000 unique visitors every day

How is that calculated when there are things like Tor, VPNs, shared IPs, fingerprint resistant browsers, etc?

---

## Post 190 by @anon48875053 — 2024-12-03T09:02:49Z

> [@Anon47486929](#):
>
> Also there are 31 votes for the topic :eyes:

It’s the record breaking number for PG. No other topic ever had this much votes.

---

## Post 191 by @jonah — 2024-12-03T09:08:25Z

> [@Anon47486929](#):
>
> I was merely pointing out the consensus is not so clear as your previous statement led me to believe.

My previous statement was saying that not requiring open-source in this category was the _previous_ consensus, which is just an objective fact that it was. Now we are seeking a _new_ consensus, which is fine, but it will take as long as it takes.

It is much preferable for us all to accept that it is not the end of the world for us to leave a less-than-perfect criteria on the website — _with the understanding that Privacy Guides is always gradually improving and changes are being discussed and considered_ — than to try and fight for and push forward some immediate change for a particular preferred version of the criteria ASAP.

This is probably an off-topic discussion we could take elsewhere, but I _do_ see PG’s “governance and consensus structure” as similar to Wikipedia personally, and at least that seems to be the direction things have been heading.

> [@anon48875053](#):
>
> How is that calculated when there are things like Tor, VPNs, shared IPs, fingerprint resistant browsers, etc?

This is also off-topic, but yes I would take our statistics with a big grain of salt. People sharing IPs or using Tor might appear as the same person to our (primitive) stats lowering the count, and on the other hand people switching IPs/circuits frequently may appear as multiple visitors increasing the count. So I think it is probably a wash basically, but who knows for sure.

Our _pageviews_ are probably the most accurate statistic we have, which hovers around 35-40K/day.

---

## Post 192 by @anon80779245 — 2024-12-03T10:03:49Z

> [@jonah](#):
>
> Privacy Guides gets like 8,000 unique visitors every day, and this forum has over 3,000 members. One poll which has 34 votes and is split between 41% / 49% is unfortunately not the _clear consensus_ you are imagining. On the contrary it proves that we can’t proceed too quickly here.

Sorry, but that doesn’t make any sense. The ratio between votes and total visitors here is irrelevant. There is always only a minority which actively participate, on any subject - so following your argument we couldn’t take any decision cause too few people participated in it.

> [@jonah](#):
>
> [Much like Wikipedia](https://en.wikipedia.org/wiki/Wikipedia:What_Wikipedia_is_not#Wikipedia_is_not_a_democracy), Privacy Guides is not a democracy, rather we make our decisions based on **discussion** and consensus.

Sorry, but **PG often doesn’t make decisions based on consensus. When you or the team wanted something -** like including Mull- **you do it**  **despite** huge **backlash**.

Plus, achieving consensus would require more tools, and a forum thread is not the best way to do this.

---

## Post 193 by @anon80779245 — 2024-12-03T10:15:03Z

I made a new thread for [How should Privacy Guides take decision?](https://discuss.privacyguides.net/t/how-should-privacy-guides-take-decision/22892)

Some recent comments about that could be moved there.

Also, I closed the poll. I think I agree with Jonah, that while it shows a small majority supporting open, we might need to wait for a stronger consensus - even as I personally support requiring open-source, and believes there is a double-standard going on (see [Mull (Android Browser) + Criteria Change](https://discuss.privacyguides.net/t/mull-android-browser-criteria-change/14460)) where team members and esp.

---

## Post 195 by @Bhaelros — 2024-12-21T00:20:03Z

What is your deal with the 1Password? I am not paid by 1Password but I strongly defend them, even though I find their support and social media practices bad.

They are frequently audited, more frequently than any other password managers in the market, and that is not good enough for you?

I suggest you to write your own password manager, make it FOSS, and let’s see what happens.

You are speaking like FOSS is the next big thing, no, it is not. We, or I, regular people trust the audit companies, bug bounties and how companies react to the findings, becase I don’t know how to code and how to properly check a code for a vulnerability or enhance it, like the majority of the world population.

---

## Post 196 by @anon48875053 — 2024-12-21T08:10:13Z

> [@Bhaelros](#):
>
> I am not paid by 1Password but I strongly defend them, even though I find their support and social media practices bad.

You don’t need to be paid by 1Password, just the fact that you’re using it is enough.

> [@Bhaelros](#):
>
> They are frequently audited, more frequently than any other password managers in the market, and that is not good enough for you?

So what? How does that matter? 1Password has one annual pentest per year, which is next to useless.

1. Who knows if the auditing company is competent enough?
2. Who knows if the exact people from that company that did pentesting are competent enough?
3. Even if the auditing company and the people who did the audit were competent, they’re unfamiliar with the code because they aren’t the ones working on it.
4. Even if the audit was done perfectly and flawlessly in every way, 1Password is only doing audits annually, and the vulnerability can be introduced in the next update right after the audit.

There is literally a year gap in which the 1Password developers, maliciously or not, could introduce a vulnerability, and if it was in fact malicious, get rid of it before the next audit.

* * *

You’re just a user of 1Password who likes how it looks and feels and who is completely used to it, that’s why you defend it so much, but Privacy Guides isn’t about “looks” and “feels,” at least I hope so.

* * *

> [@Bhaelros](#):
>
> We, or I, regular people trust the audit companies

Good, I will make a password manager, get it audited to get the trust of regular people, and then introduce 10 backdoors until the next annual audit.

---

## Post 197 by @fria — 2024-12-21T15:12:50Z

> [@anon48875053](#):
>
> There is literally a year gap in which the 1Password developers, maliciously or not, could introduce a vulnerability, and if it was in fact malicious, get rid of it before the next audit.

The audit doesn’t defend against malicious developers it’s instead about making sure they’ve done things competently. You’re right if they were malicious they could easily remove the malicious parts for an audit and then continue in their way.

---

## Post 198 by @anon48875053 — 2024-12-21T15:31:18Z

> [@fria](#):
>
> The audit doesn’t defend against malicious developers it’s instead about making sure they’ve done things competently.

Yes, but things could be done incompetently just after the audit even without being malicious and it would stay that way for a year.

---

## Post 199 by @Niek-de-Wilde — 2024-12-21T15:58:19Z

And thats why you do repeated audits, if they have done things competently for multiple years , then its safe to say that the dev team has gained enough trust to maintain their software over thr long term.

---

## Post 200 by @anon48875053 — 2024-12-21T15:59:51Z

Trust as a concept should be abondened when it comes to security and privacy. Technical solutions are what people need.

If Proton would get rid of encryption, I would move on to another mail provider no matter how much I trust Proton, etc.

---

## Post 201 by @Niek-de-Wilde — 2024-12-21T16:01:06Z

ALL tech is bound by trust, you trust your cpu is not backdoored for example, as there is no way to verify it.

---

## Post 202 by @anon48875053 — 2024-12-21T16:03:13Z

This is not a good comparison. If there was a backdoor in Intel or AMD CPUs, then military, hospitals, goverment, banks and everything else would also have that backdoor and both Intel or AMD wouldn’t allow that to happen, it’s just not a realistic threat.

Also, what choice do we have? We have no choice. Meanwhile with 1Password we can choose to replace it with KeePass, Bitwarden, Proton Pass, etc.

---

## Post 203 by @anon48875053 — 2024-12-21T16:09:55Z

Using 1Password over KeePass, Bitwarden or Proton Pass is like granting root access to all of the apps on your phone just because you trust the developers, it doesn’t make sense, trust should be minimized as much as possible.

---

## Post 204 by @fria — 2024-12-21T16:46:43Z

Yeah I think open source code with reproducible builds is a big step in being able to verify that the developer is not malicious.

---

## Post 205 by @overdrawn98901 — 2024-12-21T17:20:39Z

Trust is part of a threat model. The degree of trust people are willing to give is variable. A slippery slope of zero trust is becoming a hermit in the woods, and while I don’t think you mean that, I’d say that trust is flexible depending on the person.

---

## Post 206 by @anon48875053 — 2024-12-21T17:27:12Z

Fine, everyone can trust and use whatever they want, but 1Password doesn’t belong on PG recommendations or we could also then recommend Gmail and OutLook for business because they pinky promise to not read or scan your emails in the privacy policy. One could trust Gmail and be fine with it, doesn’t mean it should be recommended.

---

## Post 207 by @lint — 2024-12-21T17:36:36Z

Alright. I’m going to stir the pot a bit as I’ve been lurking for a while. I would like to propose that a minimum requirement for a password manager be that they have an active bug bounty program. This can help cover bugs or vulnerabilities discovered during between audits.

I’m of the opinion that closed source can be ok as long as they have a history of audits and have a bug bounty (especially if they post at least minimal details of the bounty history like 1Password does).

---

## Post 208 by @anon48875053 — 2024-12-21T17:39:38Z

1. There are bug bounties for tons of software that are a lot bigger than what 1Password offers.
2. A bug hunter could sell that vulnerability for more to the bad/dark side.
3. They could also use that bug themselves.

A password manager would have to pay HUGE bug bounties, and bug hunters would have to be nice enough to disclose it to 1Password.

---

## Post 209 by @phnx — 2024-12-21T17:43:06Z

1Password may remain a sensible option for people who already use it, but I agree with the sentiment that continuing to recommend it will ultimately cause more harm in the future. For users looking for a new password manager, there is no legitimate reason to choose 1Password over options like Bitwarden and Proton Pass, and Privacy Guides’ recommendations should reflect that.

---

## Post 210 by @overdrawn98901 — 2024-12-21T18:21:55Z

My “trust” with 1Password is that the business model of password managers usually goes against leaking customer data. Gmail provides enough utility people look past the rest of the issues. Security exploits and leaks would greatly harm the reputation of 1Password. It is in their interest to not allow that to happen. This isn’t a strong degree of trust, but we also have the history of the application to keep in mind as well.

In general, I am for removing non-FOSS password managers. The devils advocate is that I don’t think we should remove it because 1Password it is bad necessarily, but rather there are simply better FOSS alternatives with good enough UX and features at this point of time. Removing 1Password as recommended is really a celebration that FOSS alternatives can compete with a proprietary one.

---

## Post 211 by @anon48875053 — 2024-12-21T18:26:11Z

> [@overdrawn98901](#):
>
> Security exploits and leaks would greatly harm the reputation of 1Password.

No, all software has exploits and vulnerabilities. It doesn’t make sense to discard the company just because of it, so their reputation would be fine.

> [@overdrawn98901](#):
>
> It is in their interest to not allow that to happen.

They can’t do anything about this, there is no such thing as flawless code and 100% secure software.

---

## Post 212 by @anon29374801 — 2024-12-21T18:31:46Z

A reminder that there is already a discussion for 1Password.

> [@Remove 1Password](https://discuss.privacyguides.net/t/remove-1password/13921):
>
> 1Password embeds tracking pixels in its newsletters. You can subscribe to their newsletter through their website. The tracking pixel should be included in your subscription confirmation email.

This topic should of been closed a while ago but, if staff is going to keep it open, at least stay on topic. :slight_smile:

---

## Post 213 by @overdrawn98901 — 2024-12-21T18:45:25Z

To stay on topic the best I can, all of the issues you talk about also persist with FOSS software. Just because someone can view it, doesn’t mean it actually has been audited for issues. An audit will help identify issues in the current version, but new updates will need to be audited again. FOSS is not exempt from any issues or bugs that proprietary software has. More observability, but the bugs will persist.

The only time FOSS has any legal benefits to an end user is if it’s GPL based for client side software, and AGPL based for web applications. Everything else can be tampered with and given to you, though separate FOSS builds could be made (VSCode vs VSCodium). Even then, the only sure way to be the safest is self compilation. For those willing to do so, great, but the average user will not do that.

---

## Post 214 by @phnx — 2024-12-21T19:11:43Z

> [@anon29374801](#):
>
> This topic should of been closed a while ago but, if staff is going to keep it open, at least stay on topic. :slight_smile:

The fact is that 1Password is the password manager at issue when it comes to whether open source should be required for password managers. (Yes, Strongbox is also proprietary, but it’s far less popular, especially among novice users, so removing it doesn’t have the same implication(s).)

I am trying to make the argument that although there may be legitimate reasons for using closed-source options (i.e. 1Password) today, there is no reason to continue recommending closed-source options. Open-source significantly increases trust, especially within the context of a cloud-based password manager and when combined with reproducible builds and regular audits.

Continuing to recommend closed-source options when they are clearly inferior from a privacy, security, and increasingly a usability standpoint (email aliasing) makes little sense to me. I also think it makes the most sense to stop recommending closed-source options immediately so that new users stop adopting them, giving existing users plenty of time to migrate.

Also, the fact that Obsidian isn’t a recommended notebook:

> [@Require Open Source for Password Managers](https://discuss.privacyguides.net/t/require-open-source-for-password-managers/12480/179):
>
> This is what I think a lot of users find strange. Obsidian could in many ways be considered the ‘1Password’ of digital notebooks, yet it is not recommended due to being closed-source despite being able to be used fully offline (with lower stakes in general), unlike 1Password.

---

## Post 215 by @anon29374801 — 2024-12-21T21:02:16Z

> [@phnx](#):
>
> The fact is that 1Password is the password manager at issue when it comes to whether open source should be required for password managers

Which has been discussed ad nauseum in like 3 different topics. I thought when @anon48875053 failed meme protest [tool suggestion of NordPass](https://discuss.privacyguides.net/t/nordpass-password-managers/22705) died immediately we would get a break from this.

@jonah already provided a very clear guideline on what would need to occur for the criteria to change, so i just dont see the point in rehashing these same tired arguments.

> [@Require Open Source for Password Managers](https://discuss.privacyguides.net/t/require-open-source-for-password-managers/12480/174):
>
> I guess the answer is yes. The criteria would remain unchanged unless one of the following is true: The community wants to add something that is clearly so much worse than our recommendations (like Nordpass) that increasing the criteria is necessary to avoid confusion about why Nordpass isn’t recommended. One of the recommendations falls so far behind the others that it no longer makes sense to list. The community wants to add something that is so much radically better than our existing recom…

---

## Post 216 by @anon48875053 — 2024-12-21T21:07:26Z

> [@anon29374801](#):
>
> @jonah already provided a very clear guideline on what would need to occur for the criteria to change, so i just dont see the point in rehashing these same tired arguments.

Jonah isn’t the only team member.

---

## Post 217 by @anon29374801 — 2024-12-21T21:08:49Z

Ok. Just ignore his comments. See if that works.

---

## Post 220 by @IksNorTen — 2024-12-22T08:35:25Z

Yes, let’s hope the team gets the point someday.

1Password should no longer be recommendable, and those who read this entire thread will be smart enough to understand it. Data as sensitive as passwords should not be managed in a proprietary way, whether there are regular audits or not.

Being open-source isn’t magic, but it does add that additionnal and **minimal layer of security and trust you absolutely need** to have fewer doubts when adding highly confidential data to the software.

1Password doesn’t have this minimal security layer, whether you like it or not. It’s factual, not an opinion.

---

## Post 221 by @IksNorTen — 2024-12-22T08:36:46Z

If there weren’t already a good number of reliable and secure password managers (KeePassXC/DX, Bitwarden…), it would be understandable to recommend 1Password (because in that case, it would be the least worst of all).

But this is not the case.

---

## Post 222 by @Niek-de-Wilde — 2024-12-22T09:23:29Z

We get your point, we just currently disagree. :slight_smile:

---

## Post 223 by @anon48875053 — 2024-12-22T10:40:02Z

Then the open source requirement should be removed from all the other categories.

PG either only cares about privacy and the minimal amount of security to enforce privacy. In which case the open source requirement should just be removed from all the categories.

Or PG also cares about freedom, digital rights, etc., in which case open source should be required everywhere where it makes sense and isn’t harming the security, privacy, or the available options to zero or just one.

The reason why criteria exist is to make the recommendations as objective as possible and somewhat protect against bias, conflict of interest, etc. But the way it is right now is this: yeah, we like 1Password, so no open source criteria for password managers, but we don’t like Obsidian enough, so notebooks are required to be open source. Even though Obsidian is quite a lot better than the alternatives than 1Password is against its alternatives, and Obsidian manages a lot less sensitive data. Do I think this is objective? Not at all.

---

## Post 224 by @overdrawn98901 — 2024-12-22T14:19:28Z

> [@anon48875053](#):
>
> Then the open source requirement should be removed from all the other categories.
> 
> PG either only cares about privacy and the minimal amount of security to enforce privacy. In which case the open source requirement should just be removed from all the categories.
> 
> Or PG also cares about freedom, digital rights, etc., in which case open source should be required everywhere where it makes sense and isn’t harming the security, privacy, or the available options to zero or just one.

Bit of a black and white take. I don’t think everything needs to be binary, and the recommendations certainly aren’t binary. I think it should boil down to “are there FOSS solutions that offer a seriously good enough UX experience or a legit variable alternative”.

If PG is strict FOSS, there are not e-mail vendors to be recommended. We must all resort to using PGP handwritten or printed letters to one another haha.

FOSS isn’t a hard requirement if E2EE is supported. If it isn’t supported, then FOSS is more heavily looked at.

---

## Post 225 by @anon48875053 — 2025-07-03T13:00:15Z

> **[Store passports, WiFi codes, SSH keys and more in Proton Pass | Proton](https://proton.me/blog/password-manager-custom-item-management)**
>
> Organize your life better with support for more items in Proton Pass, storing all of your essential day-to-day data in a custom format that works for you.

Time to raise standards and require FOSS for password managers?

---

## Post 226 by @anonymous363 — 2025-07-03T14:18:56Z

no.

> [@jonah](#):
>
> The criteria would remain unchanged unless one of the following is true:
> 
> 1. The community wants to add something that is clearly so much worse than our recommendations (like Nordpass) that increasing the criteria is necessary to avoid confusion about why Nordpass isn’t recommended.
> 2. One of the recommendations falls so far behind the others that it no longer makes sense to list.
> 3. The community wants to add something that is so much radically better than our existing recommendations that it necessitates delisting the existing tools.
> 
> None of these 3 three things really apply.

That does not meet the criteria @jonah put out for a change to occur.

