r/PasswordManagers • u/Lumpy-Army-1702 • 7d ago
AI-Slop Password Managers
Seeing many people now attempting to create password managers. AI is making it easier now, which worries me a lot. I've been in the cybersecurity industry for quite a while now and have seen huge problems with password managers, especially new ones that focus on local-first, offline-first, air-gapped (fill in your AI-slop buzzword here), without understanding that's not where the security enforcement should rely.
Every day on HN and Reddit now, it’s the exact same post:
Tired of Bitwarden (1Pass, LastPass, ...), so I spent the last couple of months building VaultSlopAI, a zero-knowledge, local-first, air-gapped, post-quantum-ready password manager written from scratch with next-gen semantic entropy.
...and people are going to lose their life savings over hallucinatory XOR ciphers.
Every single one of them:
- "Air-gapped architecture" (Bro, you just disabled network permissions in the Electron manifest).
- "Local-first sovereign vault" (It writes unpadded base64 to localStorage and calls it a day).
- "Self-healing zero-knowledge enclave" (Literally just crypto.getRandomValues() wrapped inside a buggy Next.js server action).
Can we please go back to letting boring, audited, battle-tested tools manage our digital lives instead of downloading 400MB of hallucinated Tailwind wrappers masquerading as military-grade security?
(Ohh and yes, I’m building one too 😄 except I’ve actually worked in cybersecurity for years, know how the primitives work, and didn’t just vibe/slop prompt the entire architecture over a weekend.)
10
u/fdbryant3 7d ago
I have to wonder if anyone is actually downloading one these password managers over the more well known and vetted alternatives. I kinda feel if they are, they deserve whatever comes of it.
3
8
6
u/djasonpenney 7d ago
Where I lose patience is that these authors just don’t have any sense of prior art. You get a big nothing when you ask them to compare their “innovative” password manager to Bitwarden, KeePass, or even 🤦♂️ Apple Passwords.
If you do not know enough to compare and contrast your app with these industry leaders, I don’t have time for you either.
4
u/VB0101 6d ago
I don't necessarily hate on vibe coded projects, but password managers? How dense do you have to be to think security conscious users will trust their credentials to their BS when free, open source, and battle tested solution exists. Not only are they terrible developers, even worse businessmen.
2
u/Revolutionary_Gap183 6d ago
i had built one and use it, but never shipped it coz the trust you need to put in password manager is a lot. i wont download some ones product and use so i will not expect people to use mine. it works for me i am happy.
2
u/jpgoldberg 7d ago
How will you convince people that they should trust your product with their passwords? Will your source code be public or reviewed by external trusted experts? Will you be publishing it under your real name so that we can actually look,at your résumé?
Ranting about everyone and their dog thinking that they can create a password manager that people will trust is fine. I do plenty of that myself. But until you demonstrate otherwise, for all we know you are just rebranding and reskinning slop that has been already been thrown at us.
By the way, I really do have the résumé, but despite my considerable experience and expertise I would wouldn’t trust my own efforts without a great deal of external review.
2
u/billdietrich1 6d ago
There has to be some way (in general, for all types of apps) to hand-craft the important modules and then AI-slop the other stuff (UI, mainly). And tell the AI never to mess with the hand-crafted parts.
1
u/travisjd2012 5d ago
This is kind of rich given most complaints around all of the traditional password managers are bad UX/UI
Also, computers understand programming, encryption, and math far better than they do design and usability.
That said, I'm not making my own password manager either way.
2
u/giannis_athina 6d ago
AI has made it really easy for people to build just about anything, but getting something to work is one thing, actually understanding what you’ve built and knowing how to keep it secure is another. Especially with a password manager, you need to know what vulnerabilities to look for, how to deal with bugs when they come up, and have the technical knowledge to keep it secure long term. That’s why I stick with RoboForm. It’s been around for years, and when I’m trusting something with all my passwords, I want the people behind it to actually know what they’re doing and be committed to keeping it secure long term.
1
u/Awkward_Leah 6d ago
I think I'd focus more on whether the pm has a good track record. I've been using roboform and haven't had issues with it
1
u/rubixstudios 5d ago
I look at the repos see there's like 5 commits and some absurd amount of commenting cause no real person writes a full dictionary for comments in one hit, close repo, never look at it again.
Look for some extremely named function and file, lack of project structure or people who simply don't know how that framework generally is structured, also close and never look again.
On another note, sometimes its fun looking at what crazy ideas these guys have, just learn from it, write up your own and make it secure and better, chuckle cause they wasted all that token and money on rubbish.
1
u/DCCXVIII 7d ago
I mean, whilst I agree with you, at the same time, it's on people to do at least a modicum of due diligence before deciding who to entrust what is effectively they're entire lives to.
Joe Blow's "password manager 5000" should raise more alarm bells than say, Bitwarden or KeepassXC for example.
1
u/jabbeboy 6d ago
Yes, im really against all solutions that people develop for a problem that does not exist.
Bitwarden is absolutely good enough and free.
1
u/IllustriousGap5629 6d ago
Agree. Let cybersec companies do the job. I used Bitwarden in the past, now I use 2FAS Pass. I’m not giving my data to some random dude on Reddit, sorry.
0
1
13
u/Orange_Kittens1132 7d ago
for pwm, its better to use keepass, bitwarden, or 1password. period.