Video summary
2026 Password Manager Tier List: Does Yours Stack Up?
Main summary
Key takeaways
Overview
A Privacy Guides-hosted, non-scrubbed “tier list” ranks 10–15 popular password managers based on:
- Security properties
- Architecture / transparency (e.g., source availability)
- Availability of free tiers
- Practical features (e.g., autofill, passkeys, travel mode)
The speaker also argues that:
- Even mediocre password managers are better than password reuse
- F-tier is reserved for the concept of “no password manager / no password system.”
Tier highlights (technical themes + stated reasons)
Passwork Now — B
- Enterprise-focused, primarily self-hosted/on-prem (less “SaaS-first” than many tools).
- Has a SaaS edition/community version for individuals, but the product is “designed for self-hosting.”
- Notes self-hosting caveats:
- backups
- external access
- patching
- network segmentation
- Recommended, but not the best fit for typical individuals/families compared to alternatives.
Keeper — C
- Business-leaning; not source available.
- No free tier (about ~$4/month mentioned).
- Lacks strong differentiation for individuals; features like breach alerts/data checks aren’t uniquely compelling.
1Password — S
Despite concerns (not source available, no free tier), it earns top placement due to:
- “Immaculate” autofill, especially on macOS (strong integration with the Apple ecosystem)
- Travel Mode: selectively hides certain logins on your device to reduce exposure if compelled at borders/searches
- Security architecture requiring three elements to decrypt: 1) account password 2) secret key 3) encryption on the data itself
- Cites expert praise and regular audits
- Claimed as having a uniquely strong “original” security/feature design vs others
Proton Pass — A
- Newer and still “catching up,” but:
- Free tier
- Speaker believes open source / plans for source publishing
- Security audits reported
- Advantage: fits into Proton’s broader ecosystem (Mail / VPN / Drive)
- Caveat: “eggs in one basket” concern for users who prefer separating vendors
Physical Notebook — D
- Claims it can be “breach-proof” from remote hacking/telemetry.
- Major security caveats:
- risk of fire
- theft/confiscation or raids
- loss of convenience features that also act as security signals (notably autofill behavior used to detect phishing/mismatched domains)
- backup and update friction (maintaining multiple copies)
- requires true offline randomness when generating passwords (warns against weak “word-picking” randomness)
Apple Passwords app — D
- Polished and integrates with Apple:
- view/save passwords and passkeys
- Siri can find passwords
- data-breach checks and credit card storage
- Downgrades due to:
- not source available
- vendor lock-in (harder migration to non-Apple tools)
- Suggests third-party managers for users who want future portability.
Dashlane — C
- No standout technical differentiators; described as mostly “advertising.”
- Includes features like VPN / “AI scam protection” (speaker expresses skepticism).
- No free tier mentioned; not source available.
- Considered “better than Apple/browser/notebook” mainly due to dedicated password manager convenience (e.g., autofill).
Browser password managers (Chrome/Brave/Firefox) — D
- Reasons:
- vendor lock-in to browser ecosystem
- browser tool is an “afterthought” vs a dedicated manager
- malware risk discussion: browser data (history/session tokens/passwords) may be targeted
- uncertainty about encryption implementations (speaker mentions rumors like “Google password manager isn’t encrypted,” not confirmed)
RoboForm — C
- Has a free tier (personal/family), but:
- free tier isn’t accessible on all devices
- Seen as a more dedicated product than Apple/browsers/notebook, but not enough unique value.
LastPass — D
- Not placed in F, but strongly criticized due to the 2022 breach:
- attacker pivoted from a compromised Plex server to other network devices, including the company computer
- stolen vaults (including an employee-at-home scenario)
- Criticized response/timing:
- disclosed at ~4pm Friday, Dec 23 (speaker interprets as burying it over the holidays)
- Technical/security claims about vault handling:
- alleged vault improvements lagged (encryption/hashing not updated over time)
- parts of vault possibly not encrypted (e.g., login URLs; notes/seed phrases/recovery codes mentioned as potentially not encrypted)
- Overall conclusion: many better options exist; “would not recommend” LastPass.
Passbolt — C
- Open source and self-hostable/cloud option; company-focused.
- Main reason for downgrade: does not support passkeys (speaker views this as a major miss).
- Passkey emphasis: phishing resistance and low user effort (keypair-based design).
Bitwarden — A
Strong recommendation. Key points:
- Generous free tier (“always free,” unlimited devices/entries; advanced features omitted)
- Supports passkeys
- Supports emergency access (highlighted as important, especially after LastPass)
- Integrates with alias providers (e.g., SimpleLogin / Addy / Firefox Relay—requires some tinkering)
- Mentions cryptography improvement: upgraded to Argon2 (optional for older devices)
Not S/S-tier because:
- 1Password’s architecture + Travel Mode are considered uniquely stronger.
Enpass — B
- Not open source; no free plan (speaker suggests pricing is still relatively reasonable).
- Unique technical approach:
- designed to work with user-selected storage (“own cloud”: Nextcloud/Drive/Azure/AWS, etc.)
- “cloudless sync” for local-network synchronization (local LAN sync; compared conceptually to Syncthing)
- Adds complexity vs typical cloud syncing, but the distinctive feature set is recognized.
KeePassXC / KeePass clients (KeePassDX, KeePassium) — S
S-tier for maximum privacy/security potential:
- Can operate totally offline
- Vault remains encrypted even if devices are taken (example given: air-gapped Qubes VM)
But explicitly advanced-user:
- requires careful backup discipline
- manual sync/versioning problems if using multiple devices (vault updates must be correctly propagated)
- UI described as dated despite being feature-rich and cross-platform
NordPass — B
- Controversial due to company ethics/marketing style (e.g., “anonymous/hacker proof” type claims).
- Technical/feature notes:
- has a free tier but not on multiple devices; only essential features
- encryption mentioned as XChaCha20 (speaker: “if I understand correctly,” i.e., not fully confident)
- publishes security architecture/white papers; has audits and a bug bounty program (implied)
Overall placement:
- above many C-tier tools largely due to perceived reliability as a large established vendor,
- but not matching uniqueness attributed to Bitwarden / Proton / 1Password.
F-tier concept (not assigned to a brand)
- F-tier reserved for “not using a password manager/system” (speaker argues against using this label for specific products like LastPass or NordPass).
Core argument:
- humans are poor at generating/remembering strong unique passwords
- password reuse remains catastrophic due to credential stuffing and breaches
- even a “better-than-nothing” manager reduces risk by enabling unique passwords across many accounts (speaker cites “100+ accounts” as common)
Main speakers/sources
- Speaker: Nate (Privacy Guides)
- Referenced external sources/people:
- Troy Hunt / Have I Been Pwned
- Jono (implied co-host/expert commenter)
- “Steve Terreberry” (mentioned as a comedy musician; not a security authority)
- Referenced security database: Have I Been Pwned (HIBP)