---

## Post 227 by @moonwriting — 2025-07-03T14:48:31Z

While this is a great addition to Proton Pass, it is unfortunately pretty half-baked at this time, so just because Proton has implemented it doesn’t mean that the implementation is as good as with 1Password. Yet, I still support making this category open source. Here are some feedback that people have had on this feature:

> **[Reddit - The heart of the internet](https://www.reddit.com/r/ProtonPass/comments/1lmu1hh/why_dont_we_get_these_lovely_colours_and_icons_to/)**

> **[Reddit - The heart of the internet](https://www.reddit.com/r/ProtonPass/comments/1llvti8/entry_duplication_for_custom_item_types/)**

> **[Reddit - The heart of the internet](https://www.reddit.com/r/ProtonPass/comments/1lo2zeu/custom_items_suggestions/)**

---

## Post 228 by @jonah — 2025-07-29T06:39:48Z

> [@IksNorTen](#):
>
> Yes, let’s hope the team gets the point someday.

Personally, I would not really be opposed to making this change at this point, but this is not really a decisive discussion, so I don’t want to mark this as #approved. Yes there are quite a lot of votes on this issue, but for every person in favor of making this change, I’ve seen another person against it. And I think both sides have merit here.

When topics are so split like this the best path forward is usually to maintain the status quo, which means still not changing this criteria for now.

I’m mainly saying this to make sure nobody is against this change _solely_ because I was, and to encourage the rest of the [@team](/groups/team) to speak up if they are getting a different feeling about the community consensus on this than I am.

---

## Post 229 by @Bhaelros — 2025-07-29T07:17:30Z

While FOSS is good for security and privacy, that would also mean removing 1Password from PG. which I am against. Just because they are not FOSS, doesn’t mean they are insecure. If people want FOSS, then let’s ask for backends to be open source too, that will eliminate Proton and many others.

Call me a fan but no other password manager can replace 1Password at the moment, and considering the development rate, listening to customer feedback and taking action for them, I don’t think neither Bitwarden, nor Proton Pass can catch 1Password in the foreseeable future.

I mentioned many times before, I am not a programmer, so being open source has no meaning to me, but I understand there are people who can inspect the code, but unless you can compile both frontend and backend, just checking the code and creating bug reports, issues or feedback on Github won’t do much, right? It all depends on developer, to process these Github requests or not. I am trusting audit reports, and the actions taken to those reports. 1Password has the most audits so far, and they have bug bounties in addition to that.

---

## Post 230 by @anonymous378 — 2025-07-29T12:29:27Z

I just don’t like creating unnecessary restrictions that reduce choice without providing a clear benefit. At this moment, the criteria change would create an event where privacy guides would be removing a good privacy tool for a non privacy ideological reason. Which just seems out of scope.

I don’t see any reason for @jonah to waffle on what would cause the criteria to change, when no significant developments have happened.

> [@Require Open Source for Password Managers](https://discuss.privacyguides.net/t/require-open-source-for-password-managers/12480/174):
>
> I guess the answer is yes. The criteria would remain unchanged unless one of the following is true: The community wants to add something that is clearly so much worse than our recommendations (like Nordpass) that increasing the criteria is necessary to avoid confusion about why Nordpass isn’t recommended. One of the recommendations falls so far behind the others that it no longer makes sense to list. The community wants to add something that is so much radically better than our existing recom…

---

## Post 231 by @jonah — 2025-07-29T15:59:31Z

I just want to stress that ultimately you all are responsible for making this change, there’s nobody at the team holding this back behind the scenes, outside of their personal opinions which really have the same weight as anyone else.

This thread comes up a lot like “requiring open source for password managers has so many votes, it’s ridiculous that Privacy Guides hasn’t made this obvious change yet!”

> [@jonah](#):
>
> Yes there are quite a lot of votes on this issue, but for every person in favor of making this change, I’ve seen another person against it. And I think both sides have merit here.
> 
> When topics are so split like this the best path forward is usually to maintain the status quo, which means still not changing this criteria for now.

* * *

> [@anonymous378](#):
>
> for a non privacy ideological reason.

Open source, and freedom in general, are certainly factors when it comes to privacy, so this is wrong. However, it **is** just one factor of many, and clearly many people here don’t believe it should be the most important one, which is again exactly why we haven’t pushed this change through :slight_smile:

---

## Post 232 by @anonymous378 — 2025-07-29T16:09:43Z

> [@jonah](#):
>
> Open source, and freedom in general, are certainly factors when it comes to privacy, so this is wrong

While I agree those factors are important _in general_, it seems a bit disingenuous to say that in this context when there is a clear example of a non FOSS option being perfectly valid. It also seems to devalue user choice and tool effectiveness.

---

## Post 233 by @anon11657877 — 2025-07-29T17:28:05Z

> [@jonah](#):
>
> Open source, and freedom in general, are certainly factors when it comes to privacy, so this is wrong. However, it **is** just one factor of many, and clearly many people here don’t believe it should be the most important one

It should be, or at least one of the most important factors.

If I had my way, no cloud password managers would be recommended, or the local password managers would be prioritized over cloud solutions. I don’t trust the cloud in general, and I don’t think it’s a good idea to store all of your passwords in the cloud even encrypted, because you’re essentially trusting someone else with your passwords. Of course everyone’s passwords are stored on the internet on the sites they have accounts on, but we don’t need to create another point of attack.

But with closed source cloud based managers like 1Password, you never really know what’s going on. Everyone knows closed source code is much harder to audit than open source, less transparent, reduced trust in the developer. For something as sensitive as passwords, closed source services shouldn’t be trusted.

---

## Post 234 by @anon11657877 — 2025-07-29T17:30:49Z

> [@Bhaelros](#):
>
> I am not a programmer, so being open source has no meaning to me

Open source is about more than auditing code and anyone can benefit from other developer’s ability to read, audit, and modify the source. Without open source we wouldn’t have good forks of bad software like LibreWolf (Firefox) and Tenacity (Audacity). It ensures software can outlive it’s original authors and prevents vendor lock-in. You don’t have to be a programmer to support open source.

---

## Post 235 by @Bhaelros — 2025-07-29T18:08:40Z

But what is the point of forking if you can’t access backend or even change the actual frontend code? I am talking about current recommended password managers.

It is not about supporting it. I am not against open-source software, don’t get me wrong. I am only against the people who are doing witch hunt against closed-source apps just because it is not open-source.

Some people are treating 1Password like it is their lifelong nemesis. I just couldn’t understand that.

---

## Post 236 by @overdrawn98901 — 2025-07-29T18:29:06Z

> [@anon11657877](#):
>
> If I had my way, no cloud password managers would be recommended, or the local password managers would be prioritized over cloud solutions.

Threat models, threat models, threat models… i was using the same password variations across all sites before a password manager, significantly increasing my risk of attack in my opinion.

Lastly, the value proposition of password managers is intense security. Password managers not encrypting their data reduces their value a lot. It makes (reputable) password managers one of the easiest closed source applications to trust for this reason, ironically. Failing to be secure means people will abandon the platform, or significantly deter new users from joining.

> [@anon11657877](#):
>
> But with closed source cloud based managers like 1Password, you never really know what’s going on

Wireshark and monitoring IO calls from 1pass will let you know pretty quickly if it’s sending plaintext.

---

## Post 237 by @anonymous378 — 2025-07-29T18:31:06Z

> [@Bhaelros](#):
>
> Some people are treating 1Password like it is their lifelong nemesis. I just couldn’t understand that.

It does seem like ever since @fria resurrected the [Remove 1Password - #39 by fria](https://discuss.privacyguides.net/t/remove-1password/13921/39) thread the kabal of anti-1password users has become the majority of support for this criteria change. Which is fine, there is no requirement to support in good faith, just odd.

---

## Post 238 by @overdrawn98901 — 2025-07-29T18:32:29Z

I would be happy with a middle ground: new password managers to be recommended must be FOSS. Existing ones will stay until a vulnerability kicks them out.

---

## Post 239 by @anon11657877 — 2025-07-29T21:28:28Z

> [@overdrawn98901](#):
>
> Lastly, the value proposition of password managers is intense security. Password managers not encrypting their data reduces their value a lot. It makes (reputable) password managers one of the easiest closed source applications to trust for this reason, ironically. Failing to be secure means people will abandon the platform, or significantly deter new users from joining.

I’ll believe this when LastPass goes out of business.

> [@overdrawn98901](#):
>
> Wireshark and monitoring IO calls from 1pass will let you know pretty quickly if it’s sending plaintext.

And how can I find backdoors and vulnerabilities? Wireshark isn’t enough.

---

## Post 240 by @anonymous372 — 2025-07-29T22:11:07Z

> [@anon11657877](#):
>
> And how can I find backdoors and vulnerabilities?

Third party audits, and 1Password has had many. Open source doesn’t mean everyone will try to look for a vulnerability, but paying experts to audit guarantees a skilled analysis.

---

## Post 241 by @anon11657877 — 2025-07-29T22:37:31Z

> [@anonymous372](#):
>
> Third party audits, and 1Password has had many.

So has NordVPN.

> [@anonymous372](#):
>
> Open source doesn’t mean everyone will try to look for a vulnerability

I never said it did but open source does make it a lot easier for the community to report and patch vulnerabilities. Audits are good for security but not a substitute for releasing the source code.

> **[The right thing for the wrong reasons: FLOSS doesn't imply security](https://seirdy.one/posts/2022/02/02/floss-security/#good-counter-arguments)**
>
> While source code is critical for user autonomy, it isn't required to evaluate software security or understand run-time behavior.

> Software as a Service can be incredibly difficult to analyze, as we typically have little more than the ability to query a server. Servers don’t send core dumps, server-side binaries, or trace logs for analysis. Furthermore, it’s difficult to verify which software a server is running. For services that require trusting a server, access to the server-side software is important from both a security and a user-freedom perspective

---

## Post 242 by @anonymous372 — 2025-07-30T00:28:59Z

> [@anon11657877](#):
>
> So has NordVPN.

Unlike Nord, 1Password hasn’t reacted badly to data breaches

---

## Post 243 by @anon11657877 — 2025-07-30T00:54:16Z

Also third-party audits won’t guarantee every backdoor or vulnerability is disclosed and only cover a small time period. The service could conceal backdoors or briefly change their logging policies. This is especially bad for Software as a Service. Data breaches or no, 1Password should be removed.

---

## Post 244 by @anonymous372 — 2025-07-30T01:25:46Z

This is from the article you linked:

> Releasing source code is just one thing vendors can do to improve audits; other options include releasing test builds with debug symbols/sanitizers, publishing docs describing their architecture, and/or just keeping software small and simple. We should evaluate software security through _study_ rather than source model.

1Password is documented really well, and it’s just as bloated as Proton Pass and Bitwarden

---

## Post 245 by @BiggishDoctor — 2025-07-30T02:47:22Z

An audit has a scope. If it’s outside of scope the auditor doesn’t have much say in the matter.

If I search for NordVPN audits, I find audits of the no-log policy and app security.

> Cure53’s assessment included penetration testing and a source code review of NordVPN’s desktop applications (Windows, macOS, and Linux), mobile apps (iOS and Android), browser extensions (Chrome, Edge, and Firefox), and features including [Threat Protection Pro](https://www.tomsguide.com/computing/vpns/what-is-nord-threat-protection-pro) and [Meshnet](https://www.tomsguide.com/features/nordvpn-meshnet-what-is-it-and-when-should-i-use-it).

If I search for the breach it says a malicious actor gained control of one of their third party servers. The security and access policies of it’s servers wouldn’t fall within the scope of either audit.

I wouldn’t recommend NordVPN. But, I would recommend it over a great many other VPN’s.

My main point here is that the scope of the audit and the actual stated results matter far more than whether an audit has taken place.

1Password could of course in theory build a very secure app, have it audited and then immediately afterwards add a function that forwards all user passwords to them in plaintext.  
But not much stops Proton Pass or Bitwarden from doing the same and just removing it again before they publish the source code.

---

## Post 246 by @jonah — 2025-07-30T03:20:41Z

> [@BiggishDoctor](#):
>
> 1Password could of course in theory build a very secure app, have it audited and then immediately afterwards add a function that forwards all user passwords to them in plaintext.

I’ve said it before and I’ll say it again: audits don’t measure trustworthiness, they measure **competency** :slight_smile:

You never know if a no-log audit means a VPN provider isn’t logging, but you _do_ know it means they didn’t accidentally forget to disable logging, which is still useful information to know about a company.

---

## Post 247 by @anon48875053 — 2025-07-30T04:15:13Z

All the truth about audits: [Frequently Asked Questions | GrapheneOS](https://grapheneos.org/faq#audit)

The most important part:

> The benefits of a group unfamiliar with the code spending a short time doing a shallow review are greatly overstated in marketing.

---

## Post 248 by @anonymous372 — 2025-07-30T05:38:22Z

1Password has been frequently audited by security firms such as Recurity Labs and Secfault security, so they do

> focus on having people very familiar with areas of the code regularly auditing

---

## Post 250 by @anon11657877 — 2025-07-30T14:41:41Z

[From KeePassXC FAQ](https://keepassxc.org/docs/#faq-audit)

> - An audit is not 100% proof that software is safe and secure. Some flaws can be overlooked even by the best auditors.
> - An audit is valid only for a “snapshot” of the code. If new code is added, new vulnerabilities can be introduced.

---

## Post 251 by @anonymous372 — 2025-07-30T16:53:00Z

KeePassXC only got audited once, so they’re worse off than 1Password

---

## Post 252 by @anon11657877 — 2025-07-30T17:10:46Z

No, because KeePassXC is offline software that doesn’t use the cloud so there’s no provider to trust and significantly less attack surface and even a rare case of security through obscurity actually working (because your passwords are only stored on your devices and not a centralized database which is a huge target for hackers and data breaches).

---

## Post 253 by @cgrams — 2025-07-30T17:17:48Z

This cannot be a serious argument? Audits do not prove anything, they are a checklist item to sell ideas of trust to people who want assurance of security more than they want security.

This sums up what audits are:

> **[Reviewing the Cryptography Used by Signal - Dhole Moments](https://soatok.blog/2025/02/18/reviewing-the-cryptography-used-by-signal/#:~:text=AJ-,Audits%20For%20Normies,-Audits%20are%20a)**
>
> Last year, I urged furries to stop using Telegram because it doesn’t actually provide them with any of the privacy guarantees they think it gives them. Instead of improving Telegram’s c…

> Regardless of the expertise of the consultants, every audit suffers from the same limitations:
> 
> 1. The engagement has a specific timebox, which means that coverage will be finite.
> 
> 2. The engagement is performed over a finite number of snapshots of the source code (typically, one commit hash), so each subsequent commit to the codebase erodes the relevance of the audit.
> 
> 3. The consultants are human beings, and therefore imperfect.

As for 1Password having “more audits”, simple CVE check tells you how useless the term itself is: [CVE - Search Results](https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=1password) (2 data exfiltration, 1 auth bypass, 1 server redirection, 1 privilege escalation, and 1 TLS vulnerability in the last 5 years itself). Interestingly, KeePassXC in the same duration has no actual attack vulnerability, except a weird memory dumping attack. And this too does not prove anything, since CVE counting is just as dumb as audit counting for security.

1Password is software, software has vulnerabilities. This blind trust is bad faith argumentation at best, and serious delusion at worst.

---

## Post 254 by @anonymous372 — 2025-07-30T17:49:13Z

> [@cgrams](#):
>
> Audits do not prove anything

Yes, they do. They prove competency as stated not long ago:

> [@Require Open Source for Password Managers](https://discuss.privacyguides.net/t/require-open-source-for-password-managers/12480/246):
>
> I’ve said it before and I’ll say it again: audits don’t measure trustworthiness, they measure competency slight_smile You never know if a no-log audit means a VPN provider isn’t logging, but you do know it means they didn’t accidentally forget to disable logging, which is still useful information to know about a company.

The GrapheneOS article linked in this topic shows that audits are most effective when done regularly by people familiar with the software. Soatok’s described limitations have less effect in this scenario;

- coverage will be finite, but it gets easier to cover as auditors become more familiar
- each subsequent commit to the codebase erodes the relevance of the audit, but the audits are frequent to maintain some relevance
- The consultants are human beings, but they can improve as they get more familiar

> [@Require Open Source for Password Managers](https://discuss.privacyguides.net/t/require-open-source-for-password-managers/12480/247):
>
> All the truth about audits: [Frequently Asked Questions | GrapheneOS](https://grapheneos.org/faq#audit) The most important part: The benefits of a group unfamiliar with the code spending a short time doing a shallow review are greatly overstated in marketing.

> [@cgrams](#):
>
> As for 1Password having “more audits”

I never meant to say that number of audits determines security, but KeePassXC has not been audited frequently, especially by entities as familiar with the codebase. Therefore the advantages it got from an audit are not as big as the advantages 1Password had.

> [@cgrams](#):
>
> This blind trust is bad faith argumentation at best

Sorry if it seems to you like I’m arguing in bad faith, but for example, I don’t think it’d be blind trust to say that MacOS is one of the more secure operating systems

---

## Post 255 by @anon11657877 — 2025-07-30T20:06:41Z

> [@anonymous372](#):
>
> KeePassXC has not been audited frequently, especially by entities as familiar with the codebase. Therefore the advantages it got from an audit are not as big as the advantages 1Password had.

I don’t think you understand. 1Password is a service. KeePassXC is not. Audits don’t guarantee software is safe and secure, and even if it did, cloud services are inherently less trustworthy than local storage, so KeePassXC can get away with not having yearly audits moreso than any cloud password manager. Again, there’s no provider to trust, only code, and all software has code.

---

## Post 256 by @anonymous372 — 2025-07-30T20:08:22Z

So you would think 1Password being closed source would be much less of a problem if it used local storage?

---

## Post 257 by @anon11657877 — 2025-07-30T20:11:26Z

1Password would be a problem regardless because it’s closed source.

> **[Proprietary Software
- GNU Project - Free Software Foundation](https://www.gnu.org/proprietary/proprietary.html)**

> **[Is It Ever a Good Thing to Use a Nonfree Program? 
- GNU Project - Free...](https://www.gnu.org/philosophy/is-ever-good-use-nonfree-program.html)**

---

## Post 258 by @fria — 2025-07-30T20:18:16Z

> [@anon11657877](#):
>
> 1Password is a service. KeePassXC is not. Audits don’t guarantee software is safe and secure, and even if it did, cloud services are inherently less trustworthy than local storage, so KeePassXC can get away with not having yearly audits moreso than any cloud password manager.

