Yahoo
Skip to main content
Advertisement
Advertisement
Advertisement
Advertisement

I Like Open-Source Password Managers, but I Don’t Restrict Myself to Them

Bitwarden is a great password manager, but its open-source nature is only a part of that.

Sarah Tew/CNET

You should be using a password manager , but an open-source password manager isn't inherently better than one built with proprietary software. I like the idea of being able to see what a piece of security software is doing, but I wouldn't choose a password manager based on that alone. 

Open source mainly gives you another way to judge the software you're trusting with an enormous amount of sensitive information. For some people, that extra visibility is reason enough to seek it out. For others, including myself, factors such as convenience and the company's security record matter more.

There are excellent proprietary options, and there are open-source projects out there that I wouldn't trust with a grocery list, much less every password I own.

Advertisement
Advertisement

Here's where I think open source actually matters, where it doesn't and which options are worth considering.

Open-source password managers offer transparency, not necessarily more security

Open-source software makes its code publicly available under a license that allows people to inspect, use, modify and redistribute it. That matters with a password manager , which you're trusting with some of your most sensitive information. Researchers can examine how passwords are encrypted and stored, how authentication works and whether the code contains vulnerabilities or backdoors. Bitwarden, for example, publishes code for its server, browser, web, desktop and command-line applications.

One common concern is that publishing all of this gives hackers a head start. It doesn't, though — at least not if the cryptography is doing its job. Encryption methods such as AES are already public knowledge. Knowing which algorithm protects a vault doesn't give a bad actor the key needed to decrypt it. Good encryption can withstand somebody knowing how it works.

The real advantage is that open source gives more people a chance to check the work. As I just mentioned, researchers can find vulnerabilities, question security claims and report problems without waiting for the company to invite them in. But that's an opportunity, not a guarantee. Code sitting on GitHub isn't necessarily being picked apart by security experts every afternoon. 

Advertisement
Advertisement

Open source gives you more transparency, which I consider a plus, but it doesn't automatically make a password manager secure.

Open source doesn't always mean free

Open source and free tend to get lumped together, but they're not the same thing. Open source tells you something about the code and its license, not the price tag. A company can let anyone inspect its code and still charge you to use parts of the service.

Bitwarden, again, is a good example. It has a generous free plan, but charges for premium features and family and business plans. Proton Pass does something similar, offering open-source client apps alongside free and paid plans. What you're paying for might be cloud services, extra storage, additional security features, family sharing or business tools, rather than the underlying code itself.

Closed-source password managers have merits, too

Closed-source password managers don't publish their complete code for anyone to inspect. That means you have to take more of the company's word for what its software is doing, but that doesn't mean the software is insecure. Plenty of good password managers are proprietary.

Advertisement
Advertisement

The most important items to look for are established encryption methods, zero-knowledge architecture, multifactor authentication and, nowadays, passkey support . It's also worth checking what happened the last time the company found a vulnerability. Finding bugs is normal, but what a company does about them tells you considerably more.

Things like independent security audits, penetration testing, bug bounty programs and detailed security documentation are other good signals that closed-source software is worth its salt. SOC 2 reports can also tell you whether certain company controls have been independently assessed, although passing one doesn't mean the software is bulletproof.

There are practical reasons to choose proprietary software, too. Some closed-source password managers may put more resources into things such as account recovery, family sharing, customer support, business features or polished apps because those features are a big part of what they're selling. That doesn't mean proprietary software is inherently more capable, but a paid commercial service may offer a particular feature or level of support you can't get from the open-source alternative you're considering. If an open-source password manager drives you nuts every time you use it, choosing it on principle isn't accomplishing much.

Here's why you should and shouldn't consider an open-source password manager

If transparency matters to you, open source has an obvious advantage. Some open-source password managers also give you more control — Bitwarden, for example, can be self-hosted. That doesn't automatically make it safer. If you run the server yourself, the updates, backups, configuration and security become your problem, too.

Advertisement
Advertisement

The question is how much any of that matters to you.

Consider open source if…Don't make open source a priority if… You want the option to self-host

You value transparencyYou care more about specific featuresYou want independent researchers to be able to inspect the codeA closed-source option works better on your devicesYou want to inspect the code yourselfFamily sharing or account recovery matters moreYou prefer community-driven developmentYou prioritize customer support or ease of useYou're satisfied with the provider's audits and security recordYou want more control over the softwareYou have no real need to access the source code

For me, open source is a plus, not a requirement. If two password managers are otherwise equally good, I'll take the one that lets people inspect the code. But I'm not giving up better security, useful features or an app that actually works just to get a GitHub link.

Three open-source password managers worth considering

Open source isn't exactly the same from one password manager to the next. Some companies publish code for nearly the entire product, some make only certain components available. Regardless, here are three good open-source password managers worth considering, though they take pretty different approaches.

Bitwarden

Bitwarden is CNET's editors' choice for best free password manager and the open-source password manager I'd recommend to most people. It publishes code for major parts of its platform, including its server and client apps, while offering most of the conveniences you'd expect from a commercial password manager. It uses end-to-end encryption and a zero-knowledge architecture, supports passkeys, works across the major platforms and browsers, undergoes third-party security testing and runs a bug bounty program .

Advertisement
Advertisement

The free plan is enough for plenty of people, but the paid plans add more features. You can also self-host Bitwarden if that's your thing, although most people have little reason to bother.

Proton Pass

Proton Pass makes the most sense if you want a strong free option or already live in the Proton ecosystem with Proton Mail or Proton VPN . The free plan gives you unlimited logins and devices, plus passkeys, password generation and email aliases. Proton Pass paid plans add more features and can be bundled with Proton's other services.

There's one wrinkle: Proton makes its Pass apps open source, but unlike Bitwarden, it doesn't publish the complete server-side implementation. That's worth taking into consideration, and it's a good example of why calling something "open source" doesn't always tell you the whole story.

KeePassXC

KeePassXC is the DIY option. It stores your encrypted password database locally instead of automatically syncing it through a company's cloud. If you want that database on several devices, figuring out how to sync and back it up is largely up to you.

Advertisement
Advertisement

It's free and open source, runs on Windows, macOS and Linux and works with KeePass databases and browser extensions. There's no official KeePassXC mobile app, either. You get a lot of control, but you also get more work, which makes KeePassXC a better fit for people who don't mind managing some of this stuff themselves.

Open source is an advantage, not a requirement

I actually use 1Password , which is closed source. I particularly like 1Password's Travel Mode, which lets me temporarily remove sensitive vaults from my devices when I'm traveling and restore them when I'm done. That's useful enough for me to care more about the feature than whether I can inspect the source code myself.

That's ultimately how I'd choose a password manager. Open source is a plus, but the best password manager is the one that fits how you actually plan to use it.

And remember, a password manager is only one piece of the security puzzle. We have some recommendations for the best VPNs and best antivirus software if you're looking to cover the rest.

Advertisement
Advertisement

CNET and Yahoo may earn commission from links in this article.

Advertisement
Advertisement
Mobilize your Website
View Site in Mobile | Classic
Share by: