For a graphical password manager, consider instead PasswordSafe, KeePass, KeePassXC. They're not complicated. Don't look for or enable any integrations. Manually copy your encrypted password database to google drive or dropbox. It's simple and secure.
Anything more automated and "easy" is almost always found to be vulnerable. LastPass and OnePass have both had problems with their fancy online accounts and recovery systems and browser integrations. Just don't bother with all that crap, you don't need it.
I just tried it and the lack of plugin or sync support was a deal-breaker for me. I have plugins for syncing to cloud storage, for browser integration, for OTP generation, etc., none of which it seems to support?
These days AgileBits(the 1password people) are doing everything they can to get everyone onto a subscription plan, and are breaking local vaults slowly. Most people don't seem to recommend it anymore.
The only security issue really is the online vault(which isn't a security issue per-say, but is a security weakness since your passwords are no longer under your direct control). This may or may not be an issue for you, depending on your security posture.
But other researchers have played with 1password and most have historically had good things to say about it, except recently when they started pushing everyone to the online vaults like I mentioned.
And yes, he is a security researcher for Google.
These days AgileBits(the 1password people) are doing everything they can to get everyone onto a subscription plan, and are breaking local vaults slowly. Most people don't seem to recommend it anymore.
Now you have other options:
* KeepassXC (the latest seemingly well-recommended keepass variant - but there are a bunch of them)
* Bitwarden (it's OSS and can support author(s) with payment. Can run on your own server/machine while still supporting cross device sync)
* Pass (and the go variant, and the Qt variant) uses GPG under the hood, basically just a directory/git repo full of encrypted text files. Sync across devices is your problem.
I'm seriously evaluating Bitwarden to replace 1Password as it's pretty simple to understand and has a similar strategy as 1Password security wise, but is OSS.
However, I like the flexibility to use any "file sync" tool I want to pass KeePass files around between my devices (or none at all, depending on the threat model of individual password files). That opens up flexibility to use things like Keybase File Share and Resilio Sync Encrypted Shares where you have additional options in in-transfer and at-rest encryption of your files.
[1] In that category some security-minded friends that I trust have done their own research on the subject recommend Dashlane over LastPass.
But I'd recommend keepass if you want something graphical.
This technique might not work so well for people who actually have to share devices, log out of things, etc.
If you're just starting, here's some guidance on setting up a password manager.
First of all: Don't be afraid of using one. It's not just more secure, it's super convenient. Never again will you ask yourself: Did I make an account for this website/service? What email did I use? Never again will you have to remember a password. Using a password manager is a quality of life improvement.
KeepassXC is what I recommend to people at this point. It's free and you own your data (your passwords). They live wherever you want them to live. There are plenty of online services that are supposedly more convenient but I have to say I trust them less -- YMMV (1Password is the best I'm aware of).
If you do use keepassxc, you get the added benefit of being able to store 2FA settings in it as well (if you store them in the same database as your passwords, be aware that you lose the security benefit of a second factor, however it is still more secure than not having 2FA enabled due to the One-time password component).
Put every account you ever made and ever make into keepass. Enable 2fa wherever you don't have it enabled. Add login URLs and notes. Generate your passwords from keepass itself; the password generator is really powerful and lets you very easily deal with site-specific shitty password limitations. I'm telling you this because, seriously, it's incredibly convenient to have this stuff as long as you're rigorous about maintaining it.
Oh, also, keepass has the full history of all your passwords. Need to look up an old password? Go into details and look at "History". You can also attach files to items (items don't have to be accounts at all, you can use keepassxc as a simple encrypted storage db).
Mobile support: Keepass2Android. Best android client, with google drive support. iOS I have no idea, suggestions welcome.
IMPORTANT: BE STUPIDLY PARANOID AND RIGOROUSLY CAREFUL ABOUT YOUR MASTER PASSWORD. That thing, together with your keepass database, unlocks all your accounts ever. Use a really long passphrase that you will never have to write down (if you do decide to write it down because you don't trust yourself, store it in a safety deposit box, don't put it in a bloody drawer). Make sure the device you unlock the database on is malware-free.
PS: Wondering what's up with Keepass vs. KeepassX vs. KeepassXC? Keepass is the original app, written in .NET but with poor multi-platform support. KeepassX is a rewrite in Qt and is a fantastic password manager, but has gone unmaintained recently. The open source community picked up the slack in the KeepassXC fork (after continuing countless attempts to upstream the patches) and has implemented lots of powerful features. I've switched to it and at this point I strongly believe it's the better client.
Really? Why?
WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues
This page exists only to help migrate existing data encrypted by TrueCrypt.
The development of TrueCrypt was ended in 5/2014 after Microsoft terminated support of Windows XP. Windows 8/7/Vista and later offer integrated support for encrypted disks and virtual disk images. Such integrated support is also available on other platforms (click here for more information). You should migrate any data encrypted by TrueCrypt to encrypted disks or virtual disk images supported on your platform.