E2EE implemented properly removes the need to trust the server, so effectively as long their encryption is sound it doesn’t matter that they offer cloud sync. Audits don’t guarantee software is safe, true, but they show that someone knowledgeable has looked at the code that knows how encryption should be handled and made sure the overalll design is sound, plus alert them to any vulnerabilities they find. The fact that 1Password has been audited by multiple independent security firms several times is a good sign for their security I think.

---

## Post 259 by @anon11657877 — 2025-07-30T21:16:01Z

And you can’t 100% know E2EE is properly implemented even with audits and data breaches can happen on any online service. Avoiding cloud services and storing data locally mitigates that risk. It’s not true E2EE unless the user controls the encryption keys.

---

## Post 260 by @fria — 2025-07-30T21:41:48Z

> [@anon11657877](#):
>
> And you can’t 100% know E2EE is properly implemented even with audits

The firms auditing it know better than most people but yes it would be better if it was fully open source.

> [@anon11657877](#):
>
> data breaches can happen on any online service

If there’s a data breach of your password vault then they won’t have anything because it’ll all be encrypted.

> [@anon11657877](#):
>
> It’s not true E2EE unless the user controls the encryption keys.

E2EE doesn’t mean the user controls the keys it just means it’s encrypted between two points like your phone and your friend’s phone. I guess a better term is zero-knowledge encryption but regardless nothing about it means the user needs to control the keys.

---

## Post 261 by @anon11657877 — 2025-07-30T21:56:55Z

> [@fria](#):
>
> If there’s a data breach of your password vault then they won’t have anything because it’ll all be encrypted.

True, but you still have to trust the provider that it’s encrypted and if there’s a data breach, they can still harvest the encrypted data and decrypt it later, although it wouldn’t matter as long as everyone changed all their passwords right after the data breach.

> [@fria](#):
>
> E2EE doesn’t mean the user controls the keys it just means it’s encrypted between two points like your phone and your friend’s phone. I guess a better term is zero-knowledge encryption but regardless nothing about it means the user needs to control the keys.

If the user controls the encryption keys the risks of a backdoor are much lower.

Also should we make a poll for this (to see whether or not the majority of users here are in favor of requiring open source for password managers) or make a separate thread for prioritizing local storage password managers?

---

## Post 262 by @overdrawn98901 — 2025-07-31T00:21:18Z

> [@anon11657877](#):
>
> make a separate thread for prioritizing local storage password managers?

I’m never going to use a local password manager, even if more secure. I like the convenience. Not sure if such a thread is proposing to kick out cloud based managers.

I don’t think we should prescribe prioritization or local vs cloud, but explain the risk and usability benefits if not already done so.

---

## Post 263 by @anon11657877 — 2025-07-31T00:36:07Z

Maybe the local password managers could be lised first and the cloud password managers could be _worth mentioning_ (_worth mentioning_ should return, for some categories at least).

---

## Post 264 by @anon48875053 — 2025-07-31T09:06:30Z

> [@anonymous372](#):
>
> KeePassXC has not been audited frequently, especially by entities as familiar with the codebase.

How do you know that?

---

## Post 265 by @Niek-de-Wilde — 2025-07-31T09:25:33Z

One thing is that you would need to look at security in a broader term. The CIA traid dictates security in 3 manners: confidentiality, Intergrity, and availability.

Cloud based providers can help with the A part of this, availability. When your phone gets smashed or when youre computer crashes, you can simply login on another device and you are good to go.

One may argue that indeed confidentiality is a very important part of security, but its not the only thing that matters, especially with folks who are less tech savvy, who are unlikely to make proper backups.

---

## Post 266 by @anon61753997 — 2025-07-31T11:56:44Z

> [@anon11657877](#):
>
> If the user controls the encryption keys the risks of a backdoor are much lower.

It totally depends on how knowledgeable that user is. In opsec, you have to factor in “the users” as well since they are sometimes the weakest link. I will never let my mom, who is tech-illiterate and live far away from me, use a local password manager. Privacy Guides should provide resources for the mass as well, not just the tech-savvy.

> [@Niek-de-Wilde](#):
>
> One thing is that you would need to look at security in a broader term. The CIA traid dictates security in 3 manners: confidentiality, Intergrity, and availability.

---

## Post 267 by @anon11657877 — 2025-07-31T14:48:56Z

> [@Niek-de-Wilde](#):
>
> Cloud based providers can help with the A part of this, availability. When your phone gets smashed or when youre computer crashes, you can simply login on another device and you are good to go.

Anyone can backup their passwords onto other devices so this is a non-issue.

> [@Niek-de-Wilde](#):
>
> especially with folks who are less tech savvy, who are unlikely to make proper backups.

If they lose their passwords then it’s their own fault for not making proper backups.

---

## Post 268 by @Niek-de-Wilde — 2025-07-31T15:21:53Z

If this is your attitude then we no longer have to discuss. All I am saying is that while I acknowledge the upsides of an offline password manager, there are also downsides for non tech savvy users, a lot of which read PG as well. We try to keep a lot of threatmodels in mind, a cloud based are often just the best options for aformentioned users, you are always free to use an offline on yourself.

We will just have to agree to disagree here.

---

## Post 269 by @Bhaelros — 2025-07-31T15:46:53Z

As Niek says, not everyone is tech savy. You or me or most of the people visiting this forum is aware of how to operate a computer or mobile device but let’s say my kid or my wife or my neighbour have no clue about it. When they use a computer or mobile they only know which buttons to push and don’t care anything else because just pushing these buttons is doing what they want. They don’t need to and want to know anything else.

So, no, you cannot put blame on users because they are not good with tech. The software should do it instead, and while doing that it could try to educate the people like ELI5. But saying things like below is not the proper way to communicate or treat people.

> [@anon11657877](#):
>
> If they lose their passwords then it’s their own fault for not making proper backups.

---

## Post 270 by @anon11657877 — 2025-07-31T18:17:12Z

Then make video tutorials on how to make backups, transfer data from your computer to your phone (no cloud storage required, just a USB cable), and import passwords into another password manager. It’s easy. Even normies could do it. To me, this privacy journey isn’t just about using X instead of Y, but making lifestyle changes and cutting tech and the internet from my life. It doesn’t matter how reputable a cloud provider is. There’s always the risk associated with trusting a provider with anything, and passwords are the last thing I’d want to trust anyone else with.

---

## Post 271 by @Shampoo — 2025-07-31T18:35:31Z

Until the security of Linux and operating systems in general is improved cloud based providers may actually be safer than having an offline/local one unless local one is on a device that never connects to the internet. Their servers most likely have a smaller attack surface as they aren’t downloading and running programs made by devs with varying levels of competency, they aren’t browsing the internet on browsers that may be actively exploited (here’s a recent chromium one: [NVD - CVE-2025-6558](https://nvd.nist.gov/vuln/detail/CVE-2025-6558) ), and (in theory) they’re being monitored by people who are used to spotting threats.

---

## Post 272 by @anonymous378 — 2025-07-31T18:36:59Z

> [@anon11657877](#):
>
> Then make video tutorials on how to make backups, transfer data from your computer to your phone (no cloud storage required, just a USB cable), and import passwords into another password manager. It’s easy. Even normies could do it.

lol just what “normies” want to do, spend time managing two password managers.

> [@anon11657877](#):
>
> To me, this privacy journey isn’t just about using X instead of Y, but making lifestyle changes and cutting tech and the internet from my life. It doesn’t matter how reputable a cloud provider is.

I think your projecting your own personal privacy goals onto everyone else. Not everyones goals or needs are going to be the same. A lot of these “normie” user have no need, threat model wise, to avoid the cloud. Not to mention, it adds another layer of inconvenience for people just trying to upgrade from keeping their password on the back of a manilla folder in their computer desk.

---

## Post 273 by @anon48875053 — 2025-07-31T19:14:45Z

There are plenty of proprietary tools that could be considered better than FOSS alternatives, but it doesn’t mean that PG should just forget all the FOSS benefits and give up on it by including proprietary tools when it’s not necessary :face_with_diagonal_mouth:

KeePass, Bitwarden, and Proton Pass are enough for pretty much 99% of people. I have transitioned a lot ot of my family members and friends into one of these password managers from just reusing the same password everywhere and all of them are happy.

And again, audits are not a replacement for open source.

---

## Post 274 by @anon11657877 — 2025-07-31T19:24:10Z

> [@Shampoo](#):
>
> cloud based providers may actually be safer than having an offline/local one

Bullshit. Locally storing your passwords where they never leave your devices is less attack surface than trusting a provider whose ownership, privacy policy, and security can be compromised at any time. Your passwords aren’t in a centralized database which is likely a much bigger target for hackers. Besides, you’re still running the software on your device regardless.

---

## Post 275 by @Niek-de-Wilde — 2025-07-31T19:44:07Z

I think you can just boil this down to a fundamental disagreement. We both know eachothers points and arguments, but we just disagree, thats fine, we are allowed to have a different views on things :).

---

## Post 276 by @anon48875053 — 2025-07-31T19:44:30Z

One more benefit is that password managers like KeePassDX are completely offline, so they can’t even exfiltrate your database.

---

## Post 277 by @anon11657877 — 2025-07-31T21:29:48Z

Yeah we are, and I think we should make a compromise and write more about the pros and cons of local vs cloud password managers. Maybe PG can cater to both normies and advanced tech-savvy users (and although not as applicable here as other categories, ideologies as well).

And 1Password should be removed regardless because it’s closed source and we already have several other password managers which are enough for most people. 1Password is frequently audited? So is Bitwarden.

---

## Post 278 by @overdrawn98901 — 2025-07-31T22:32:50Z

> [@anonymous378](#):
>
> I think your projecting your own personal privacy goals onto everyone else.

This is 100% what’s happening.

> [@anon11657877](#):
>
> I think we should make a compromise and write more about the pros and cons of local vs cloud password managers

I also think this is a pretty good recommendation and think PG should do this.

---

## Post 279 by @Niek-de-Wilde — 2025-07-31T22:36:09Z

Maybe a neat idea for an article on the blog?@KevPham @fria @em

---

## Post 280 by @anonymous378 — 2025-07-31T22:54:08Z

> [@anon48875053](#):
>
> it doesn’t mean that PG should just forget all the FOSS benefits and give up on it by including proprietary tools

How does including a proprietary tool = PG forgetting the benefits of FOSS?

Recommending good privacy tools should be the goal, regardless if they are FOSS or proprietary.

> [@anon48875053](#):
>
> KeePass, Bitwarden, and Proton Pass are enough for pretty much 99% of people.

This is a made up stat and is meaningless. What is the argument here? More choice is bad?

I find it so baffling, especially with Password Managers and VPNs, users here are so excited to continuously attempt to limit the amount of recommendations for no other reason then “there are enough already” regardless of any other factors.

---

## Post 281 by @anon11657877 — 2025-07-31T23:22:13Z

> [@anonymous378](#):
>
> I find it so baffling, especially with Password Managers and VPNs, users here are so excited to continuously attempt to limit the amount of recommendations for no other reason then “there are enough already” regardless of any other factors.

I think the goal of PG is to recommend the best tools for the job instead of every single acceptable option. It’s not just with password managers and VPNs, but with anything. There’s no good reason to recommend a proprietary password manager when there are three other cloud password managers that meet all the requirements and 1Password doesn’t provide anything not already covered by Bitwarden or Proton Pass. Even Gopass, a local password manager, at least caters to those who prefer to use the commandline. There is no reason to keep recommending it.

> [@anonymous378](#):
>
> More choice is bad?

More choice is good, but so is having a criteria and supporting FOSS instead of proprietary garbage.

---

## Post 282 by @anonymous378 — 2025-08-01T00:05:16Z

> [@anon11657877](#):
>
> I think the goal of PG is to recommend the best tools for the job instead of every single acceptable option.

That’s never been the case nor is it anywhere close to being the case in any category on PG.

> [@anon11657877](#):
>
> There’s no good reason to recommend a proprietary password manager when there are three other cloud password managers

This may be true if there was a significant difference in quality but when there is not, both should be recommended and allow each user to make their own choice based on their threat model and circumstance instead of virtue signaling because a vocal minority is afraid to put a FOSS option alongside a proprietary one.

> [@anon11657877](#):
>
> having a criteria and supporting FOSS instead of proprietary garbage

its pretty clear to me you would consider any proprietary tool as “garbage”. The reality is all this does is limit options, the criteria in place has already proven to keep low quality recommendations from even being seriously posted.

It seems from your recent posts, the real intent is to remove 1password and IVPN using criteria suggestions more then it is to promote beneficial criteria.

---

## Post 283 by @anon11657877 — 2025-08-01T00:46:05Z

> [@anonymous378](#):
>
> vocal minority is afraid to put a FOSS option alongside a proprietary one.

More like a vocal majority values FOSS and believes we shouldn’t recommend proprietary tools when it’s unnecessary.

> [@anonymous378](#):
>
> the criteria in place has already proven to keep low quality recommendations from even being seriously posted.

I’ll believe that when open source becomes a hard requirement.

> [@anonymous378](#):
>
> the real intent is to remove 1password and IVPN using criteria suggestions more then it is to promote beneficial criteria.

IVPN is better than most other providers and does everything right (they’re even working on RAM-only servers) except physically own servers. That should be a dealbreaker. Otherwise they’re one of the best VPN services alongside Mullvad.

---

## Post 284 by @overdrawn98901 — 2025-08-01T00:52:11Z

> [@anonymous378](#):
>
> users here are so excited to continuously attempt to limit the amount of recommendations for no other reason then “there are enough already” regardless of any other factors.

More recommendations increases the chance of items being revoked. If PG lists it and the recommendation goes defunct, that would put PG as somewhat compliant in recommending it. So they are hesitant on that front.

The other is analysis paralysis. If I had 10 recommendations, all without distinct advantages, I’d be exhausted trying to determine what to use. For example there are tens of hundreds of Linux distros, all great for privacy, but the recommendations are distinct.

Recommendations must be the “best” at what they do, and offer distinct advantages to other recommendations. For example, Arch Linux vs SecureBlue is a strong argument, but recommending Arch and Manjaro vs (choose Arch derivative) leads to more questions.

These are recommendations not prescriptions. Use Manjaro, or whatever, but the recommendations serve as a default jumping off point, especially important for newcomers.

> [@anon11657877](#):
>
> More like a vocal majority values FOSS

Hmmm, this statement needs a qualifying statement against what majority is. The majority of all people will think you meant to say floss, and then get confused because they use free services like Google cause they don’t need to pay for it.

---

## Post 285 by @anon11657877 — 2025-08-01T00:58:08Z

> [@overdrawn98901](#):
>
> Hmmm, this statement needs a qualifying statement against what majority is.

Majority of users here and other privacy communities.

> [@overdrawn98901](#):
>
> Recommendations must be the “best” at what they do, and offer distinct advantages to other recommendations. For example, Arch Linux vs SecureBlue is a strong argument, but recommending Arch and Manjaro vs (choose Arch derivative) leads to more questions.

I agree. Even among the distros that aren’t recommended, Alpine (one of my favorite distros) stands out among minimalist distros for using Busybox, musl, and a non-systemd init. It’s great for software minimalists and servers but a bad option for anyone who doesn’t have advanced knowledge of Linux.

---

## Post 286 by @anon11657877 — 2025-08-05T13:56:05Z

Can’t we all move forward with this already? Either require open source for all categories (except providers and hardware since doing so isn’t feasible), or don’t require open source anywhere.

---

## Post 287 by @mangomango — 2025-08-05T16:54:44Z

> [@jonah](#):
>
> When topics are so split like this the best path forward is usually to maintain the status quo

Hey, why ?

---

## Post 288 by @anon11657877 — 2025-08-05T17:54:44Z

I and others have said it before. It doesn’t make sense to recommend proprietary software when it isn’t necessary, and we already have several open source password managers that meet all the criteria.

With this logic we might as well recommend [Obsidian](https://obsidian.md/), [Authy](https://www.authy.com/), and [Chrome](https://github.com/RKNF404/chromium-hardening-guide) too.

PG should be recommending alternatives that are better for privacy. For password managers, this would mean alternatives to LastPass, NordPass, Dashlane, RoboForm, **and 1Password.**

---

## Post 289 by @RandomGuyyy — 2025-08-05T18:02:29Z

I’m sorry but recommending something just because it’s open source is also not the way imo. Most people cannot read code and audit the product themselves. The only thing they can do is hope that someone else did and keeps doing it (when changes happen) and then also should compile the code themselves. I see this thrown around too many times and I start hearing non-technical people around me say “it’s safe because it’s open source”, which isn’t necessarily true.

---

## Post 290 by @anon11657877 — 2025-08-05T20:07:13Z

> [@RandomGuyyy](#):
>
> I’m sorry but recommending something just because it’s open source is also not the way imo.

I’m not recommending for anything just because it’s open source.  
I’m recommending **against** something because it’s **closed** source.

> [@RandomGuyyy](#):
>
> Most people cannot read code and audit the product themselves.

Most people don’t know how a car works and can’t repair it but they can still drive.

---

## Post 291 by @anon61753997 — 2025-08-05T20:25:58Z

> [@anon11657877](#):
>
> Most people don’t know how a car works and can’t repair it but they can still drive.

and can’t tell if a car has a safety defect.

This is the lamest analogy that I have heard in a long while. :man_facepalming:t2:

---

## Post 292 by @anon11657877 — 2025-08-05T20:27:41Z

The point is you don’t have to know how something works in order to use it.

---

## Post 293 by @anonymous378 — 2025-08-05T21:07:07Z

> [@anon49578468](#):
>
> No reason to not have this requirement now that there are good options all around.

> [@anon48875053](#):
>
> There are enough options already.

> [@fria](#):
>
> There are so many open source password managers available now there’s no reason not to make it a requirement.

> [@moonwriting](#):
>
> The current open source options for the password manager category are already more than good enough

> [@anon48875053](#):
>
> KeePass, Bitwarden, and Proton Pass are enough for pretty much 99% of people.

