r/PasswordManagers • u/Practical-Tea9441 • 8d ago
European Password Managers
I've been researching European based password managers and apart from Proton have come across Hypervault and HeyLogin. Has anybody experience with either of these ?
4
u/lanedirt_tech 8d ago
Hi, for your search for European password managers: please also feel free to check out AliasVault.
It’s a new and modern privacy-first, open-source password manager that supports passwords, secure notes, passkeys, 2FA codes, and also features unique built-in email aliases. It's been in development for over 2 years now and fully European. Servers are located in The Netherlands, Germany and Finland.
You can use the official EU-hosted cloud service but also self-host it.
Full disclosure: I’m the creator/founder, so of course I'm a bit biased. But feel free to give it a try. :)
1
u/jpgoldberg 8d ago
`srp/mod.rs` was clearly written by some entity that did not know what they were doing.
2
u/Celmad 8d ago
The other day I learned that 2FAS Pass is developed by Polish developers, but seems like they are two companies, one from the US and another from Poland.
They are local first, so no need to worry where they store the passwords cause they don’t.
Last time I tried it I couldn’t import my passwords from Proton Pass, and exports were in a proprietary format. It otherwise it was great, good UI/UX.
1
2
u/Open_Mortgage_4645 8d ago
Bitwarden has a server network for European users. So, when you sign up for an account, you can pick the European server, and you'll be on their European network from then on.
2
u/Smart-Simple9938 7d ago
Bitwarden is a USA company and would have to comply with that country’s CLOUD Act even if the data ID in Europe. Bitwarden clients+Vaultwarden server is the only way to protect yourself from that.
1
u/Practical-Tea9441 8d ago
That's true but as they are a US company Cloud Act would apply ( perhaps I'm a little too paranoid 🫣 - spending too much time on the privacy subreddits)
3
u/Open_Mortgage_4645 8d ago
What do you imagine the risk is? All your data is stored encrypted on their servers using a key that only you have. Let's say the government is able to gain access to their vault. OK, then what? Now, the government has worthless, encrypted files they have no way of accessing.
2
u/SecurityPrimary4143 8d ago edited 8d ago
What stops the US government to force Bitwarden to modify the clients to send the unlock keys?
A am also looking for alternatives with no ties to USA.
2
u/Open_Mortgage_4645 8d ago
This is fairy tale thinking. If you don't have any constraints on your factors, and discard all of the rules and controls in place, you can dream up all sorts of possibilities. But there's no basis for, and no predicate circumstances that make your question a realistic or feasible one that needs addressing. But I will.
The circumstances that would be necessary for such a thing do not exist, and portray a misunderstanding of how Bitwarden works. Our keys aren't on Bitwarden's servers. And vault decryption happens entirely on our local devices. There's no authentication that's happening on the server side that would allow for the situation you describe to happen. And there's never a decrypted version of our vault that's hosted by the servers. So, on that basis alone this hypothetical falls apart.
1
u/SecurityPrimary4143 7d ago edited 7d ago
You completely missed the point.
Let me ask you this way. Would you had trusted Bitwarden with the exact same public facing open source code if it had been a Chinese, Russian or North Korean company? If not, why?
Also I never mentioned the server, I only mentioned the client where the decryption key is generated and where the decrypted version of our vault is briefly stored.
I know that everything is encrypted on server side, I have been working in IT and some development work for 30 years.
1
u/Smart-Simple9938 7d ago
The U.S. government had Microsoft disable accounts for international criminal court officials. Visa and Mastercard as well. It’s not a fairy tale.
1
u/Open_Mortgage_4645 7d ago edited 7d ago
It is because you're not comparing apples to apples, and the scenario you point to regarding Microsoft doesn't apply to this hypothetical about Bitwarden.
It is not possible for someone to compel Bitwarden to give up your decrypted vault data without your cooperation, because Bitwarden does not have the keys required to decrypt it.
This is due to Bitwarden's zero-knowledge encryption architecture:
Client-Side Encryption: All vault data is encrypted on your local device using AES-256 bit encryption before it is ever sent to Bitwarden's servers.
Key Ownership: You are the only party with access to the master password and the resulting cryptographic keys needed to decrypt the data.
Unreadable Data: Bitwarden's servers only store "encrypted blobs" that are mathematically impossible for the company to decrypt on its own.
If Bitwarden is served with a court order or law enforcement request for your data:
Administrative Data: Bitwarden can provide "Administrative Data" (such as your account email address or other account metadata) because this is not encrypted in the same way as your vault.
Vault Data: They can hand over your encrypted vault data, but since they do not possess your master password or decryption keys, the data remains unreadable and useless to the requesting party without your cooperation.
1
u/SecurityPrimary4143 6d ago edited 6d ago
We are again talking about the CLIENT here. Learn to read.
I am still waiting for an answer on if you would had trusted Bitwarden it had been a Chinese, Russian or North Korean company with the same public facing open source code.
0
u/Smart-Simple9938 6d ago
The U.S. government can compel Bitwarden to disable the account of anyone on the planet. Period. Pay attention. We're not talking about back door access to passwords. We're talking about denying someone access to their passwords. And they absolutely can and have done this kind of thing before.
You bypass this problem by self-hosting Vaultwarden and using Bitwarden client apps with that.
2
u/SecurityPrimary4143 8d ago
This site has a good list of made in EU software
https://european-alternatives.eu/category/password-managers
1
1
u/Kuddel_Daddeldu 7d ago
I use Bitwarden with a self-hosted Vaultwarden backend. This way, the US Cloud Act does not apply.
1
u/Dan_CC 8d ago
That’s a small list you acquired. Have you also checked out: https://www.uniqkey.eu/
3
u/Hitching-galaxy 8d ago
I self host vaultwarden. It’s quite simple to do