I Spent a Month Living With All Three Password Managers.
Bitwarden, 1Password, and KeePassXC represent three genuinely different answers to the same unsettling question.
I Spent a Month Living With All Three Password Managers. The Difference Isn’t Features -It’s Who You Trust.
Bitwarden, 1Password, and KeePassXC represent three genuinely different answers to the same unsettling question.

Let me tell you what nobody says out loud when recommending a password manager.
They almost never tell you: “I chose this one because I made a deliberate decision about who I’m willing to trust with the most sensitive data in my digital life.” They usually say something about browser extensions, autofill reliability, or whether it works on both their iPhone and their work laptop.
Those things matter. But they’re downstream of a question most people skip entirely.
Where does your password vault actually live? And who — besides you — has any theoretical path to it?
I’m not trying to be alarmist here. I use a password manager. You probably do too, or you’re reading this because you’re trying to figure out which one to start with. What I want to do is give you the underneath-the-hood version of this comparison — the one that feels a little uncomfortable to sit with, because it requires you to have a view on risk rather than just checking off features.
The three approaches, honestly described
Bitwarden is open-source, which means anyone can inspect the code. The company runs cloud infrastructure that stores your encrypted vault. Strong crypto — they’ve moved to Argon2id for key derivation, which resists the kind of GPU-accelerated brute-force cracking that older PBKDF2 implementations are more vulnerable to. You can also self-host it, meaning you can run the entire server stack on your own machine if you want to.
1Password runs closed-source cloud infrastructure with a clever architectural twist. When you set up an account, it generates a 34-character Secret Key locally — something with 128 bits of entropy that never gets transmitted to 1Password’s servers. The practical effect: your vault is encrypted with both your master password and this Secret Key. If someone somehow obtained 1Password’s server data, they’d be stuck. They’d need the Secret Key from your device too, and that combination makes brute-force attacks computationally absurd to attempt.
KeePassXC does neither of these things. Your password database is a file. It sits on whatever storage you choose — your hard drive, a USB drive, a network-attached storage device you manage yourself. There’s no cloud component unless you deliberately add one (Syncthing, Dropbox, whatever you prefer). In November 2025, KeePassXC version 2.7.9 received a First-Level Security Certification from France’s ANSSI — the national cybersecurity agency — following real penetration testing and cryptographic review.
Three legitimate options. Three genuinely different philosophies about where risk lives and how to manage it.
The thing about “zero-knowledge”
All three of these tools advertise zero-knowledge encryption. The term means that your data is encrypted on your device before it goes anywhere, so even the company hosting your vault can’t read it.
This is true, and also not the whole story.
Zero-knowledge protects you from the provider reading your data. It doesn’t protect you from:
— A provider being breached and your encrypted vault becoming an offline cracking target for however long it takes hardware to catch up to whatever encryption standard is in use today
— A provider going out of business or being acquired, and you having to scramble to migrate your vault under pressure
— A provider’s practices diverging from their stated architecture in ways that aren’t visible to you
None of these are inevitable. But they’re the things that local storage eliminates by design. KeePassXC can’t be breached at the provider level because there is no provider level. The trade-off is that you become responsible for your own backups, your own sync setup, and your own disaster recovery plan.
Whether that trade-off is worth it depends on factors that only you know: how sensitive your accounts are, what environment you’re working in, how technically comfortable you are with running your own infrastructure.
The recovery question cuts both ways
Here’s the part that doesn’t get talked about enough.
Cloud managers — both Bitwarden and 1Password — offer managed recovery options. 1Password has recovery kits for family accounts. Bitwarden has emergency access features where you designate a trusted contact who can get in after a waiting period. If you forget your master password, you have paths to getting back in.
KeePass has no recovery option. Forget your master password, or lose your key file, and the data is gone. That’s the design. The absence of a backdoor is the security feature.
I spent a month using all three. Here’s what I actually noticed: the KeePass discipline feels like a financial decision you make once and then maintain. You set up your backup routine, you store a recovery document in a sensible physical location, and you don’t think about it again. The cloud managers feel more like subscription relationships — convenient, frictionless, but fundamentally involving ongoing trust in another organization’s competence and continuity.
Neither framing is wrong. They’re just different.
What the ANSSI certification actually tells you
This is worth spending a moment on, because I’ve seen it mentioned in passing and then left unexplained.
ANSSI — France’s national cybersecurity agency — runs a certification process that involves real penetration testing and cryptographic implementation review, not just a checklist audit. Getting a First-Level Security Visa from them means your software has been attacked by people whose job is finding what’s wrong with it.
For KeePassXC, this is meaningful because it validates the open-source, community-audited development model in a government-backed way. It’s particularly relevant for environments where cloud services are prohibited by policy — regulated industries, government contractors, healthcare organizations handling sensitive information.
For most individuals, you don’t need this certification specifically. But what it signals matters: an independent body with serious technical credibility reviewed the security claims and found them to hold up.
How to actually choose
I’ll skip the flowchart. You’ve seen those.
Instead: what’s the most sensitive thing in your password manager right now? Think about it for a second.
If it’s your Netflix and Amazon passwords, the threat model differences between these three tools are largely academic. Use whichever one you’ll actually stick with.
If it’s access to financial accounts, healthcare systems, client data, legal documents, or anything with real consequences attached to compromise — the question of where that vault lives is worth taking seriously.
Technical users who want full sovereignty and are comfortable managing their own infrastructure: KeePassXC is the honest answer. The ANSSI certification gives you something concrete to point to if you’re in a regulated environment.
People who want flexibility and open-source transparency without committing to full self-hosting right now: Bitwarden’s hybrid model is genuinely well-designed. You can start with the cloud service and migrate to self-hosted if your needs change.
People who want a polished experience, family or team sharing features, and layered security without technical overhead: 1Password’s Secret Key architecture does what it claims, and 21 years of operational history counts for something.
The honest answer is that any of these, used consistently and correctly, will protect you far better than the alternative — which is reusing passwords and hoping.
Start there. Get more specific as you understand your own threat model better. And maybe stop judging the choice by which one has the better browser extension.
TechEd Publishers helps everyday technology users navigate complex security decisions with clear, jargon-free guidance.
Originally published on TechEd Publishers blog. For more articles like this, visit https://techedpublishers.com/.
메타데이터
- post_id
- a2d67ee1f6ad
- slug
- i-spent-a-month-living-with-all-three-password-managers-a2d67ee1f6ad
- url
- https://medium.com/@ed_22350/i-spent-a-month-living-with-all-three-password-managers-a2d67ee1f6ad
- canonical_url
- https://medium.com/@ed_22350/i-spent-a-month-living-with-all-three-password-managers-a2d67ee1f6ad
- author_url
- https://medium.com/@ed_22350
- status
- ok
- fetched_at
- 2026-06-22 05:41:33