Hacker News new | ask | show | jobs
by antiframe 1555 days ago
I too switched from BitWarden to KeePass. I was reading about browser security and became concerned about running my password manager in the same process as the browser and relying on its sandbox. With KeePassXC I have the option to either forgo browser integration completely or use their addon which communicates to the manager and asks for an entry, which prompts for permission itself or uses an allow list by URL. That makes it much harder for a website to somehow break the sandbox and access my entire database.

It's a small change but it does reduce the attack surface as well as force me to manage my data myself which I want to do more of.

Also with BitWarden, their UI annoyed me when I needed a password outside the browser. L