> [@anon11657877](#):
>
> There’s no good reason to recommend a proprietary password manager when there are three other cloud password managers that meet all the requirements and 1Password doesn’t provide anything not already covered by Bitwarden or Proton Pass. Even Gopass, a local password manager, at least caters to those who prefer to use the commandline. There is no reason to keep recommending it.

TheRe aRe aLrEady EnOugH oPtiOns … we get it guys

Wanted to get this in before the next cycle of this happens.

---

## Post 294 by @anon11657877 — 2025-08-05T23:25:37Z

> [@RandomGuyyy](#):
>
> recommending something just because it’s open source is also not the way

> [@anonymous372](#):
>
> Open source doesn’t mean

> [@Bhaelros](#):
>
> the people who are doing witch hunt against closed-source apps just because it is not open-source.

> [@anonymous378](#):
>
> there is a clear example of a non FOSS option being perfectly valid. It also seems to devalue user choice and tool effectiveness.

> [@Bhaelros](#):
>
> Just because they are not FOSS, doesn’t mean they are insecure.

> [@overdrawn98901](#):
>
> FOSS isn’t a hard requirement if E2EE is supported.

BuT fOSs DoEsNt MaTtEr … we get it guys

---

## Post 295 by @anonymous378 — 2025-08-06T04:04:01Z

@anon11657877 I am glad we agree, basically nothing new is being said and hasn’t since atleast 2024.

I blame @jonah for flip flopping every few months :joy:

> [@jonah](#):
>
> I think we could re-evaluate this once Proton Pass is out and there are multiple open-source cloud-based password managers

> [@jonah](#):
>
> I’m not really opposed to adding a FOSS criteria to this category

ok, sounds like were adding FOSS as a criteria…

> [@jonah](#):
>
> I don’t agree with the need for this criteria, personally.

> [@jonah](#):
>
> I still don’t really understand the motivation behind removing well-regarded products _solely_ because of their source code licensing

> [@jonah](#):
>
> I am against unnecessarily undoing existing work.

> [@jonah](#):
>
> no changes needed.

ok I guess FOSS is not going to be added as a Criteria

> [@jonah](#):
>
> The criteria would remain unchanged unless one of the following is true:
> 
> 1. The community wants to add something that is clearly so much worse than our recommendations (like Nordpass) that increasing the criteria is necessary to avoid confusion about why Nordpass isn’t recommended.
> 2. One of the recommendations falls so far behind the others that it no longer makes sense to list.
> 3. The community wants to add something that is so much radically better than our existing recommendations that it necessitates delisting the existing tools.
> 
> None of these 3 three things really apply.

oh cool, criteria for the criteria

> [@jonah](#):
>
> Personally, I would not really be opposed to making this change at this point

oh wait nevermind…

---

## Post 297 by @RandomGuyyy — 2025-08-07T04:24:08Z

If it becomes a requirement, I would also expect Jonah or someone else to audit the code. Otherwise it sounds like “Yeah it’s open source, it’s safe. We didn’t check but someone else in the world probably did and if it’s bad it would probably be known”. I would argue that 1password has a good reputation and imo works way better (and looks way better) than Bitwarden.

---

## Post 298 by @hashcatHitman — 2025-08-07T04:30:34Z

[A published audit from a reputable, independent third party is already required criteria regardless of source availability](https://www.privacyguides.org/en/passwords/#minimum-requirements), and I wouldn’t expect that requirement to go away any time soon.

---

## Post 299 by @RandomGuyyy — 2025-08-07T08:34:20Z

Exactly so I think the software being open source doesn’t add a lot imo

---

## Post 300 by @anon11657877 — 2025-08-07T14:50:22Z

1. KeePassXC has been audited.
2. It’s been established that while audits are good, they are not a replacement for open source.

> 1password has a good reputation

So do Bitwarden and Proton Pass.

> looks way better

This has nothing to do with whether or not 1Password should be recommended.

---

## Post 301 by @anonymous378 — 2025-08-08T05:13:29Z

> [@anon11657877](#):
>
> This has nothing to do with whether or not 1Password should be recommended.

False.

> [@Niek-de-Wilde](#):
>
> A note here is that we only recommend it because it provides a very good UX for for nontechnical people.  
> […]  
> The side wide policy is that that opensource is preffered, but that close source alternatives are allowed if they provide genuin UX or security improvements.

---

## Post 302 by @anon11657877 — 2025-08-08T14:20:49Z

So you think we should recommend NordPass and LastPass because of their UX?

Bitwarden and Proton Pass are good enough for most nontechnical people.

---

## Post 303 by @anonymous378 — 2025-08-08T15:19:54Z

> [@anon11657877](#):
>
> So you think we should recommend NordPass and LastPass because of their UX?

Irrelevant. I was pointing out that UX is actually a factor. You would of known this if you had taken the time to read the thread before commenting.

You should ask @anon48875053 about [NordPass](https://discuss.privacyguides.net/t/nordpass-password-managers/22705) since you two seem to come up with the same misguided comparisons.

You seem to have a concerning pattern for making [factually incorrect statements](https://discuss.privacyguides.net/t/rewrite-obtaining-applications-recommend-f-droid-over-obtainium-and-the-aurora-store/29820/18) as if they are true. Something that is frowned upon here.

---

## Post 304 by @anon11657877 — 2025-08-08T18:23:17Z

I’m starting to wonder how many votes this will get before this finally gets resolved. We’re already at 43 votes but the 1Password shills won’t go home.

> [@anonymous378](#):
>
> You should ask @Lukas about [NordPass](https://discuss.privacyguides.net/t/nordpass-password-managers/22705) since you two seem to come up with the same misguided comparisons.

> **off-topic**
>
> Open source for password managers might be one of the only things I agree with him on. From my knowledge he appears to be some anti-ideology Google advocate who dismisses sane views as conspiracy theories.

---

## Post 305 by @anon83428815 — 2025-08-08T18:29:25Z

Votes do not have any bearing on the outcome. Its mostly used to gauge interest.

Plus since every account can [double vote](https://discuss.privacyguides.net/t/anonymous-voting/29566/4), any user can create multiple accounts, and users who have left the community still have their votes count. Its hard to say the number of votes has any real meaning.

---

## Post 306 by @overdrawn98901 — 2025-08-08T21:57:17Z

> [@anon11657877](#):
>
> but the 1Password shills won’t go home.

I also don’t appreciate the hostility and aggro’d tone. Even if you disagree, vehemently, everyone here does have the same goal.

---

## Post 307 by @anon11657877 — 2025-08-08T22:56:59Z

If privacy is that goal then yes but instead of focusing on the actual issue we’re forever stuck debating whether or not open source should be required for password managers, and I’m going to keep this thread going until this gets approved.

Some of us value open source. Others think it doesn’t matter. Some of us want to avoid big tech. Others think that’s stupid. If the others had their way PG wouldn’t recommend open source at all. Whenever some expert writes any kind of article criticizing a piece of open source software, no matter how secure or insecure it really is, people will use that to trash open source projects.

My point stands. If Bitwarden and Proton Pass both have feature parity as 1Password, then because 1Password is proprietary and we have multiple other recommended password managers, then there’s no reason to have it recommended if Bitwarden, Proton Pass, KeePass, and Gopass satisfy everyone’s threat models and use cases. It doesn’t make sense to not require open source in areas where there are many acceptable open source solutions. This wouldn’t be much different than Authy being recommended and us debating about how open source should be required for 2FA.

---

## Post 308 by @anonymous390 — 2025-08-08T23:15:42Z

> [@anon11657877](#):
>
> If the others had their way PG wouldn’t recommend open source at all

No one’s arguing to remove KeePassXC or Bitwarden which are FOSS, they don’t have any security issues that stick out.

> [@anon11657877](#):
>
> If Bitwarden and Proton Pass both have feature parity as 1Password

Then I would agree that 1Password may be redundant, but as of now there are unique 1Password features like browser extension syncing

> [@Proton Pass product roadmap for next 6 months : file atachments, desktop-wide autofill, and more](https://discuss.privacyguides.net/t/proton-pass-product-roadmap-for-next-6-months-file-atachments-desktop-wide-autofill-and-more/22452/35):
>
> There is still no connecitivity between desktop and browser like 1Password does via native messaging.

and the secret key feature

> [@Require Open Source for Password Managers](https://discuss.privacyguides.net/t/require-open-source-for-password-managers/12480/19):
>
> 1Password does have a Secret Key feature so your account won’t be accessed even when someone else somehow knows your account and password: But it’s practically similar to Keepass’ keyfile so it does not affect me much.

You can vote for Proton Pass to support the latter feature on [UserVoice](https://protonmail.uservoice.com/forums/953584-proton-pass/suggestions/48518702-option-to-add-secret-key-like-how-1password-has)!

> [@Require Open Source for Password Managers](https://discuss.privacyguides.net/t/require-open-source-for-password-managers/12480/21):
>
> The SSH agent in particular is kind of a killer 1Password feature for me, although in general that’s probably too niche for most people to care about.

You can also [vote](https://protonmail.uservoice.com/forums/953584-proton-pass/suggestions/46853296-ssh-agent) for this feature!

---

## Post 309 by @RandomGuyyy — 2025-08-09T07:00:54Z

1Password is also way more stable imo. Bitwarden has a lot of issues autofilling on Android. Which is why I switched to 1Password (now at Proton Pass).

I see you’re the only one downvoting every comment that doesn’t agree with you. Also your tone “I’m going to keep this thread going till someone does what I say” sounds a bit eh….

”It’s been established that while audits are good, they are not a replacement for open source.” They are not a replacement for open source as they are different subjects.. I would however rather have a reputable 3rd party audit code & verify the security than having some open source project that I will have to trust someone in the world might have checked because I cba to do it myself..

---

## Post 310 by @anon11657877 — 2025-08-09T20:11:52Z

> [@anonymous390](#):
>
> No one’s arguing to remove KeePassXC or Bitwarden which are FOSS, they don’t have any security issues that stick out.

I meant PG wouldn’t have open source as a minimum requirement for any category.

> [@anonymous390](#):
>
> as of now there are unique 1Password features like browser extension syncing

An unnecessary “feature” that isn’t needed at all.

> [@RandomGuyyy](#):
>
> ”It’s been established that while audits are good, they are not a replacement for open source.” They are not a replacement for open source as they are different subjects.. I would however rather have a reputable 3rd party audit code & verify the security than having some open source project that I will have to trust someone in the world might have checked because I cba to do it myself..

Again. Audits are only valid for one version, and they are not 100% proof of security. Even the reputable 3rd parties will miss things. Open source however guarantees the right for anyone to audit and verify code of all versions.

---

## Post 311 by @hashcatHitman — 2025-08-09T20:55:33Z

> [@anon11657877](#):
>
> An unnecessary “feature” that isn’t needed at all.

For you, perhaps. Other people can disagree. As nice as it would be for everyone to use KeePass, some people consider local-only too much of a burden and need cloud-based password management. Options aren’t pie - giving more choices to others doesn’t mean fewer choices for you. (on that note, as far as I can tell Proton Pass DOES sync with the browser extension? not sure what feature we’re talking about here.)

---

## Post 312 by @anon11657877 — 2025-08-09T21:44:11Z

It’s unnecessary because browser extensions are unnecessary.

---

## Post 313 by @anonymous390 — 2025-08-09T21:51:50Z

> [@anon11657877](#):
>
> It’s unnecessary because browser extensions are unnecessary.

> [@hashcatHitman](#):
>
> For you, perhaps. Other people can disagree. As nice as it would be for everyone to use KeePass, some people consider local-only too much of a burden and need cloud-based password management. Options aren’t pie - giving more choices to others doesn’t mean fewer choices for you.

Also, the extension can use passkeys on desktop

---

## Post 314 by @hashcatHitman — 2025-08-09T22:06:19Z

I encourage you to take a minute to put yourself into the shoes of someone else. An old woman who is not particularly tech-literate. Do you deserve privacy and security? Personally, I’d argue yes! I’d say that’s a basic human right.

You don’t really understand why a password manager is needed at all. You were doing just fine before, with your password “ilovemygrandkids”. You used it for everything, so you wouldn’t forget it. But your son doesn’t think this is good enough. He really wants you to use a password manager, insisting your current practices are putting you at risk. It seems like a bit of a pointless hassle, but he promises it’ll be easy, and he’ll help you, so you agree.

So he downloads something to your computer and starts talking. “Okay, so when you want to make a new password you click over here…” “so to find your password you click this and start looking for the website” “you can copy paste it from here”. This is a lot to remember. You don’t even know what a “copy paste” is! And the way he presses some of those buttons on the keyboard looks like it would hurt your poor old bones. You silently decide to just keep doing it the old way. He won’t notice.

It’d be a lot easier if there was a way for it to take care of most of this for you. Sadly, no such solution exists!

…Except it does. Browser extensions are absolutely necessary for some people. Even the smallest obstructions can be too much to deal with, especially for people who are non-technical and/or disabled.

I say it again! Options are NOT pie! It is GOOD to have more options! It might not be necessary for _ **you** _, but _ **you** _ are not representative of _ **everyone** _.

---

## Post 315 by @anon11657877 — 2025-08-09T23:03:28Z

> [@hashcatHitman](#):
>
> So he downloads something to your computer and starts talking. “Okay, so when you want to make a new password you click over here…” “so to find your password you click this and start looking for the website” “you can copy paste it from here”. This is a lot to remember. You don’t even know what a “copy paste” is! And the way he presses some of those buttons on the keyboard looks like it would hurt your poor old bones. You silently decide to just keep doing it the old way. He won’t notice.

This can be done with any password manager.

> [@hashcatHitman](#):
>
> …Except it does. Browser extensions are absolutely necessary for some people. Even the smallest obstructions can be too much to deal with, especially for people who are non-technical and/or disabled.

Many people cannot read at all. Should they learn how to read or should they be told it’s okay not to know how to read?

---

## Post 316 by @hashcatHitman — 2025-08-09T23:12:51Z

> [@anon11657877](#):
>
> This can be done with any password manager.

You’ll need to elaborate on your point here, I have no idea what you’re trying to get across. My whole point is that browser extensions often greatly simplify this process and allow less-able users to bypass it completely.

> [@anon11657877](#):
>
> Many people cannot read at all. Should they learn how to read or should they be told it’s okay not to know how to read?

I’m not sure someone with cataracts would respond well to being told “just learn how to read”. Apparently that “isn’t how it works”. Accessibility is a good thing, actually.

---

## Post 317 by @anon11657877 — 2025-08-10T13:51:04Z

> [@hashcatHitman](#):
>
> You’ll need to elaborate on your point here, I have no idea what you’re trying to get across. My whole point is that browser extensions often greatly simplify this process and allow less-able users to bypass it completely.

Copy + paste passwords

---

## Post 318 by @mika — 2025-08-10T14:18:56Z

I agree with the bold stance that accessibility and ease of use are important elements of making privacy available to _everyone_.

I use BitWarden so I can’t speak to whether 1Password’s better UX justifies its inclusion despite not being open source. I _can_ attest that there were significant UI/UX hurdles to getting my family using BitWarden. They’ve (fortunately) improved a lot in the past year but still have a little ways to go.

> [@anon11657877](#):
>
> Again. Audits are only valid for one version, and they are not 100% proof of security. Even the reputable 3rd parties will miss things. Open source however guarantees the right for anyone to audit and verify code of all versions.

As someone who can’t read code - either way I’m trusting someone else to audit for me. Open source is _preferred_, but there is no option for me or most people that doesn’t involve trusting a 3rd party.

Open source is inherently better _if_ there is a large enough community with enough code-reading eyes on it to catch anything. Otherwise regular paid 3rd party audits seem more reliable than just code availability.

---

## Post 319 by @anonfox — 2025-08-10T14:45:52Z

I think bitwarden extension supports auto syncing

> Items owned by you in the [web vault](https://bitwarden.com/help/getting-started-webvault/) will always remain in-sync. Items owned by an [organization](https://bitwarden.com/help/about-organizations/) will sync across users and client applications every 30 minutes.
> 
> Other Bitwarden apps (browser extensions, mobile apps, desktop apps, and CLI) will sync automatically on login, and regularly when unlocked. You can also [manually sync](https://bitwarden.com/help/vault-sync/#manual-sync) your vault to pull changes immediately.

> **[Sync your Vault | Bitwarden](https://bitwarden.com/help/vault-sync/)**
>
> Personal Vaults always remain in sync, while Organization Vaults update ever 30 minutes. Learn how to perform a manually Vault sync if necessary.

---

## Post 320 by @anon11657877 — 2025-08-10T15:07:36Z

Accessibility and ease of use doesn’t make it more private it just means more people will want to use it so I don’t think it should be a criteria for which password managers offer the best privacy.

> [@mika](#):
>
> Open source is inherently better _if_ there is a large enough community with enough code-reading eyes on it to catch anything.

And both Bitwarden and KeePass are large enough projects so this isn’t an issue. Again audits aren’t a replacement for open source and cloud password managers should have to be both open source and audited to be included.

---

## Post 321 by @mika — 2025-08-10T15:58:33Z

> Accessibility and ease of use doesn’t make it more private it just means more people will want to use it so I don’t think it should be a criteria for which password managers offer the best privacy.

[The general criteria for Privacy Guides](https://www.privacyguides.org/en/about/criteria/) include usability and accessibility. That’s part of what makes this website and community such a great - and approachable - resource for everyday people navigating their personal threat models and priorities.

If you want recommendations based solely on what is the most private then PrivacyGuides is not the place for you.

---

## Post 322 by @Shampoo — 2025-08-10T19:07:28Z

Copy and pasting is worse than autofill. If you make a typo in a URL or fall for a phishing link autofill not working gives you a heads up that something might be wrong.

---

## Post 323 by @anon11657877 — 2025-08-10T19:13:17Z

If either Bitwarden and Proton Pass are accessible and usable for 99.9% of people, which they probably are, then there’s no room for 1Password and other proprietary password managers.

Also most of you may have seen this by now but if not I recently made a poll about this although it won’t affect this. Seems not a lot of people here actually use 1Password.

