Comment by Aachen

2 days ago

PrivacyGuides (mentioned in a sibling comment) usually has some strange logic for what makes something a good option but it's broadly useful to get some options and ideas

My answer is to more generally look for what's been around, whose authors haven't turned out to be malicious (even after 10+ years of being popular enough that they'd get the motherlode with one malicious update), have had good security responses and seemingly good security practices... so basically look at the oldest thing that meets your needs and search e.g. HN and read its Wikipedia to find out about any red flags. Compare that to two runner-ups

A specific feature I'd recommend is phishing-resistant browser integration, that is, autofill for the browser but it only suggests passwords that you've stored specifically for this website. If another domain asks for it, it shouldn't suggest it and that then raises alarm bells of like "did the website change domains or is someone pretending to be them?". There have been bugs in browser integrations but it's not that regular, you still need to be among the unlucky few that visit a malicious website or ad before it gets found out and fixed, and my professional opinion is that it's easily worth it (our company helps with custom/targeted phishing simulations) - just like the having of a password manager (single point of failure for (nearly) all your credentials) is a tradeoff in the first place that seems to generally pay off. Perhaps memorise a few strong passwords though, like for bank/broker login and such things that would be truly disastrous and also likely that someone has a use for the thing they hack (they're not going to care about your nudes nearly as much as when they can drain hard cash)