I store all of my passwords in firefox’s built-in password manager. They auto-fill into websites, sync to my phone, notify me if one appears publicly, and I can generate strong new passwords conveniently. The pw vault is stored encrypted in the cloud as far as I know, but I don’t really know the technical details. I presume that it’s just as secure as using a “proper” manager.

Is there a problem with not using a dedicated password manager? I used to use LastPass but then… I stopped. And at the time I didn’t see anything wrong with just sticking with FF.

Using Firefox is fine right? If so, what’s the benefit of something like BitWarden/etc over the built-in one?

  • sbird@sopuli.xyz
    link
    fedilink
    English
    arrow-up
    2
    ·
    7 hours ago

    It’s better to use a separate password manager, since it’s an additional layer of security, as you must type in a master password or, if you configure it, use a hardware key/biometrics. Also, as others have said, you can use them in non-website logins too, so it’s more flexible!

    Personally, I think Bitwarden is a pretty good option for most people. It’s cross-platform, and I think there is an option to self-host the server if you wish.

    Another option, the one I use, is KeePass (XC on desktop, DX on Android, KeePassium on iOS), which stores passwords in a local database file, and you can use Syncthing to sync the contents of the database!