> [@Poll: Which password manager do you use?](https://discuss.privacyguides.net/t/poll-which-password-manager-do-you-use/29915):
>
> [poll](/t/poll-which-password-manager-do-you-use/29915/1)

---

## Post 324 by @anon11657877 — 2025-08-11T20:26:46Z

More about audits not being a replacement for open source. This is especially true for software as a service like 1Password which is more difficult to analyze.

> [@iPhones for privacy?](https://discuss.privacyguides.net/t/iphones-for-privacy/29939/35):
>
> About third party audits Matchbox posted this back in 2023. “The problem with audits the way we traditionally think about them (a company being paid to go through a snapshot of the codebase at a certain point in time) is flawed. New code is introduced all the time, so auditing a snapshot of that is not really going to be useful at any given point in time, since the “audit” would be outdated soon after.” I can see audits if an app or service gets updated a few times per year but it’s a serio…

---

## Post 325 by @IksNorTen — 2025-08-12T11:06:24Z

Why don’t you say the same thing to your friend @anonymous378 , who started the hostilities by resorting to ad hominem and strawman argument - even digging up other posts they wrote on other topics?

If we truly share the same goal here, maybe start by holding everyone to the same standard.

---

## Post 326 by @IksNorTen — 2025-08-12T11:10:16Z

Ah yes, the classic “mock the repetition” routine — because it’s so much easier to sneer at how something is said than to actually address why so many different people keep saying it. Maybe instead of copy-pasting posts to ridicule them, you could try engaging with the substance? The fact that this “cycle” keeps repeating should probably tell you something… and it’s probably not that everyone else is wrong.

---

## Post 327 by @IksNorTen — 2025-08-12T11:21:18Z

You say privacy and security are a basic human right. I completely agree — which is why I don’t see the point in steering non-technical users toward a paid, closed solution when there are open, well-audited ones that are easier to get started with and don’t lock you in.

For someone like the “grandma” in your example, the priority is removing as many hurdles as possible. Free access, simple browser autofill, and the ability to move your data if needed are what make the difference. Some tools already tick those boxes without putting a subscription paywall or company cloud in the middle. That’s what actually makes security accessible.

---

## Post 328 by @anonymous378 — 2025-08-12T12:48:12Z

> [@IksNorTen](#):
>
> Maybe instead of copy-pasting posts to ridicule them, you could try engaging with the substance?

Maybe read the thread first? There was a whole back and forth before that comment. I was not ridiculing anyone, granted it was a tad snarky :grin: but @anon11657877 can hold their own. I was pointing out a fact, our conversation had devolved into rehashing the same talking points that had been discussed thoroughly 8 months ago, which brings nothing new to the thread.

> [@IksNorTen](#):
>
> even digging up other posts they wrote on other topics?

If a user is so embarrassed by their post history that quoting them is an insult. Then maybe the user should take more time to think about what they type…or you know, delete their comment. Also, if you had taken the time to read carefully, you would notice all the quotes are from this thread not “other topics”.

Its amazing someone could support the ideals of open source transparency but, see quoting someone as an insult.

> **Off Topic**
>
> @IksNorTen You do not need to make three comments, you can edit one comment to include all your thoughts. You can also separate those with lines using `---`

---

## Post 329 by @WhinyHamletPayer — 2025-08-12T16:51:31Z

I haven’t contributed to this discussion yet but I will say that it is now the 3rd longest thread on PG. Congrats, everyone!

---

## Post 330 by @anon11657877 — 2025-08-12T16:55:53Z

> [@anonymous378](#):
>
> our conversation had devolved into rehashing the same talking points that had been discussed thoroughly 8 months ago, which brings nothing new to the thread.

And it’s never going to end until this gets approved (and then a new thread will be made to add back 1Password and drop the open source requirement).

> [@WhinyHamletPayer](#):
>
> I haven’t contributed to this discussion yet but I will say that it is now the 3rd longest thread on PG. Congrats, everyone!

That isn’t something to be proud of.

---

## Post 331 by @Bhaelros — 2025-08-12T17:04:24Z

If I understand your long posts correctly, you keep insisting nonsense until PG removes 1Password because they are your lifelong nemesis. Right? You keep saying every app must be FOSS or they shouldn’t exist at all. Every user must be technically adept or they are too stupid for your elitist ideas of privacy.

And until PG team removes 1Password you will keep opening new threads and polls and keep continuing this, whatever you think this is.

---

## Post 332 by @overdrawn98901 — 2025-08-12T17:22:17Z

I’m not a staff member. I have different opinions on when lines are crossed enough to call out. My line isn’t drawn at poor arguments, but when users are consistently using inflammatory language. We all get heated sometimes and it’s good to be checked on it to reflect. I have no ill will or intent to hurt his character. My intent is to de-escalate, even if candid, and to remind anyone, not just the person I’m replying to, to be act in good faith.

To put it simply:

> _“Be excellent to each other.”_ – **Bill S. Preston, Esq.**

---

## Post 333 by @cgrams — 2025-08-12T17:33:22Z

> [@anonymous372](#):
>
> Yes, they do. They prove competency as stated not long ago

No, they don’t. Quoting Jonah does not make it a fact, given that Jonah is not a relevant security researcher who can fall back to appeal to authority. Audits show exactly what they themselves say on the label: A team of supposedly competent people have looked at some code given by a company (often running on a demo server) under a given deadline. The soft undercurrent of “The one you are reviewing is also your financier” also does lead to mellow reports and recommendations.

> [@anonymous372](#):
>
> regularly by people familiar with the software

And this does not happen at 1Password. You can look at their audit reports.

> [@anonymous372](#):
>
> auditors become more familiar

Auditors are not constant. This is just ignorance or intentionally misleading.

> [@anonymous372](#):
>
> I never meant to say that number of audits determines security

> [@anonymous372](#):
>
> KeePassXC only got audited once, so they’re worse off than 1Password

You did exactly that.

> [@anonymous372](#):
>
> KeePassXC has not been audited frequently, especially by entities as familiar with the codebase.

Source? How do you know? Are all audits public? Is there no social audit by frequent users? Are you aware of if governments that use KeePass (there are a lot) have employed secret audits? This just keeps on getting worse.

> [@anonymous372](#):
>
> but for example, I don’t think it’d be blind trust to say that MacOS is one of the more secure operating systems

This is orthogonal and unrelated to our discussion. The blind trust comment was related to audits not 1Password.

I don’t care about macos, I don’t care about 1Password, I don’t care about open source requirements. I just want people to stop insinuating audits prove A is better than B at anything.

---

## Post 334 by @cgrams — 2025-08-12T17:40:23Z

I also cannot comprehend why this debate is so long. If 1Password is indeed necessary for serving common minimum user (which I don’t believe), then why should open source become a hurdle in recommending good software. Open source in all tools does not make sense unless it is ceteris paribus when it comes to UX. This is privacy guides not foss guides.

More specifically for 1Password, there is also cognitive dissonance in the guides team. If the idea is to recommend tool for general users, then recommending existing foss tools that provide decent experience should not be an issue:

1. User is already being pushed to use a new tool (password manager) and thus has a chance to learn new UX, so no constraint on sticking with “better” UI, seeing as the user has no initial “bad” UI to compare it to.
2. The general user has no need for tools like ssh login or complex setups, and thus basic tools that lack specific niche features are fine.

Very weird thread overall.

---

## Post 335 by @anon11657877 — 2025-08-12T21:27:36Z

> [@Bhaelros](#):
>
> 1Password because they are your lifelong nemesis. Right?

1Password isn’t the problem. Proprietary software is.

> [@Bhaelros](#):
>
> You keep saying every app must be FOSS or they shouldn’t exist at all.

**Correction:** every app that isn’t FOSS shouldn’t be recommended on PG.

> [@cgrams](#):
>
> If 1Password is indeed necessary for serving common minimum user (which I don’t believe), then why should open source become a hurdle in recommending good software.

If Bitwarden and Proton Pass are capable of serving normies, then why should proprietary software be recommended especially if it’s for something as security-sensitive as passwords?

---

## Post 336 by @mika — 2025-08-12T21:42:21Z

> [@anon11657877](#):
>
> **Correction:** every app that isn’t FOSS shouldn’t be recommended on PG.

This is not FOSSGuides, it’s PrivacyGuides. [The policy of PrivacyGuides](https://www.privacyguides.org/en/about/criteria/) is “open source is preferred” while also balancing considerations of privacy, security, availability, and usability, among other factors.

A community that truly _only_ allowed FOSS software wouldn’t even host recommendations for Windows, Mac, and iOS, and would thus be a _far_ less useful resource for helping most people make more private choices. A few versions of that community already exist out there, and you’re free to join them. But we’re all here on PrivacyGuides for _its_ unique strengths. Personally, I prize this community’s accessibility and overall balanced approach.

Saying ‘I will keep opening threads and arguing with others until this community changes its values to reflect _ **my** _ preference’ is asinine and isn’t winning anyone over to your cause.

---

## Post 337 by @Bhaelros — 2025-08-12T21:45:38Z

Bitwarden and Proton Pass are not good enough. They are still ages behind 1Password and Proton Pass is still looks like beta app with outrageous pricing. And yet you keep attacking 1Password nearly on your every post.

PG is privacy oriented forum but it is not FOSS only forum.

---

## Post 338 by @overdrawn98901 — 2025-08-12T22:39:31Z

> [@Bhaelros](#):
>
> PG is privacy oriented forum but it is not FOSS only forum.

This is the correct mindset. I’ll advocate FOSS till the day I die, but we live in a reality that isn’t that binary. I choose Bitwarden because it is FOSS. But that doesn’t mean I won’t recommend 1Password to those would benefit from the UX it offers over Bitwarden and Proton Pass. The moment Bitwarden and/or Proton Pass features some UX feature parity, then 1Password has lost the battle and should be kicked.

We shouldn’t be debating what is or isn’t FOSS, we should be debating what are the key improvements we want to see in Bitwarden / Proton Pass to leave 1Pass in the dust. This provides a clear and actionable step to raise the bar, and those who pay for Bitwarden / Proton Pass can help push for that.

---

## Post 339 by @anon11657877 — 2025-08-12T23:29:10Z

> [@mika](#):
>
> This is not FOSSGuides, it’s PrivacyGuides. [The policy of PrivacyGuides](https://www.privacyguides.org/en/about/criteria/) is “open source is preferred” while also balancing considerations of privacy, security, availability, and usability, among other factors.

The point is open source should be required in all categories unless allowing proprietary software is necessary due to lack of FOSS alternatives. There are some categories where it isn’t feasible to require FOSS and a proprietary solution is necessary. Password managers is not one of them.

> [@Bhaelros](#):
>
> Bitwarden and Proton Pass are not good enough. They are still ages behind 1Password

Firefox and Brave are not good enough. They are still ages behind Chrome.  
GrapheneOS is not good enough. It is still ages behind iOS and Stock Android.  
Signal and SimpleX are not good enough. They are still ages behind WhatsApp.  
Aegis and Ente Auth are not good enough. They are still ages behind Authy.  
Mullvad and ProtonVPN are not good enough. They are still ages behind NordVPN.

We get it. You love proprietary software.

> [@overdrawn98901](#):
>
> I won’t recommend 1Password to those would benefit from the UX it offers over Bitwarden and Proton Pass. The moment Bitwarden and/or Proton Pass features some UX feature parity, then 1Password has lost the battle and should be kicked.

There is nothing beneficial about a bloated [Electron](https://blog.doyensec.com/2022/09/27/electron-api-default-permissions.html) UX.

---

## Post 340 by @jonah — 2025-08-12T23:33:24Z

> [@anon11657877](#):
>
> Firefox and Brave are not good enough. They are still ages behind Chrome.  
> GrapheneOS is not good enough. It is still ages behind iOS and Stock Android.  
> Signal and SimpleX are not good enough. They are still ages behind WhatsApp.  
> Aegis and Ente Auth are not good enough. They are still ages behind Authy.  
> Mullvad and ProtonVPN are not good enough. They are still ages behind NordVPN.

I think the main problem a lot of people have with this proposal is that all of the examples you’ve named are demonstrable privacy-offenders, but the problems with 1Password are theoretical.

---

## Post 341 by @overdrawn98901 — 2025-08-12T23:40:33Z

> [@anon11657877](#):
>
> There is nothing beneficial about a bloated [Electron](https://blog.doyensec.com/2022/09/27/electron-api-default-permissions.html) UX.

Wait till you see how the desktop Bitwarden app is built.

With this, UX is more than just performance and the delivery mechanism of the app. Your linked article talks about security, nothing about how the user actually interacts with the set of features. It’s the feature set and usability of those features with minimal friction. The delivery mechanism can assist with that, but isn’t the sole arbiter of a good experience.

What we need is a set of features that is currently lacking, or a clear user story / UX problem that is currently lacking, in order to evaluate why 1Password is still recommended.

> [@anon11657877](#):
>
> We get it. You love proprietary software.

Non sequitor. Just because someone believes some proprietary applications offer a better UX than comparable FOSS alternatives, does not mean the user prefers proprietary over FOSS.

Again, I’ll call you out, be in good faith.

---

## Post 342 by @anon11657877 — 2025-08-13T14:53:54Z

1Password being closed source is **not** theoretical. It’s a fact.

> [@overdrawn98901](#):
>
> What we need is a set of features that is currently lacking, or a clear user story / UX problem that is currently lacking, in order to evaluate why 1Password is still recommended.

Well in that case at least change the order of recommendations so that 1Password is the last resort option for the select few who can’t use anything better.

**Local Storage** (for security)

- KeePassXC
- KeePassDX
- Gopass

**Cloud-based** (for convenience)

- Bitwarden
- Proton Pass
- Psono
- 1Password

---

## Post 343 by @anonymous378 — 2025-08-13T16:45:43Z

> [@anon11657877](#):
>
> 1Password being closed source is **not** theoretical. It’s a fact.

> [@jonah](#):
>
> the problems with 1Password are theoretical.

I think you misunderstood the point. The issues you are associating with 1Password because they are closed source are just theoretical. Whereas the other examples you gave have verifiable issues.

This has always been a key point that people who want to remove 1Password have no counter too. The fact is, 1Password has been an excellent password manager with a stellar record. Removing them when that’s the case seems heavy handed. Removing it at this point just lowers the amount of good options PG provides visibility to, with no benefit.

---

## Post 344 by @fria — 2025-08-13T16:48:57Z

Honestly can we get a petition going for 1Password to open source their app, that would solve this whole thing. They do genuinely seem to value security, so opening the source code up and maybe offering reproducible builds would be a big security boon.

---

## Post 345 by @anonymous378 — 2025-08-13T16:53:27Z

:100: Totally agree.

---

## Post 346 by @anon11657877 — 2025-08-13T17:06:39Z

> [@anonymous378](#):
>
> The fact is, 1Password has been an excellent password manager with a stellar record. Removing them when that’s the case seems heavy handed.

You could say that about Chrome even though we have several great open source browsers, both Chromium based and Firefox based. There’s nothing heavy handed about requiring open source. **Closed source password managers never should have been recommended in the first place.**

---

## Post 347 by @anonymous378 — 2025-08-13T17:09:27Z

> [@anon11657877](#):
>
> You could say that about Chrome

:joy: no you can’t

---

## Post 348 by @anon11657877 — 2025-08-13T18:36:24Z

> [@anonymous378](#):
>
> :joy: no you can’t

- [GitHub - RKNF404/chromium-hardening-guide: Harden chromium (somewhat)](https://github.com/RKNF404/chromium-hardening-guide)

> **Brave**  
> Not terrible, but a weak option. Most of this browser is either matching vanilla chromium, a degredation, or modifies a default. For example, they enable MV2 support when that format is actively being deprecated in chromium. MV2 is awful for security  
> Brave is rather useless. It is filled with bloat and any security or privacy advantages, even the adblocker, can be achieved with Chrome.

> **Firefox**  
> Firefox is [inherently insecure](https://madaidans-insecurities.github.io/firefox-chromium.html).

> Librewolf is just Firefox with defaults changed… nothing else. They don’t even maintain the defaults, they just use [arkenfox-user.js](https://github.com/arkenfox/user.js/).

So Chrome is more secure and compatible with the web than any PG recommended browser.

> The only downside is that Chrome is proprietary. This has no effect on security nor significant effect on privacy, it is essentially vanilla Chromium with a few proprietary additions and licenced libraries. Most of the intrusive stuff is disabled by following this guide.

So by every 1Password shill’s logic we should allow proprietary browsers and recommend Chrome. This is bullshit. Next someone will want to recommend Microsoft Office because LibreOffice wasn’t enough.

---

## Post 349 by @anonymous378 — 2025-08-13T18:43:48Z

> [@anon11657877](#):
>
> So by every 1Password shill’s logic we should allow proprietary browsers and recommend Chrome. This is bullshit.

You are drawing conclusions out of thin air. Literally nobody is advocating what you are saying.

> [@overdrawn98901](#):
>
> Again, I’ll call you out, be in good faith.

The actual logic being used, at least by me, is strong privacy options should not be removed over what is basically a source code licensing issue.

* * *

I think this is a great standard for looking at removal of recommendations.

> [@jonah](#):
>
> Historically we have only removed recommendations when something happens that directly impacts people’s privacy negatively.

I also thought, before @jonah seemingly changed his mind, this was a great way to evaluate if a criteria should be changed.

> [@jonah](#):
>
> The criteria would remain unchanged unless one of the following is true:
> 
> 1. The community wants to add something that is clearly so much worse than our recommendations (like Nordpass) that increasing the criteria is necessary to avoid confusion about why Nordpass isn’t recommended.
> 2. One of the recommendations falls so far behind the others that it no longer makes sense to list.
> 3. The community wants to add something that is so much radically better than our existing recommendations that it necessitates delisting the existing tools.

---

## Post 350 by @anon11657877 — 2025-08-13T19:04:14Z

> [@jonah](#):
>
> Historically we have only removed recommendations when something happens that directly impacts people’s privacy negatively.

- [Reddit - The heart of the internet](https://www.reddit.com/r/PrivacyGuides/comments/u31ocu/privacy_guides_changelogs_first_half_of_april_2022/)

> ### #Removed pass
> 
> Why : Should use gopass instead. **While there is nothing wrong with pass** in particular, **there is little reasons to recommend it** , as gopass is both compatible with pass APIs and is cross platform. gopass also has experimental pass backend as well for those who do not want to use PGP.

