Video summary

2026 Password Manager Tier List: Does Yours Stack Up?

Main summary

Key takeaways

Technology

Overview

A Privacy Guides-hosted, non-scrubbed “tier list” ranks 10–15 popular password managers based on:

  • Security properties
  • Architecture / transparency (e.g., source availability)
  • Availability of free tiers
  • Practical features (e.g., autofill, passkeys, travel mode)

The speaker also argues that:

  • Even mediocre password managers are better than password reuse
  • F-tier is reserved for the concept of “no password manager / no password system.”

Tier highlights (technical themes + stated reasons)

Passwork Now — B

  • Enterprise-focused, primarily self-hosted/on-prem (less “SaaS-first” than many tools).
  • Has a SaaS edition/community version for individuals, but the product is “designed for self-hosting.”
  • Notes self-hosting caveats:
    • backups
    • external access
    • patching
    • network segmentation
  • Recommended, but not the best fit for typical individuals/families compared to alternatives.

Keeper — C

  • Business-leaning; not source available.
  • No free tier (about ~$4/month mentioned).
  • Lacks strong differentiation for individuals; features like breach alerts/data checks aren’t uniquely compelling.

1Password — S

Despite concerns (not source available, no free tier), it earns top placement due to:

  • “Immaculate” autofill, especially on macOS (strong integration with the Apple ecosystem)
  • Travel Mode: selectively hides certain logins on your device to reduce exposure if compelled at borders/searches
  • Security architecture requiring three elements to decrypt: 1) account password 2) secret key 3) encryption on the data itself
  • Cites expert praise and regular audits
  • Claimed as having a uniquely strong “original” security/feature design vs others

Proton Pass — A

  • Newer and still “catching up,” but:
    • Free tier
    • Speaker believes open source / plans for source publishing
    • Security audits reported
  • Advantage: fits into Proton’s broader ecosystem (Mail / VPN / Drive)
  • Caveat: “eggs in one basket” concern for users who prefer separating vendors

Physical Notebook — D

  • Claims it can be “breach-proof” from remote hacking/telemetry.
  • Major security caveats:
    • risk of fire
    • theft/confiscation or raids
    • loss of convenience features that also act as security signals (notably autofill behavior used to detect phishing/mismatched domains)
    • backup and update friction (maintaining multiple copies)
    • requires true offline randomness when generating passwords (warns against weak “word-picking” randomness)

Apple Passwords app — D

  • Polished and integrates with Apple:
    • view/save passwords and passkeys
    • Siri can find passwords
    • data-breach checks and credit card storage
  • Downgrades due to:
    • not source available
    • vendor lock-in (harder migration to non-Apple tools)
  • Suggests third-party managers for users who want future portability.

Dashlane — C

  • No standout technical differentiators; described as mostly “advertising.”
  • Includes features like VPN / “AI scam protection” (speaker expresses skepticism).
  • No free tier mentioned; not source available.
  • Considered “better than Apple/browser/notebook” mainly due to dedicated password manager convenience (e.g., autofill).

Browser password managers (Chrome/Brave/Firefox) — D

  • Reasons:
    • vendor lock-in to browser ecosystem
    • browser tool is an “afterthought” vs a dedicated manager
    • malware risk discussion: browser data (history/session tokens/passwords) may be targeted
    • uncertainty about encryption implementations (speaker mentions rumors like “Google password manager isn’t encrypted,” not confirmed)

RoboForm — C

  • Has a free tier (personal/family), but:
    • free tier isn’t accessible on all devices
  • Seen as a more dedicated product than Apple/browsers/notebook, but not enough unique value.

LastPass — D

  • Not placed in F, but strongly criticized due to the 2022 breach:
    • attacker pivoted from a compromised Plex server to other network devices, including the company computer
    • stolen vaults (including an employee-at-home scenario)
  • Criticized response/timing:
    • disclosed at ~4pm Friday, Dec 23 (speaker interprets as burying it over the holidays)
  • Technical/security claims about vault handling:
    • alleged vault improvements lagged (encryption/hashing not updated over time)
    • parts of vault possibly not encrypted (e.g., login URLs; notes/seed phrases/recovery codes mentioned as potentially not encrypted)
  • Overall conclusion: many better options exist; “would not recommend” LastPass.

Passbolt — C

  • Open source and self-hostable/cloud option; company-focused.
  • Main reason for downgrade: does not support passkeys (speaker views this as a major miss).
  • Passkey emphasis: phishing resistance and low user effort (keypair-based design).

Bitwarden — A

Strong recommendation. Key points:

  • Generous free tier (“always free,” unlimited devices/entries; advanced features omitted)
  • Supports passkeys
  • Supports emergency access (highlighted as important, especially after LastPass)
  • Integrates with alias providers (e.g., SimpleLogin / Addy / Firefox Relay—requires some tinkering)
  • Mentions cryptography improvement: upgraded to Argon2 (optional for older devices)

Not S/S-tier because:

  • 1Password’s architecture + Travel Mode are considered uniquely stronger.

Enpass — B

  • Not open source; no free plan (speaker suggests pricing is still relatively reasonable).
  • Unique technical approach:
    • designed to work with user-selected storage (“own cloud”: Nextcloud/Drive/Azure/AWS, etc.)
    • “cloudless sync” for local-network synchronization (local LAN sync; compared conceptually to Syncthing)
  • Adds complexity vs typical cloud syncing, but the distinctive feature set is recognized.

KeePassXC / KeePass clients (KeePassDX, KeePassium) — S

S-tier for maximum privacy/security potential:

  • Can operate totally offline
  • Vault remains encrypted even if devices are taken (example given: air-gapped Qubes VM)

But explicitly advanced-user:

  • requires careful backup discipline
  • manual sync/versioning problems if using multiple devices (vault updates must be correctly propagated)
  • UI described as dated despite being feature-rich and cross-platform

NordPass — B

  • Controversial due to company ethics/marketing style (e.g., “anonymous/hacker proof” type claims).
  • Technical/feature notes:
    • has a free tier but not on multiple devices; only essential features
    • encryption mentioned as XChaCha20 (speaker: “if I understand correctly,” i.e., not fully confident)
    • publishes security architecture/white papers; has audits and a bug bounty program (implied)

Overall placement:

  • above many C-tier tools largely due to perceived reliability as a large established vendor,
  • but not matching uniqueness attributed to Bitwarden / Proton / 1Password.

F-tier concept (not assigned to a brand)

  • F-tier reserved for “not using a password manager/system” (speaker argues against using this label for specific products like LastPass or NordPass).

Core argument:

  • humans are poor at generating/remembering strong unique passwords
  • password reuse remains catastrophic due to credential stuffing and breaches
  • even a “better-than-nothing” manager reduces risk by enabling unique passwords across many accounts (speaker cites “100+ accounts” as common)

Main speakers/sources

  • Speaker: Nate (Privacy Guides)
  • Referenced external sources/people:
    • Troy Hunt / Have I Been Pwned
    • Jono (implied co-host/expert commenter)
    • “Steve Terreberry” (mentioned as a comedy musician; not a security authority)
  • Referenced security database: Have I Been Pwned (HIBP)

Original video