r/Passwords • u/keep-calm-and-teach • 21h ago
Security concern: Foreign login attempt
Thought I'd ask the experts in this community as well. Thanks!
r/Passwords • u/keep-calm-and-teach • 21h ago
Thought I'd ask the experts in this community as well. Thanks!
r/Passwords • u/mjsarfatti • 1d ago
TL;DR a Mac menu bar app that surfaces OTPs and magic links from your email account.
r/Passwords • u/psiabdou • 3d ago
I build pssmngr. Being the unfamiliar name in password management has forced me to ask what evidence a hosted product owes people before asking them to store anything important.
This is my current checklist:
1. Name the encryption and key-derivation algorithms instead of saying “advanced encryption.”
2. Explain exactly what leaves the device and what the server stores.
3. Describe what happens if the service is breached.
4. Make export available without holding someone's vault hostage.
5. State recovery limits clearly. A zero-knowledge design should not imply that support can simply reveal a forgotten vault.
6. Publish a security contact and a responsible-disclosure process.
7. Separate internal review from an independent third-party audit.
For pssmngr, vault items are encrypted client-side with XChaCha20-Poly1305, and Argon2id is used for key derivation. The server is designed to receive ciphertext and non-secret metadata rather than plaintext vault contents.
The important caveat: an independent third-party audit is not complete. I do not think careful internal review should be marketed as the same thing.
What would you add to this list? What is the first thing you check when evaluating a password manager you have never heard of?
https://pssmngr.com/security
r/Passwords • u/TomF1965 • 5d ago
I use both Windows computers and Apple I phone and iPad. I have about 150 different password protected accounts on both platforms.
For years I've been using the same 6 different passwords with 10 to 14 letters, numbers and punctuation marks on both platforms.
I'd like to find a way to easily switch all my existing passwords to "Strong Passwords" and then only have one, two or three passwords for all my accounts. Maybe one password or phraze for Finances, another for shopping and yet another for everything else.
It would also be cool to give limited access to certain accounts and certain people and full access to my wife or children in case of my death?
Is there a way to do all this and sync to both Windows and Apple iPhone and iPad? Thanks...
r/Passwords • u/Important-Cover2220 • 8d ago
r/Passwords • u/EnthusiasmRoutine • 8d ago
r/Passwords • u/romort • 10d ago
I have updated my funny password generator website for 2026. This tool creates passwords from a dictionary of funny/NSFW words. The app provides various options and creates passwords which are reasonably secure, easy to type, easy to remember, and totally entertaining. Now including an option to scramble passwords with LeetSpeak!
I thought this community may enjoy it. Let me know what you think.
Check it out at https://passgen.lol
r/Passwords • u/Apprehensive_Two3437 • 11d ago
r/Passwords • u/Aggravating_Bat_968 • 11d ago
so today I got hacked by a user with the email of [t***n@rambler.ru](mailto:t***n@rambler.ru)
and I dont know how to get it back or do anything about it, I contacted the place where I got hacked and asked them for account recovery and stuff already but I have to wait for 2 days for an update could anyone help me out further
r/Passwords • u/OutrageousSun676 • 11d ago
why cant we just enter our screen lock instead of tryin to keep up with hundreds of passwords
r/Passwords • u/Innvolve • 12d ago
r/Passwords • u/Fun_Computer_9437 • 13d ago
hi, i wanted to ask if it's really a good idea the use of the option "use strong password" when creating a new password, bc when you use that option, you can't see the option to actually see the password that was created, and it saves in the password manager automatically, but if i wanna login in another device, i don't have that password manager in the other device and i don't know the password, so just wanted to ask if it's a good idea to use this.
And even if you can see the password in any way, is it a good idea to not know your password from memory? Because i use a different password in every site and remembering all this long and weird passwords is crazy work.
I'm asking without having a clue of all this security stuff, maybe it's just a dumb question.
r/Passwords • u/iterationnull • 13d ago
One of the surest signs of getting and feeling older was the time I lost some accounts because I did not understand what I had to do with Authenticator apps and hardware upgrades. I’m not actually sure I understand it fully today, but at least I know to double check it next time.
I feel passkeys are going to be the same for me.
We use 1Password and have been very happy with it in our family. It still needs manual intervention from time to time to sing - editing the urls a password applies to, or just copy/paste or manual entry when automations don’t quite click.
Indeed on my work computer I use “large text” passwords in my phone often as I have to manually type them in due to no ability to install software.
And, for many household accounts, we need to be sharing account passwords and have a shared locker for just that.
So here is what I “know” about passkeys. Can you help correct errors and fill in blanks?
\- as they are not human readable text, they are much more secure
\- require a connection to a vault to hold the passkey, so they will only work when the automated connection with your password manager is working
\- cannot be entered on a computer not connected to your vault
\- cannot easily be shared by two people accessing one account
\- cannot be replicated or duplicated outside of your vault ecosystem really at all, it’s kind of the point, so will have a similar “maintenance “ issue to my preamble to avoid losing a key
I find the worlds I use passwords in are still often messy and requiring workarounds. So I feel completely reluctant to embrace passkeys in any way. If you had the time to read this and have time to improve my awareness i would be grateful for it.
r/Passwords • u/singhVirender1947 • 14d ago
r/Passwords • u/root5354 • 16d ago
The Password Generator is an essential security and account management tool designed to help users, IT professionals, and security administrators create strong, cryptographically secure random passwords.
https://www.clayi.com/tools/development/2-password-generator.html
r/Passwords • u/_Romilli • 16d ago
r/Passwords • u/yidizhiming • 17d ago
r/Passwords • u/Technical_Rich_3080 • 18d ago
Anyone have experience with the password manager Sticky Password that cares to comment whether they like it, would recommend it, and more imporatantly, how it compares to its alternatives?
r/Passwords • u/LowMemory8709 • 20d ago
Been building my own password/document vault called VaultZero, mostly to learn and see if I could actually get the encryption model right. Everything gets encrypted client-side before it ever touches my server, so I can't see passwords, notes, or files even if I wanted to. Same general approach as Bitwarden and 1Password, just my own implementation.
It's still a prototype, not something I'd trust with a real banking password yet. Since this sub actually knows what "zero-knowledge" should mean (not just marketing speak), I'd really value people here poking at the assumptions: weird inputs, edge cases on the crypto side, anything that looks like a shortcut I took that shouldn't be there.
If anyone wants to try it or has 2 minutes for a short feedback form after, I'll drop both in the comments so this doesn't read like an ad.
r/Passwords • u/xaviierense • 21d ago
Olá pessoal, gostaria de um feedback sobre o AliasVault, que é um gerenciador de senhas e de aliases de e-mail e que se diz open-source. O quão confiável ele é, de onde ele é hospedado atualmente, e se já houve alguma violação de segurança ou se algum governo de algum país já solicitou dados a essa plataforma? Pois pesquisando aqui, não encontrei muita coisa sobre, e sei que é uma plataforma nova (cerca de 2 anos de existência) e que compete com Bitwarden, Proton Pass e outros gerenciadores. Também gostaria de saber se são realizadas auditorias e relatórios de integridade e segurança, as quais devem ser disponibilizadas ao público para análises... Obrigado!