* * *

There is little reasons to recommend 1Password, as Bitwarden, Proton Pass, and KeePass are both enough for most people and are open source.

---

## Post 351 by @anon83428815 — 2025-08-13T20:26:32Z

> [@anon11657877](#):
>
> There is little reasons to recommend 1Password

Here is the thing, **it is recommended.** Typically once a tool is already recommended it is a high bar to remove it. Saying there is already enough good options, does not meet that bar and it should not meet that bar.

This whole “enough” options argument seems silly. If you really believe there should be a limit to how many options there are in this category make a new post to get that added as a criteria. Once it is approved that argument might have some weight. Otherwise its just a meaningless argument based on a limit that does not exist.

I also question if people really believe there is enough options. If another great open source password manager comes along are you or anyone else who has said this really going to say “no thanks Bitwarden, Proton Pass, and KeePass are enough”? I have my doubts…

---

## Post 352 by @overdrawn98901 — 2025-08-13T22:56:26Z

> [@anonymous378](#):
>
> The actual logic being used, at least by me, is strong privacy options should not be removed over what is basically a source code licensing issue.

Correct. We have ran in circles about licensing to the point we’ve dug a moat, so I don’t think that approach is moving much. I am attempting to rephrase the problem as to why 1Pass was recommended in the first place, and why it holds true today, and what criteria it meets over Bitwarden and Proton Pass. Evaluating this criteria will allow FOSS to shine, but not as much of a hardline approach.

---

## Post 353 by @anon11657877 — 2025-08-13T23:12:32Z

> [@anon83428815](#):
>
> This whole “enough” options argument seems silly. If you really believe there should be a limit to how many options there are in this category make a new post to get that added as a criteria.

> [@anon83428815](#):
>
> I also question if people really believe there is enough options. If another great open source password manager comes along are you or anyone else who has said this really going to say “no thanks Bitwarden, Proton Pass, and KeePass are enough”?

If another great **open source** password manager comes along and it meets all the criteria then I’d have no problem if it were recommended. Point is there’s already enough **open source** options that there’s no need for **proprietary** options. This is less about removing 1Password and more about requiring open source.

> [@overdrawn98901](#):
>
> why 1Pass was recommended in the first place

It was recommended because some people decided FOSS didn’t matter.

---

## Post 354 by @overdrawn98901 — 2025-08-13T23:56:15Z

> [@anon11657877](#):
>
> It was recommended because some people decided FOSS didn’t matter.

This entirely trivializes the original decision without trying to understand it.

This is an impasse between us on trying to refocus on another means to understanding the problem. If it’s strictly FOSS or die, then that point is a beaten dead horse, and I think everything that has been said in the subject has been said.

---

## Post 355 by @anon83428815 — 2025-08-14T00:02:39Z

> [@anon11657877](#):
>
> This is less about removing 1Password and more about requiring open source.

Half a dozen one way, six the other. All this criteria does is remove 1Password.

> [@anon11657877](#):
>
> Point is there’s already enough **open source** options that there’s no need for **proprietary** options.

This is what I am getting at. You are creating a criteria that does not exist based on the number of options and then saying that criteria is the reason your argument is valid.

Unless you are willing to say that even if there were 0 good open source options you would still want open source to be a requirement.

It seems like what you (and others who make a similar argument) really want is a general rule to the effect of “no proprietary options if there are 3 or greater open source options” which would replace the preference for open source that PG currently has.

---

## Post 356 by @anon37002130 — 2025-08-14T11:29:46Z

Here are all the features 1Password has that these open source password managers lack or that some have in some capacity:

- **Archive** [[Archive and delete items | 1Password Support](https://support.1password.com/archive-delete-items/) ] _(None of the open source password managers support this feature)._

- **Able to store Sign in with providers** (like Google, Apple or some obscure provider. For 1Password to remember this information and sign you in accordingly). [[Use 1Password to sign in to sites with supported providers](https://support.1password.com/sign-in-with-provider/)] _(None of the open source password managers support this feature)._

- **Travel Mode** [[Use Travel Mode to remove vaults from your devices when you travel | 1Password Support](https://support.1password.com/travel-mode/) ] _(None of the open source password managers support this feature)._

- **Choose your default identity and credit card items** [[Choose your default identity and credit card items | 1Password Support](https://support.1password.com/profile/) ] _(None of the open source password managers support this feature)._

- **Watch tower in iOS/Android app** (which finds which websites support Passkeys/2FA and to fix weak passwords). [[Use Watchtower to find account details you need to change | 1Password Support](https://support.1password.com/watchtower/) ] _(Proton Pass does have a watchtower like app but it does not show sites that support passkeys, Bitwarden does have a audit page but it is only available online on desktop)._

- **Secret Key** [[Find your Secret Key or Setup Code | 1Password Support](https://support.1password.com/secret-key/) ] _(Proton Pass supports extra password which is separate from the main Proton account password, KeePass has keyfiles, Bitwarden does not have such a feature)._

- **Predefined custom fields for security questions, PINs, etc** [[Customize your 1Password items | 1Password Support](https://support.1password.com/custom-fields/) ][[Create unique answers to security questions | 1Password Support](https://support.1password.com/generate-security-questions/) ] _(Proton Pass, Bitwarden, nor KeePass support generation of security question or include a predefined field that can be created for security questions)._

- **Tags** [[Organize with favorites and tags | 1Password Support](https://support.1password.com/favorites-tags/) ] _(KeePass supports tags)._

- **Privacy cards integration** [[Use 1Password to create and fill Privacy Cards | 1Password Support](https://support.1password.com/privacy-cards/) ] _(None of the open source password managers support this feature)._

- **Collections to isolate important stuff from other items so you can get to it quickly.** [[Use collections to create custom groups of vaults | 1Password Support](https://support.1password.com/collections/) ] _(Proton Pass does have vaults that isolate items separately from each other)._

- **Additional item types** [[1Password item categories | 1Password Support](https://support.1password.com/item-categories/) ] _(Proton Pass just developed this, but Bitwarden still lacks these predefined item types)._

As, you can see when it come to 1Password it is superior in terms of features and quality of life updates with years of experience and support creating their password manager. **1Password has been around since June 18, 2006.** So, 1Password as a company has had time to build a reputation that has not faltered yet over the years.

They have the experience, expertise and have not had a data breach for the entire time they have been active.

Until one of these open source password managers come somewhat feature parity. Then I would say “personally” we should consider password managers that are fully open source. But at the moment, if you want some of 1Password features you would need to mix and match with different open source password managers to be somewhat feature parity to 1Password and even then some feature are exclusive to 1Password. Whereas you could just use 1Password which already has all the features needed for almost all individuals/families and is trusted and secure.

[[About the 1Password security model | 1Password Support](https://support.1password.com/1password-security/) ]

[[Security audits of 1Password | 1Password Support](https://support.1password.com/security-assessments/) ]

> **Bug Bounty Program**

> As of December 2024, 1Password has moved its bug bounty initiative to HackerOne.

> HackerOne is engaged in an ongoing bug bounty program targeting the 1Password service and web-application. [Check out the program details.](https://hackerone.com/1password)

> _\>This program is currently open to the public and has received submissions from hundreds of unique researchers. Issues submitted range in scope and severity. Despite the presence of findings no user secrets were at risk._

---

## Post 357 by @anon11657877 — 2025-08-14T14:57:18Z

> [@anon83428815](#):
>
> Unless you are willing to say that even if there were 0 good open source options you would still want open source to be a requirement.

If there’s at least one good open source option and all use cases are covered (Bitwarden and Proton Pass for cloud storage, KeePass and Gopass for local storage) then open source should be a requirement. Open source is required for most other software categories even though proprietary options with extra features exist.

> [@anon37002130](#):
>
> **Archive** [[Archive and delete items | 1Password Support](https://support.1password.com/archive-delete-items/) ] _(None of the open source password managers support this feature)._

Incorrect. [KeePassXC](https://keepassxc.org/docs/KeePassXC_UserGuide#_deleting_an_entry) has this in the form of a recycle bin.

> [@anon37002130](#):
>
> **Able to store Sign in with providers** (like Google, Apple or some obscure provider. For 1Password to remember this information and sign you in accordingly)

People shouldn’t be signing in through Google or other providers at all.

> [@anon37002130](#):
>
> **Choose your default identity and credit card items**

We’re recommending password managers, not credit card managers, and credit card information is even more sensitive and shouldn’t be stored on the cloud.

> [@anon37002130](#):
>
> which finds which websites support Passkeys/2FA and to fix weak passwords

You don’t need a password manager to tell you this. You can login to each website, look through your account settings, and check yourself if passkeys are supported.

Might as well recommend Microsoft Office for having more “features” like Microsoft account integration, or NordVPN for [Threat Protection Pro](https://nordvpn.com/features/threat-protection/) malware scanning, fraud alerts, [Dark Web Monitor](https://nordvpn.com/features/dark-web-monitor/).

---

## Post 358 by @Catalyst2422 — 2025-08-14T15:18:32Z

> [@anon11657877](#):
>
> We’re recommending password managers, not credit card managers, and credit card information is even more sensitive and shouldn’t be stored on the cloud.

What about online banking logins? Or business email accounts that could be compromised and used to send out altered invoices? - Trying to draw an arbitrary line as to what is considered secure vs insecure to store in a password mannager is just that. Arbitrary.

---

## Post 359 by @Catalyst2422 — 2025-08-14T15:21:01Z

> [@anon11657877](#):
>
> You don’t need a password manager to tell you this. You can login to each website, look through your account settings, and check yourself if passkeys are supported.

You don’t need a password manager at all. You can just memorise all your passwords. This is a useful and convenient feature for the majority of users. You seem to have very specific ideas as to what a password manager should and shouldn’t be used for. It’s _Privacy_ Guides. Not _Privium_ Guides.

---

## Post 361 by @overdrawn98901 — 2025-08-14T15:42:42Z

It’s not worth engaging with Privium anymore on the matter. His stance is mostly FOSS or death, and no net-new information is coming from the engagement.

---

## Post 362 by @anon83428815 — 2025-08-14T16:00:58Z

> [@anon11657877](#):
>
> If there’s at least one good open source option and all use cases are covered

Ok but that is different then requiring open source for password managers. You have already created an exception in your criteria. This is the kind of slippery slope that should be avoided otherwise PG will be constantly reverting their criteria or having to make exceptions for that criteria. It is way cleaner to just “prefer open source” which PG already does.

You will notice that in [categories that require open source](https://www.privacyguides.org/en/notebooks/?h=note#best-case) there is no clause for having there be at least “one good” option for the criteria to apply. All it says is

> Clients must be open source

* * *

> [@anon11657877](#):
>
> Open source is required for most other software categories

I think people often overlook that some categories require more nuance. It would be helpful for everyone to recognize that comparing criteria from different categories is like making an apples-to-oranges comparison, which doesn’t provide a solid foundation for changing criteria. For instance, if notebooks have overly strict criteria, they might end up with no good options. Conversely, if PG had no password managers to recommend, it would lose all credibility.

---

## Post 363 by @anon11657877 — 2025-08-14T18:55:50Z

> [@Catalyst2422](#):
>
> You don’t need a password manager at all. You can just memorise all your passwords.

Not having to memorize your passwords is the whole point of a password manager. Memorizing random 32+ character strings is harder and less convenient than manually checking to see if your site supports passkeys. You don’t even need to use 1Password for this.

- [https://passkeys.directory/](https://passkeys.directory/)

But this is about as useful as tosdr.

> [@Catalyst2422](#):
>
> It’s _Privacy_ Guides. Not _Privium_ Guides.

It’s not _Catalyst2422_ Guides either, or _Proprietary_ Guides.

> [@anon83428815](#):
>
> Ok but that is different then requiring open source for password managers. You have already created an exception in your criteria. This is the kind of slippery slope that should be avoided otherwise PG will be constantly reverting their criteria or having to make exceptions for that criteria.

The only slippery slope here was gradually removing the open source requirement for more and more categories and promoting proprietary software. First it was Safari, then 1Password, then Apple Mail, then Microsoft Office, then Apple Health.

> [@anon83428815](#):
>
> Conversely, if PG had no password managers to recommend, it would lose all credibility.

But they do have several password managers to recommend: Bitwarden, Proton Pass, Psono, KeePass, and Gopass.

---

## Post 364 by @anon83428815 — 2025-08-14T19:06:41Z

Your dodging the main point which is your not actually advocating for open source to be a hard requirement.

You are advocating for open source to be a requirement assuming there are good options. That’s a different criteria. We can go back and forth about the chances of that difference being meaningful but, it doesn’t matter. That is a different criteria and a different discussion.

Personally, I feel any criteria that leaves a non zero chance of having no recommendations in a critical category is a bad criteria. Since you are not willing to say you support the criteria even in the event it leads to 0 recommendations, I have to assume you agree.

---

## Post 365 by @mika — 2025-08-14T19:13:20Z

It’s best to just stop feeding the troll. Either he’ll find a way to make peace with PrivacyGuides not being his personal fiefdom that bends to his personal demands or he’ll move on to another community. Either way it’s not worth any more engagement.

---

## Post 366 by @anon83428815 — 2025-08-14T19:15:58Z

> [@mika](#):
>
> It’s best to just stop feeding the troll.

I get where your coming from but, I don’t want to go so far as to label @anon11657877 a troll, although I think some of their arguments have not been in good faith. That’s not say that I believe for a second that I will ever convince them of my point.

That’s ok…

I enjoy the discussion as a thought exercise anyway and, I hope others who read it but, don’t comment, get something out of it too. :grinning_face:

Although, I may give it a break for a bit. If its just me and @anon11657877 its probably better suited for a PM.

---

## Post 367 by @Catalyst2422 — 2025-08-14T20:08:38Z

> [@anon11657877](#):
>
> Not having to memorize your passwords is the whole point of a password manager. Memorizing random 32+ character strings is harder and less convenient than manually checking to see if your site supports passkeys.

I’m glad we agree. Memorising a long string is tricky. Like a credit card number for instance. Up to 19 digits. Plus 4 more for the date. Plus up to 4 for the CVV. Wouldn’t it be a good idea to keep that in a password manager too? Or is it better to carry it printed in plaintext on a piece of plastic in our pockets?

> [@anon11657877](#):
>
> It’s not _Catalyst2422_ Guides either, or _Proprietary_ Guides.

Nor is it FOSSguides….

---

## Post 368 by @americanhorse — 2025-08-14T20:49:03Z

I’m tired, boss. :pensive_face:

Can we lock this thread now? I’ve read over 300 comments, and I am pretty sure there’s nothing new to be said at this point.

---

## Post 369 by @anon11657877 — 2025-08-14T21:31:16Z

> [@anon83428815](#):
>
> Since you are not willing to say you support the criteria even in the event it leads to 0 recommendations, I have to assume you agree.

If there are no recommendations then it probably doesn’t need any.

> [@anon83428815](#):
>
> Your dodging the main point which is your not actually advocating for open source to be a hard requirement.

Open source should be a hard requirement for any software because there are always open source alternatives to software. It’s just service providers like search engines and hardware where it isn’t feasible to require it.

> [@Catalyst2422](#):
>
> Wouldn’t it be a good idea to keep that in a password manager too? Or is it better to carry it printed in plaintext on a piece of plastic in our pockets?

It’s already in plaintext on a piece of plastic anyways. Passwords aren’t.

> [@Catalyst2422](#):
>
> Nor is it FOSSguides….

Or Securityguides.

> [@americanhorse](#):
>
> Can we lock this thread now?

Not yet. We’re only 20 replies away from this being the most replied topic on this forum. And not without this being marked as either approved ~~or rejected~~.

---

## Post 370 by @Catalyst2422 — 2025-08-15T08:43:37Z

> [@anon11657877](#):
>
> It’s already in plaintext on a piece of plastic anyways. Passwords aren’t.

So it’s ok to carry it with you in plaintext, but not store it in a password manager?

You seem to be more of a fan of security (and privacy) theatre than anything else. You also seem to like to only respond to the points others make that you think you have an argument against. Whilst conveniently ignoring the rest.

---

## Post 371 by @anon11657877 — 2025-08-15T14:37:55Z

Well you’re going to have to carry it with you whenever you go out. And besides, the topic here is _password_ managers, not _credit card_ managers.

---

## Post 372 by @anon48875053 — 2025-08-15T16:47:12Z

A proprietary password manager that is sitting on 1 billion dollars of VC funding is cockblocking a criteria change because it has a few nice-to-have features that FOSS competitors don’t YET have, absolute cinema.

Might as well remove the requirement sitewide, I have a lot of proprietary tools to suggest that are leagues better than the competition in terms of features and UX and the gap is a lot bigger than between 1Password and FOSS password managers, who cares about software freedom anyway.

---

## Post 373 by @anon48875053 — 2025-08-15T16:52:31Z

> [@fria](#):
>
> Honestly can we get a petition going for 1Password to open source their app, that would solve this whole thing.

Their VC investors probably wouldn’t be too happy about that one.

---

## Post 374 by @overdrawn98901 — 2025-08-15T21:04:09Z

> [@anon48875053](#):
>
> VC funding

Prepare to have your timbers be shivered with how [Bitwarden](https://pitchbook.com/profiles/company/399608-65#overview) receives funding.

---

## Post 375 by @overdrawn98901 — 2025-08-15T21:08:03Z

FOSS is a strategy for businesses in this domain. There is value proposition in open sourcing the code outside of consumer trust - to eat away at Bitwardens addressable market and bring users to use their system instead. It’s not out of the question, but that playbook likely won’t happen until FOSS cloud based alternatives actually compete on all of their features to where they need to consider such a move.

---

## Post 377 by @anon11657877 — 2025-08-15T23:41:05Z

> [@Remove 1Password](https://discuss.privacyguides.net/t/remove-1password/13921/54):
>
> A compiled list of reasons why 1Password shouldn’t be listed: Both the backend and the frontend are proprietary. Can only create email aliases with Fastmail, which is a paid service, so people are forced into another subscription. Which is intentional because you get -25% off when signing for Fastmail using the link provided by 1Password slight_smileEmbeds tracking pixels in its newsletters. No free plan. Doesn’t have any private payment methods. Has received $1 billion in VC funding. The …

---

## Post 378 by @Catalyst2422 — 2025-08-16T08:32:08Z

> [@anon11657877](#):
>
> Well you’re going to have to carry it with you whenever you go out. And besides, the topic here is _password_ managers, not _credit card_ managers.

