After several years on LastPass, I'm switching to Bitwarden, which I can't stop raving about. Main reasons:
- It's and openly audited for security and privacy.
- LastPass had a master password breach last year.
- You can self-host Bitwarden for extra security.
- Credential sharing is cleaner.
- The Bitwarden UI is just simpler AND better, in every way.

I know it's weird to get worked up over a password manager, but seriously, give it a try.

@nicole Do you have more information about that master password breach? I've been trying to look it up, but I haven't been able to find anything.

@amandag Sorry, it looks like it wasn't the master password that was taken, but potentially individual site ones. There was a bug discovered that allowed passwords to be stolen via browser extensions:

This isn't the first time they've had vulnerabilities pointed out in their extensions.

A few years ago, an attacker got "LastPass account email addresses, password reminders, server per user salts, and authentication hashes":

@amandag LastPass says those issues have been fixed, but that's the problem with services where the code is proprietary-- you just have to take their word for it.

I feel safer on an open-source password manager whose code gets thoroughly inspected by everyone.

@nicole Absolutely. I personally use KeePass - which stores its passwords in an encrypted file - together with a file syncing service I run, so I also know exactly what server infrastructure is involved. When it comes to this particular subject I prefer having as much control as possible.

@amandag I also used KeePass for a while, but I missed a lot of the convenience I'd gotten used to with LastPass. Bitwarden is all of the convenience (and more) of LastPass, with the security of KeePass.

