* https://keepass.info/
* https://bitwarden.com/
* https://1password.com/ * https://keepass.info/
* https://bitwarden.com/
* https://1password.com/Lastpass was really buggy and had a confusing UI. Dashlane also had odd limitations.
1password had a good UI but the "master key" system is difficult for users to use. It was also more expensive.
I ended up recommending Bitwarden. Surprisingly the open source option had a great UI and great clients, with the bonus of being open source on both ends.
Unsurprising, and at the same time it makes 1password's security scheme much more bullet proof.
You need that piece of information to identify the client, and even 1password doesn't have it, which means that when inevitably one of these cloud services gets attacked with success, it will less likely be them. Plus they can't see your stuff, that's a plus.
Security is not free.
Am I talking about the same thing as you when I call this password the “master key”? I feel like I must be as this is flat-out the thing that makes 1Password easy to use.
1. The team address <team>.1password.com
2. Your login name (email usually)
3. Your 'secret key'
4. Your 'master password'
I suspect GP is talking about item #3 being the point of confusion.
Edit: I do not mean browser localStorage
However, in the year before I left LP, they went down three times, at most for about 4 hours. Each time, I could not access my local vault, not through the browser extension, not through the Android app, and certainly not through the website; no matter what I did, it was nothing but errors, and their support was useless. It just would not work. That was enough to spook me and get me off their service.
I was complacent, thinking that no matter what, I could always see my vault, regardless of network status, until it actually hit the fan. I'm currently with 1Password, which is quite slick (their change on 2FA is what actually got me to give them a try), but I've killed network access to my devices and was able to access my vaults.
Just in case, though, I have KeePassXC as well. You never know.
Security is a battle of convenience, and we still haven't struck gold for the layman to have decent enough security hygiene.