But I also store my usernames in it but it isn’t called a _username_ manager

And addresses but it isn’t called an _address_ manager

And identity documents but it isn’t called an _identity document_ manager

You’re either very narrow-minded, or a troll, or both.

---

## Post 379 by @anon48875053 — 2025-08-16T10:22:41Z

They received one-tenth of 1Password while being fully open source and self-hostable.

---

## Post 380 by @overdrawn98901 — 2025-08-16T13:17:22Z

My point being both were VC funded. If the goalpost is now moved that some VC funding is OK, then I’m not qualified to make the call at how much money for what evaluation is a green light to not worry about it.

---

## Post 381 by @anon11657877 — 2025-08-16T15:03:58Z

Since cloud-based and local storage password managers have separate criteria, we should at least add open source as a minimum requirement for local storage password managers since all of those recommendations are currently FOSS.

PG should also have this warning above 1Password if everyone insists on keeping it.

> **Warning:** 1Password is closed source, meaning the source code is not freely available for anyone to audit. While we recommend against using closed source password managers…

Someone else can finish that warning. I know PG already mentions 1Password being proprietary, but it should be made more obvious.

---

## Post 382 by @Bhaelros — 2025-08-16T15:15:48Z

What about the frontend only open source software like Proton? Do you want to remove them too?

---

## Post 383 by @anon11657877 — 2025-08-16T17:09:20Z

Iirc PG never required open source for services, only software. The frontend/client is the software, the backend/server is the service. While I’d prefer open source server code, it’s not feasible to require that because then we wouldn’t only be removing 1Password, but every cloud-based password manager. I wouldn’t mind that but everyone else would.

> **[Bitwarden: Is it really foss?](https://isitreallyfoss.com/projects/bitwarden/)**

So Bitwarden and Proton Pass have open source clients and 1Password is completely proprietary.

KeePass should be the first recommendation then.

---

## Post 384 by @Bhaelros — 2025-08-16T17:37:32Z

So, what is the point of having an open source client app when you don’t know what is going on in the backend? If your concern is which data is submitted you can do it via sniffers or wireshark.

> [@anon11657877](#):
>
> While I’d prefer open source server code, it’s not feasible to require that because then we wouldn’t only be removing 1Password, but every cloud-based password manager

Yes, that is point. According to your requirements, every cloud based password manager must be removed but you hate only 1Password and others are exception.

---

## Post 385 by @fria — 2025-08-16T17:57:17Z

> [@Bhaelros](#):
>
> So, what is the point of having an open source client app when you don’t know what is going on in the backend? If your concern is which data is submitted you can do it via sniffers or wireshark.

Since these password managers are E2EE, it doesn’t matter so much what’s running on the server. You can’t verify what’s running on the server anyway so it wouldn’t really provide any tangible privacy or security benefit.

---

## Post 386 by @anonymous378 — 2025-08-16T18:32:56Z

It just seems like we are constantly moving the goal post with this criteria thread.

The original post is to require open source for password managers.

Now it seems like the thread actually contains a ton of different criteria change requests to @anon83428815 point

_require open source for password managers if there are enough available options_  
_require open source for password managers only for the software side of things_  
_require open source for password managers but make sure they have limited VC funding_

etc etc etc

For all the people in favor of this criteria, if you have to add a qualifier at the end of the criteria you are not advocating the criteria that was submitted. full stop.

It would be more then just 1Password that does not qualify as actually open source (not just partially open source) and would need to be removed. Which is probably the biggest no brainer reason, regardless of your thoughts on open source, to reject this criteria change. Re-submit it with a bit more nuance since its obvious its not what anyone actually wants.

---

## Post 387 by @anon11657877 — 2025-08-16T19:37:02Z

People want to keep forcing everyone to make exceptions and keep shouting crap like “Oh you want to remove 1Password? You must not want any options at all!” or “Oh you want to remove 1Password because it’s not open source? Okay we’ll remove Bitwarden too”. They also seem to forget that we think open source should be a requirement instead thinking we only care about 1Password.

---

## Post 388 by @anonymous378 — 2025-08-16T20:14:15Z

> [@anon11657877](#):
>
> They also seem to forget that we think open source should be a requirement instead thinking we only care about 1Password.

Just my opinion but I have strong doubts that if this passed and Bitwarden was also removed (which it would have to be) the reaction from most users would be highly negative.

I am surprised your taking that stance since you keep referring to how popular this post is and how its going to have the most comments while ignoring that without making those exceptions this would most likely be a wildly unpopular criteria. It seems like really only you and possibly @anon48875053 (same guy who wanted to [recommend NordPass](https://discuss.privacyguides.net/t/nordpass-password-managers/22705)) are willing to take the hardliner stance that this category should require open source no exceptions.

It’s really only a convincing criteria when you frame it as supporting FOSS and removing evil 1Password, while ignoring all the other implications.

I think if people look at the whole picture. This prefers Open Source stance PG has taken is a much more elegant solution. It still only ends up with 1 proprietary option, no need for exceptions, no need for absolutist criteria, and its highly unlikely any other proprietary PW manager ever makes it past community scrutiny again, while still keeping the mostly FOSS options that a large majority of users are happy with.

Even @jonah has said if 1Password wasn’t already recommended he doubts it would get recommended but removal is a higher bar.

---

## Post 389 by @anon11657877 — 2025-08-16T21:54:30Z

> [@anonymous378](#):
>
> It seems like really only you and possibly @Lukas (same guy who wanted to [recommend NordPass](https://discuss.privacyguides.net/t/nordpass-password-managers/22705)) are willing to take the hardliner stance that this category should require open source no exceptions.

And 42 other PG users on this forum.

> [@anonymous378](#):
>
> I think if people look at the whole picture. This prefers Open Source stance PG has taken is a much more elegant solution.

IIrc PG used to have a Open Source only stance until one security researcher decided FOSS didn’t matter at all, and next thing you know, “we recommend Microsoft Office because it supports MDAG”.

---

## Post 390 by @anonymous378 — 2025-08-16T22:34:19Z

> [@anon11657877](#):
>
> And 42 other PG users on this forum.

That number is dubious at best. Anyone can vote with both a regular account and anon account. It is also counting votes of inactive and deleted users. Its why votes dont have any bearing on these issues.

Also there are thousands of PG users. Do you really think 42 votes is a meaningful amount?

> [@anon11657877](#):
>
> PG used to have a Open Source only stance until one security researcher decided FOSS didn’t matter at all, and next thing you know, “we recommend Microsoft Office because it supports MDAG”.

You have a terrible habit of taking a normal situation, such as PG changing a criteria over time, and extropaliting the least likely outcome such as “we recommend Microsoft Office because it supports MDAG”. Its an absurd argument.

---

## Post 391 by @anon83428815 — 2025-08-16T22:46:00Z

> [@anon83428815](#):
>
> I don’t want to go so far as to label @Privium a troll

> [@Valynor](#):
>
> Trolling the PG forums because you cannot have your way will not change anything for the better @Privium so please refrain from such behaviour.

My bad… I should of listened to @mika and @overdrawn98901:sweat_smile:

---

## Post 392 by @anon11657877 — 2025-08-16T22:54:03Z

This is now the most replied topic in this forum’s history.

> [@anonymous378](#):
>
> You have a terrible habit of taking a normal situation, such as PG changing a criteria over time, and extropaliting the least likely outcome such as “we recommend Microsoft Office because it supports MDAG”. Its an absurd argument.

Well they used to recommend Office for Windows users, didn’t they?

---

## Post 393 by @Valynor — 2025-08-16T23:00:46Z

**Please stay on topic.**

If you don’t have anything constructive to add it’s best to take a step back and cool off and come back to the discussion another day.

---

## Post 394 by @anon11657877 — 2025-08-16T23:05:14Z

> [@LastPass Password Manager](https://discuss.privacyguides.net/t/lastpass-password-manager/30119/6):
>
> Trolling the PG forums because you cannot have your way will not change anything for the better @Privium so please refrain from such behaviour.

Obviously it was a joke. Everyone here kept calling me a “troll” so I showed them what a “troll” really is.

> [@LastPass Password Manager](https://discuss.privacyguides.net/t/lastpass-password-manager/30119/5):
>
> The links you put are external links to this forum **and are not related with the statement**.

Of course they aren’t. Most of the links I put **contradict** LastPass, the LAST PASSword manager I’d ever want to use.

---

## Post 395 by @Stiffly2505 — 2025-08-17T02:55:29Z

I’d like to point out that this requirement would’ve removed BitWarden for about half a year, during which a mandatory dependency of all their clients was not open-source. Read more in the F-Droid GitLab issue: [Bitwarden Password Manager (#114) · Issues · F-Droid / Requests For Packaging · GitLab](https://gitlab.com/fdroid/rfp/-/issues/114)

Just on the account of that I have to disagree with this idea.

---

## Post 396 by @anon11657877 — 2025-08-17T14:01:03Z

> [@Stiffly2505](#):
>
> I’d like to point out that this requirement would’ve removed BitWarden for about half a year, during which a mandatory dependency of all their clients was not open-source.

Fine with me.

---

## Post 398 by @dngray — 2025-08-17T15:24:49Z

> [@Stiffly2505](#):
>
> I’d like to point out that this requirement would’ve removed BitWarden for about half a year, during which a mandatory dependency of all their clients was not open-source

Wasn’t that related to Xamarin which they don’t use anymore?

> [@anon11657877](#):
>
> Fine with me.

Not contributing anything useful to the thread.

---

## Post 399 by @Stiffly2505 — 2025-08-17T16:03:38Z

No, it’s related to their own SDK package: [Desktop version 2024.10.0 is no longer free software · Issue #11611 · bitwarden/clients](https://github.com/bitwarden/clients/issues/11611)

---

## Post 400 by @anon11657877 — 2025-08-17T19:50:25Z

Bitwarden’s not being open source is another reason KeePass is preferable. Why isn’t it the top recommendation? Because local storage isn’t convenient enough?

Cloud storage = convenience  
Local storage = privacy and security

And some people get mad at us for recommending things for “weird ideological reasons”.

And the very idea 1Password is more private because it’s been audited more times is like saying NordVPN is more private than Tor because it’s been audited more times.

> > **off-topic**
> >
> > The only issue with KeePassXC is it still has network access which can be a security issue. If you’re using Debian (most people here probably don’t for obvious reasons), you can install the `keepassxc-minimal` package which only includes the bare minimal functionality and no network access or browser integration. For other Linux distros, you can compile from source without networking code.
> > 
> > [Documentation and FAQ – KeePassXC](https://keepassxc.org/docs/#faq-security-network)

---

## Post 401 by @dngray — 2025-08-18T16:24:23Z

These serve different purposes, and in a lot of cases people are terrible simply at backing things up. Any benefits of local storage are quickly thrown out the window when said person loses their database because of some mishap. That and also there are simply more devices in general, tablets, phones, computers, where keeping in sync is necessary.

There also simply isn’t a significant loss of privacy for a password manager that has cloud storage if the crypto in the client is sound.

---

## Post 402 by @anon11657877 — 2025-08-18T17:27:19Z

> [@dngray](#):
>
> there are simply more devices in general, tablets, phones, computers, where keeping in sync is necessary.

Anyone can connect their phone to their computer with USB and transfer their password database from one device to another. It’s not that hard to make backups.

It’s not much different than creating strong passwords but the higher-ups have spoken. No password is safe anymore no matter how strong or random it may be and we must ditch passwords at all costs in favor for passkeys.

- [Are Passkeys really the beginning of the end of passwords? I certainly hope not!](https://unixdigest.com/articles/are-passkeys-really-the-beginning-of-the-end-of-passwords-i-certainly-hope-not.html)

Some of this information might be outdated. There may be open source solutions for passkeys now.

> My password is mine. I control my password. I own my password. I am not dependent upon some third party closed proprietary operating system or device to handle my security.

> Thus the FIDO2 Passkey implementations still heavily rely on proprietary software embedded into Apple, Google, Microsoft, and others’ devices and solutions. The general strategy results in Big Tech creating and overseeing the key storage. There are no open source software implementations for creating and exchanging keys.

> Even if alternative open source solutions appear, most users will most likely just use the solutions from Big Tech as they do with everything else - which is what is expected.

> Passkeys also makes you more vulnerable to seizures of electronics and keys. Forcing someone to give up a password is considered a violation of the Fifth Amendment to the United States Constitution by courts in the United States. Forcing someone to unlock biometrically secured devices is entirely legal.

> Possession-based systems rely on items, such as a smartphone, that can be misplaced, stolen, or damaged, potentially locking users out of their accounts. And when it happens to you, Google will let you know that they reserve the right to terminate your account for any reason or no reason at all.

> The tech industry and the tech press need to face the fact that they have yet again been swept off their feet by Big Tech hype and are now causing massive migrations to this crap!

---

## Post 403 by @Bhaelros — 2025-08-18T17:36:42Z

> [@anon11657877](#):
>
> Anyone can connect their phone to their computer with USB and transfer their password database from one device to another. It’s not that hard to make backups.

Not everyone is using a computer. Any task which requires manual action lowers the security due to human factor

---

## Post 404 by @dngray — 2025-08-18T17:37:03Z

> [@anon11657877](#):
>
> Anyone can connect their phone to their computer with USB and transfer their password database from one device to another. It’s not that hard to make backups.

… and yet people don’t, and then realize they should have. These are all failure points.

> [@anon11657877](#):
>
> It’s not much different than creating strong passwords but the higher-ups have spoken. No password is safe anymore no matter how strong or random it may be and we must ditch passwords at all costs in favor for passkeys.

There will always be passwords at some point because of how basic they are, and I doubt banking is going to want to be reliant on other companies for authentication as an example.

---

## Post 405 by @anon11657877 — 2025-08-18T19:20:54Z

> [@dngray](#):
>
> There will always be passwords at some point because of how basic they are

I hope so. The problem isn’t passwords itself but everyone failing to create strong passwords, using password managers. Instead of enforcing passkeys they should have kept promoting 2FA and encouraging users to use that (but not mandate it).

> Of course all of this requires a reliable and modern computer or smartphone which makes Passkeys inaccessible to the poor, underprivileged, or anyone who does not own or operate a capeable device.

This also applies to cash vs digital.

> I would rather have a piece of paper with all my passwords written down, stored in a drawer at home, than have Google, Apple, or Microsoft handle anything regarding security for me!

Passwords are one of the few things I would **not** write down on paper. Something as sensitive at that shouldn’t be stored unencrypted because as soon as someone gets a hold of that paper I’m done for.

---

## Post 406 by @dngray — 2025-08-18T19:25:43Z

> [@anon11657877](#):
>
> > Of course all of this requires a reliable and modern computer or smartphone which makes Passkeys inaccessible to the poor, underprivileged, or anyone who does not own or operate a capeable device.
> 
> This also applies to cash vs digital.

I don’t think there’s much worry about that, i mean as long as they can afford a phone and the poorest of the poorest countries have people who can afford a phone.

If Apple and Google support such features in their base APIs then it will be supported by all flavored OSes based on these.

> [@anon11657877](#):
>
> > than have Google, Apple, or Microsoft handle anything regarding security for me!
> 
> Passwords are one of the few things I would **not** write down on paper. Something as sensitive at that shouldn’t be stored unencrypted because as soon as someone gets a hold of that paper I’m done for.

Agreed, and also the fact simply comes now it has zero physical protection. It’s worse than biometrics because at least someone has to go to the effort of chopping off your finger, or forcing you to comply - you least get the opportunity to know about it.

---

## Post 407 by @anon11657877 — 2025-08-20T18:20:54Z

> **[1Password hits the fan | BryceWray.com](https://www.brycewray.com/posts/2021/08/1password-hits-fan/)**
>
> An Electron-ic firestorm: a follow-up to my earlier article about password management.

---

## Post 408 by @anonymous378 — 2025-08-20T18:26:11Z

That article just turned 4 years old :birthday_cake:

---

## Post 409 by @anon11657877 — 2025-08-20T19:53:00Z

Here’s a new one.

**TL;DR:** All of the major cloud-based password managers suffered a serious vulnerability. Proton Pass has already fixed it and Bitwarden soon will. 1Password and LastPass don’t care. KeePass is unaffected :smiley: .

> [@Zero-Day Clickjacking Vulnerabilities in Major Password Managers](https://discuss.privacyguides.net/t/zero-day-clickjacking-vulnerabilities-in-major-password-managers/30278):
>
> Hey y’all waving_hand First post on Privacy Guides. And not a small one. (If you saw my first attempt, I may have triggered the spam filter by mistake - mods, you can delete my first hidden thread) Long story short: if you’re using a password manager with a browser extension, your data might (have) be(en) at risk. A security vulnerability has been discovered in many popular password managers, including 1Password, Bitwarden, Dashlane, EnPass, iCloud Passwords, Keeper, LastPass, LogMeOnce, No…

---

## Post 410 by @anonymous378 — 2025-08-20T20:02:12Z

> [@anon11657877](#):
>
> Bitwarden soon will

> Do you think that stealing a payment card or personal data with a single click is a high severity issue?  
> Bitwarden sees this vulnerability slightly differently. Maybe it could be reason why it was not fixed even after more than 4 months.

Where was this in your tldr? Its like you choose to only highlight the bad parts of programs you don’t like, it is as if you have an agenda…

---

## Post 411 by @anon11657877 — 2025-08-20T20:05:40Z

> If you’re using Bitwarden, an update (2025.8.0) is coming later this week.

> The thing is that this vulnerability, relying on clickjacking (but not only), has been fixed by many other password managers like Proton, NordPass, Dashlane, etc.
> 
> This means that this specific issue is fixable. And both 1Password and LastPass have concluded that it was not critical enough to fix. I’ll let you be the judge on this, but as a long time 1Password customer, I feel betrayed and outraged at how they are dealing with this.

