It's not as comfortable as lastpass but it gives me a control of where do I store that data, how do I keep backups etc. I can't really recommend that setup, I am keep experimenting myself.
The database file is strongly encrypted and you can lock it with a keyfile and a password. It's easily synced with Google Drive or Dropbox. Keepass2Android even provides direct connection with a Dropbox or Google Drive database file. Conflicts are easily resolvable in case an update didn't get pushed until you change something at another device. I sync the 1024bit keyfile using usb sticks (only needed when setting up new devices) and a long password (the only one I have to remember).
You can even import passwords from your local firefox password manager and from 1password (though import from 1password seems to run through unencrypted csv files.
And you get all that for free.
I would never want to use a free password manager, because it's likely they have different intentions with your data or are can shut it down any time.
I use keepass2 for various serious passwords.
$4,000 over 40-60 years is insignificant. If it's useful and doesn't mess with your monthly budget, why not keep paying?
Not trying to change your mind, but I don't see the problem, and you could say that about anything you pay monthly for.
I feel I'm paying for almost everything as a "subscription" and I own zero.
$60 1Password
$156 Netflix
$120 Amazon Prime
$1200 AT&T (estimated, Family Plan)
$720 Internet
$260 NYTimes
$168 Spotify
So thats $2684.00 for services and content per year - with nothing to show for it if I cancel. Fine for most people, but part of it gnaws at me. To each their own.It's more suited for things that we consume once then throw away. We only watch a movie or episode a few times, we do play songs often but get bored of them in 40 years.
Password managers are another category, but even then I'd rather pay $4000 over 60 years than $1000 today.
I do take your point. The point is, if you cancel your subscription you are left with nothing.
But there are very good free alternatives out there like keepass, with clients for every major operating system, including mobile.
The database file is then stored on a removable piece of media that can be plugged into any other machines I use, then accessed via KeePass on that one.
I've since moved to a self-hosted Bitwarden [0]. Open source and free and weren't shady with their security audit.
[1] https://blog.bitwarden.com/bitwarden-completes-third-party-s...
https://dl.enpass.io/docs/EnpassSecurityAssessmentReport.pdf
Compare their security audit with the one provided for Bitwarden [1].
[0] https://discussion.enpass.io/index.php?/topic/404-security-a...
[1] https://cdn.bitwarden.net/misc/Bitwarden%20Security%20Assess...
It's quite easy to guess once they do have the salt. I just do this as a minimum security alternative to calling my password "password"
I would say that while I am looking for an alternative that works for "me", I'm also thinking of approaches (like this - or apps) that would work for my kids.