1Password offers the higher level of security imo with the use of the secret key. Basically, if I use proton's password manager, then If my password used for my email is compromised, that also means my password manager - I'm not really liking that at all.
Being the 1PW Remigrant thread, I would want any contender to offer something more then what 1PW offers, I'm not seeing that with Proton.
Good point about the security flaw but I think like other Proton service I have seen it would go to a much better product in the future. I think they worked too much on the security aspect and features are coming in the future.
The way I would do it is I would have a separate Proton account just for my password manager, the paid version is $1/M .
“Not related to my point. SQLCipher is probably great, but there's a whole application wrapping it which is an unknown.”
It absolutely is related to your point! The same people who developed SQLCipher wrote Codebook. They have been developing a password manager for a quarter of a century without any issues, and yet you make comments like, “I have no reason to trust it.” I don’t get your logic.
“For example, 1Password is careful to clear the clipboard of passwords after a bit. Does Codebook do that?”
Yes. From the documentation: “Codebook automatically wipes secrets from the system clipboard after 2 minutes.”
I don’t view Codebook in the same vein as KeePass. Everything in Codebook was created by the same developers, whereas many unrelated folks have had their hands in KeePass. Zetetic is a commercial company in the full time business of creating security products. KeePass is an internet cluster..... I would never use KeePass!
I must say that just because the person behind is competent , doesn't mean the work itself is great. Sometimes "competent" people do not do such a great job at some of their work and this can be seen across all professions. As much as Apple creates good hardware they do have a track of failed products.
Unless, of course, you don't keep your vault in some SaaS, thereby eliminating any hack, let alone potential for a hack. Hence, why people would rather have standalone vaults, like what 1Password used to offer. Paying the single price upfront for the permanent use of a standalone vault makes that single cost so much more valuable than paying monthly for something that could potentially be hacked because one is putting their credentials in the trust of someone else.
BL.
you can have subscription and local vault, can you not? Not that I support subscription model.