---

## Post 412 by @anonymous378 — 2025-08-20T20:07:18Z

avoidance again. The point is 1Password isn’t the only manager playing fast and loose here but you don’t want that smoke when its a precious FOSS program.

Anyway this is off topic, and should really be discussed in the thread you link.

---

## Post 413 by @anon11657877 — 2025-08-20T20:09:50Z

At least Bitwarden is going to make a fix soon while 1Password isn’t. Turns out 1Password isn’t as competent as everyone here thought.

> [@anonymous378](#):
>
> Anyway this is off topic, and should really be discussed in the thread you link.

We’re discussing the removal of 1Password and the requirement of open source for password managers aren’t we?

---

## Post 414 by @anonymous378 — 2025-08-20T20:11:43Z

> [@anon11657877](#):
>
> We’re discussing the removal of 1Password and the requirement of open source for password managers aren’t we?

Yeah but both [this issue](https://discuss.privacyguides.net/t/zero-day-clickjacking-vulnerabilities-in-major-password-managers/30278) and the [removal of 1Password](https://discuss.privacyguides.net/t/remove-1password/13921) are separate topics with their own threads.

> [@anon11657877](#):
>
> 1Password and LastPass don’t care. KeePass is unaffected :smiley: .

> **[About the security of 1Password Autofill in your browser | 1Password Support](https://support.1password.com/browser-autofill-security/)**
>
> Learn how 1Password protects your information when you autofill using 1Password in your browser.

---

## Post 415 by @anon11657877 — 2025-08-20T20:46:58Z

> [@anon11657877](#):
>
> At least Bitwarden is going to make a fix soon

Bitwarden just released their fix. 1Password still hasn’t.

---

## Post 416 by @anon12308796 — 2025-08-20T21:39:40Z

Not sure this adds much to this already very long thread but I am in favour of this proposal.

I think recommending proprietary tools makes sense in categories where there are not many trusted open source options but in the password manager section we do now have multiple options and I can’t see any reason not to raise the minimum bar.

Open source is not a silver bullet but its hard to argue it is not preferable over proprietary options. I think requiring this now and slightly changing our recommendations is a good thing as it shows things are improving generally in this category.

(I also think the page should encourage keepass and local password managers over cloud ones if the user is more technically inclined but that’s a different topic)

---

## Post 417 by @Natha — 2025-08-20T22:00:02Z

Cloud password managers are a life saver for anyone dealing working in complex business and hundreds, if not thousands, of passwords. Alas, a local KeePass is almost always better in a case of a public vulnerability like the one I shared in the other thread.

That being said, I won’t lie that I don’t feel comfortable using 1Password anymore. Unless they take care of the matter in a radically different way, this is a breach of trust. Not really compatible with a password manager or any other kind of security oriented app.

Meanwhile, you do have open sourced alternatives likes Bitwarden and Proton Pass that are taking care of things in a transparent way. Proton definitely won this time tho, as Bitwarden took 4 freaking months to fix the vulnerability… So, yeah. I have the feeling that Proton is on the right path to become the new go to.

---

## Post 418 by @Bhaelros — 2025-08-21T05:57:32Z

Official reply from 1P

Hi all,

Thanks for all the questions and the thoughtful discussion. We wanted to provide a bit more context about the research and what it means for 1Password users.

A researcher identified a variation of a clickjacking attack, where a malicious website can trick someone into unknowingly triggering the autofill action in a browser extension. They reported the issue through our bug bounty program and worked with us ahead of their DEF CON presentation.

Clickjacking is not unique to the 1Password browser extension. It is a long-standing web attack technique that affects websites and browser extensions broadly. The underlying issue lies in the way browsers render webpages. After conducting a thorough review, including prototyping potential mitigations, we concluded there’s no comprehensive technical fix that browser extensions can deliver on their own.

Your information in 1Password remains encrypted and protected. Clickjacking does not expose your 1Password data or export your vault contents, and no website can directly access your information without interaction with the browser extension’s autofill element. At most, a malicious or compromised webpage could trick you into autofilling one matching item per click, not everything in your account.

We take this and all security concerns seriously, and our approach to this particular risk is to focus on giving customers more control. 1Password already requires confirmation before autofilling payment information, and in our next release, which is already shipped and undergoing review from the browser extension stores, we’re extending that protection so users can choose to enable confirmation alerts for other types of data. This helps users stay informed when autofill is happening and in control of their data.

On the question of disabling autofill: while it might feel safer, it can actually create more risk. Without autofill, people are more likely to reuse weak passwords or copy and paste credentials into websites, where they can still be stolen if the site is malicious. Autofill also protects you against phishing sites by only working on the exact domains your credentials are saved for. In practice, for the majority of users, we believe the risk of disabling autofill is greater than the risk of clickjacking.

Passkeys are not impacted by clickjacking. Passkeys are tied to the website they’re created on and generate a one-time signature during login. That means no reusable secret is ever exposed, and even if someone tried clickjacking, there’s nothing permanent to steal.

We’re preparing a security advisory that will share more details soon.

> **[Reddit - The heart of the internet](https://www.reddit.com/r/1Password/comments/1muxnye/comment/n9stm5j/?context=3&share_id=W8cbhIJd53ZIyeDorW9bg&utm_content=1&utm_medium=ios_app&utm_name=ioscss&utm_source=share&utm_term=1)**

---

## Post 419 by @anon37002130 — 2025-08-21T10:38:35Z

> “It’s the opinion of the Socket Security Team that, if this is the case, the mitigations currently implemented by other password managers may also be bypassable.”  
> [https://socket.dev/blog/password-manager-clickjacking#:~:text=It’s%20the%20opinion%20of%20the%20Socket%20Security%20Team%20that%2C%20if%20this%20is%20the%20case%2C%20the%20mitigations%20currently%20implemented%20by%20other%20password%20managers%20may%20also%20be%20bypassable](https://socket.dev/blog/password-manager-clickjacking#:~:text=It%E2%80%99s%20the%20opinion%20of%20the%20Socket%20Security%20Team%20that%2C%20if%20this%20is%20the%20case%2C%20the%20mitigations%20currently%20implemented%20by%20other%20password%20managers%20may%20also%20be%20bypassable).

> # 
> 
> > **Discussion with 1Password Quote:**
> >
> > # **Discussion with 1Password**
> > 
> > After filing the request for CVE numbers with US-CERT the Socket Security Team reached out to the impacted password manager vendors to alert them about the pending CVE assignment. At time of publication, only 1Password responded.
> > 
> > On a call between the 1Password and Socket Security Team, 1Password explained that the mitigations proposed by Tóth could be trivially bypassed, and that the only way to mitigate the vulnerabilities fully would be to implement a dialog popup to prompt the user before autofilling. **It’s the opinion of the Socket Security Team that, if this is the case, the mitigations currently implemented by other password managers may also be bypassable.**
> > 
> > 1Password stated they considered this dialogue popup solution, and implemented it for credit card fields, but opted-not to implement this for PII due to user feedback, according to the H1 triage logs with Tóth:
> > 
> > > **Security and usability are a balance, one that we are always making tradeoffs back and forth to find the right solution. Sometimes there is no perfect solution, only the solution that works best for the most users. As I mentioned previously, it is only with user feedback that we chose to remove the prompt for the PII items that would prevent clickjacking from occurring. A change that we’ve documented in the support article under the "Identity alerts” section.**
> > 
> > As of the time of publication, 1Password has chosen not to provide an official statement to the Socket Security Research team about Tóth’s research.
> > 
> > While it is easy to assume vendors are simply ignoring these vulnerabilities, the reality is more complicated. Mitigating DOM-based clickjacking in a way that is both robust and frictionless for end users is a technically difficult challenge. The most straightforward solution, adding confirmation dialogs before autofilling, does introduce usability friction that some users may push back on. Password managers walk a tightrope between security and usability, and choices about which safeguards to enforce ultimately reflect product decisions about that balance. That said, the research highlights that what’s convenient for users in the short term can leave them exposed to systemic risks that attackers may exploit.

There is a fix it is in settings:

 ![IMG_20250821_112209_069](https://forum-uploads.privacyguidesusercontent.com/original/2X/2/2196ae09e249bf57123e230613675a110404e7dc.jpeg)

> “The most straightforward solution, adding confirmation dialogs before autofilling, does introduce usability friction that some users may push back on. Password managers walk a tightrope between security and usability, and choices about which safeguards to enforce ultimately reflect product decisions about that balance. That said, the research highlights that what’s convenient for users in the short term can leave them exposed to systemic risks that attackers may exploit.”  
> [https://socket.dev/blog/password-manager-clickjacking#:~:text=The%20most%20straightforward,attackers%20may%20exploit](https://socket.dev/blog/password-manager-clickjacking#:~:text=The%20most%20straightforward,attackers%20may%20exploit).

It is just not on by default.

---

## Post 420 by @anonymous378 — 2025-08-21T16:21:21Z

> [@Natha](#):
>
> I won’t lie that I don’t feel comfortable using 1Password anymore. Unless they take care of the matter in a radically different way, this is a breach of trust.

> [@anon11657877](#):
>
> 1Password and LastPass don’t care.

The lack of doing anything by 1Password is much worse then I had originally thought.

> [@anon37002130](#):
>
> **It’s the opinion of the Socket Security Team that, if this is the case, the mitigations currently implemented by other password managers may also be bypassable.**

I do wonder if other PMs providing “fixes” that will be bypassed (if 1Password is correct) isn’t much more then security theater that gives users a false impression that they are now safe from clickjacking attacks.

> **Note**
>
> There are multiple threads that all seem to be about 1Password at the moment, so please forgive me if this should be moved to a different one.

---

## Post 421 by @Natha — 2025-08-22T00:42:29Z

> [@anonymous378](#):
>
> I do wonder if other PMs providing “fixes” that will be bypassed (if 1Password is correct) isn’t much more then security theater that gives users a false impression that they are now safe from clickjacking attacks.

You’re not the only one wondering what their own fix is all about. A few users (me included) asked Proton for more details.

---

## Post 422 by @Natha — 2025-08-22T00:44:06Z

I’ve posted an update for the 11 password managers mentioned: [Zero-Day Clickjacking Vulnerabilities in Major Password Managers - #25 by Natha](https://discuss.privacyguides.net/t/zero-day-clickjacking-vulnerabilities-in-major-password-managers/30278/25)

---

## Post 423 by @Stiffly2505 — 2025-08-24T17:15:48Z

Not just “cloud-based”, it affects any that provide autofill within a browser as a plugin. I’d argue about the severity of it too, the precondition of exploiting this is having the website already compromised. That is, they could already steal your password if you logged in, the vulnerability just allows the site to retrieve the password assigned to it without you explicitly logging in. In my books this is in no way above a “medium” at most. If a website is compromised, you should assume the password is also compromised, and rotate it.

---

## Post 424 by @Natha — 2025-08-24T18:10:29Z

The thing is that it isn’t just about logins. It’s also about credit cards and identities stored in these password managers.

Cache poisoning is still a thing, the overlay exploit (mentioned by the researcher who found the vulnerabilities) could fool anyone, hijacked domains do happen, etc.

Yes, it’s not exclusive to password managers. Any web browser extension capable of auto filling personal data is at risk. Yes, password managers aren’t able to “fix” this completely. The Chromium and Mozilla team should be involved as well. And there will always be the real risk of facing a comprised website. Something that only the website owner will be capable to fix

Should they just pretend that it’s fine and wait for an online outcry to introduce a simple on/off button that allows their users to adapt the protection level to their threat model? No.

If there’s something that can be fixed, in a piece of software like a password manager, it should be fixed. No question asked. If there’s a security issue, a leak, anything impacting the safety of a safety-focused software, it should be the top priority for these developers to at least mitigate the risks.

---

## Post 425 by @mangomango — 2025-08-24T21:14:03Z

I am in favor of this proposition.

Open-source is not a magic thing that makes programs secure. As do audits.

However, there are reasons to think that the open-source PM we recommend are well tested and reviewed, in addition to their audits.

I think that the apps we recommend that do client-side encryption should be open-source, especially when managing very sensitive files (logins). So we can look at the encryption they use, etc. This can be a great sign of trust (as with KeePass, Bitwarden, Proton Pass, …).

If 1Password has unique features useful to 1% of PM users that no password manager with open-source clients have, I think that this shouldn’t be a reason to recommend it. Because it is not FeaturesGuide. Our policy is to prefer open-source in general when available. I find that the features that are unique to 1P are pretty niche. We CAN recommend alternatives to close-source products even if they are not equal in term of features (Apple Photos, Google Maps) ! Lacking some features is balanced by the trust that open-source can provide.

---

## Post 426 by @Stiffly2505 — 2025-08-25T03:51:15Z

> [@mangomango](#):
>
> So we can look at the encryption they use, etc.

Why would this require open-source? You can do this with source-available as well, like how Bitwarden was for multiple months. I’m sorry but I haven’t seen a single convincing argument so far why open-source is better for privacy, and your post contains none either.

---

## Post 427 by @saphypbe — 2025-08-25T17:26:22Z

I recently realized that Strongbox is dead, hence there is no alternative for iOS when it comes down to open source alternatives.

Self-hosted vaultwarden in a browser is the only way now?

---

## Post 428 by @xe3 — 2025-08-25T18:41:02Z

> [@saphypbe](#):
>
> there is no alternative for iOS when it comes down to open source alternatives.

Are you specifically talking about _non-cloud based_ password managers and _fully open source_ (client + server)?

---

## Post 429 by @saphypbe — 2025-08-25T20:06:02Z

Yes, something as simple as Keepass but for iOS where I would then manage my own thing locally while being open source. I feel like there is no good option, only a local network hosted Vaultwarden looks fitting.

---

## Post 431 by @Tux — 2025-08-25T20:16:22Z

How is this even a question? FOSS should be required in all categories of software. Proprietary software can’t be trusted; it’s either malware or it’s potentially malware.

Source available also isn’t enough. You must be able to trust the build process. With FOSS, you can reasonably trust Linux package maintainers or build yourself from source.

Regarding password managers, nothing that has a third party cloud component can be trusted. The only cloud that is acceptable is my own. As I like minimal setups, I simply host my Keepass DB on my Samba server, and access it remotely via a Wireguard tunnel.

---

## Post 432 by @anon61753997 — 2025-08-25T22:18:24Z

> [@mangomango](#):
>
> I think that the apps we recommend that do client-side encryption should be open-source, especially when managing very sensitive files (logins). So we can look at the encryption they use, etc. This can be a great sign of trust (as with KeePass, Bitwarden, Proton Pass, …).

I just want to point out that Bitwarden is technically not open-source but source-available. They have [an unusually long-winded FAQ](https://github.com/bitwarden/server/blob/a4c4d0157bff55cc665518cda6afec53943e89c5/LICENSE_FAQ.md) just for this. Everything in the bitwarden\_license folder on [the client side](https://github.com/bitwarden/clients) is only source-available.

I know I’m nitpicking, but I can see someone in the future request removing Bitwarden because of this. I’m also expecting this thread will be dragged out long into the future because for some people, open-source is an ideology.

---

## Post 433 by @saphypbe — 2025-08-26T14:29:00Z

Agreed on the self-hosted VPN-accessible part.  
Less sure about the open source/source available one.  
If the code running is visible publicly, I’m not sure you need to specifically have the open-source part to it. If the maintainers are aware and fix the issue by themselves, you probably don’t need to directly contribute.

SQLite is doing exactly that and it works just fine.

> With FOSS, you can reasonably trust Linux package maintainers or build yourself from source.

Trusts is another topic entirely and nothing protects you from having a webdev going _rogue_ and messing up the FOSS code as it quite happened a few times in the past recently. It can even happen during the build process/etc.

---

## Post 434 by @Tux — 2025-08-27T06:07:33Z

Open source isn’t just an ideology—it’s a necessity if you want to be reasonably sure that software behaves as promised. Without access to the source code, you’re relying on blind trust.

---

## Post 435 by @Tux — 2025-08-27T06:10:40Z

SQLite is “public domain,” which is even less restrictive than the typical FOSS licenses (GPL, MIT). And rogue developers are clearly more of a problem in the proprietary world where their actions are much more likely to go unnoticed. In fact, it is fair to say that Microsoft, Apple, and Google are rogue developers, since they mistreat their users.

---

## Post 436 by @saphypbe — 2025-08-27T06:37:31Z

Very true.

My point is that if:

- the code you’re running on your device/app is publicly available
- all of it is buildable from the source
- has been reviewed by some trustworthy 3rd party
- company has a sustainable business

Then I don’t think that there is any red flag to be considered and could then be safe enough to use.  
You don’t need the project to be MIT (or wider licence) + accepting Pull Requests etc to be acceptable from a trust perspective. That’s just cherry on the cake.

---

## Post 437 by @Stiffly2505 — 2025-08-27T07:15:18Z

But open sourceness is not required for access to source code. That’s the whole point of the post you replied to. Source-available is exactly what it says, access to source code. Please provide a reason why open source is better for privacy than source available.

---

## Post 438 by @U53R — 2025-08-27T14:13:10Z

Voted for.

Reason: in SOME situations (like if you are journalist) you can be in risk, so even proprietary server will be bad (unlikely)

But for general usage, proprietary products that cannot be built by user is just “trust me bro” thing. Even if there are audits (once again it is “trust me bro” but this time to auditor because no code - no proof).

And we have no proof that there is no something backdoored by govs and forbidden to disclose (for example story with Anom messager)

---

## Post 439 by @anonymous378 — 2025-08-27T15:35:44Z

Since I am seeing it more in these recent comments, I would be interested in having some clarification by @jonah on how this criteria would be interpreted if approved.

I had always assumed this would, functionally, only affect the 1Password recommendation but since others have mentioned other PMs not being “fully” open source, I am a bit unsure about what the affect on other recommendations would be.

---

## Post 440 by @Tux — 2025-08-28T03:46:39Z

On the surface, source-available software may seem sufficient. However, depending on how the license is worded, you might still be unable to freely build and redistribute the software. This means that neither you nor any third parties you trust may be able to compile it for themselves. (An example of this is Unreal Engine: it’s source-available, but it’s clearly non-free.) Additionally, without a true FOSS license, the product can effectively be reverted to a proprietary model at any time, leaving users effectively trapped.
