Live data from Hacker News

Bitwarden – Open Source Password Manager

bitwarden.com

91–100 of 163 posts

Re: Bitwarden – Open Source Password Manager

#91
post #89
post #81

Seriously? A password manager where the desktop app is build ontop of unsecure electron.

I get that Electron is undesirable, but what do you mean by unsecure? Also, can you list some alternatives if you don't want them building a desktop app in Electron?

Malware can sweep through the memory to find passwords by reading memory directly from another process' address space.

Re: Bitwarden – Open Source Password Manager

#92
post #79

https://github.com/bitwarden/core/blob/master/README.md SQL Server 2017, really? Interesting choice. Open source but we have to pay licenses for the database if we want to self host. I wonder what was wrong with PostgreSQL or MySQL even if they're using .NET Core as a language. Edit: there is an issue for that https://github.com/bitwarden/core/issues/10

> Open source but we have to pay licenses for the database if we want to self host.

As Bitwarden states in the core readme (https://github.com/bitwarden/core#requirements) "These dependencies are free to use." And if you lookup the licensing on MSFTs website (https://www.microsoft.com/en-us/sql-server/sql-server-2017-p...) you can see that the SQL Server Express version is free.

Note: No, I'm not an MSFT employee and not related in any way to the mentioned company. I'm just a (not so regular) human being who first looks up information before posting statements.

Re: Bitwarden – Open Source Password Manager

#93

I switched from LastPass to bitwarden in November, and I love it. - it's FOSS, and audited, so it's software I can trust - great UX on Firefox, chrome, and even Edge. I had my issues, but the project improved them away very quickly. - sharing support for families or organizations. - convenient standalone clients for win/Mac/Linux... And even the CLI. - built in 2FA code generation for each entry, so I don't need a se…

There's a bounty program but AFAIK there hasn't been an audit yet: https://github.com/bitwarden/core/issues/27

Re: Bitwarden – Open Source Password Manager

#98
post #22

I really, really want to be a big fan of Bitwarden. I even used it for the past year and a half. However, the last time HN talked about Bitwarden 7 months ago, I listed some reasons[0] why Bitwarden still fell massively short of 1Password, and I feel that those three points have not been addressed (which I believe impacts the friction/convenience of using Bitwarden). My three points then were: 1. A stand-alone deskto…

I used 1Password for years on iOS and stored my Vault in iCloud. But AgileBits’s intention to change to subscription model was a deal breaker. Then they made some bad design decisions at the time of iOS 11 upgrade. I lost my vault, and given their hostility towards non-subscribers, I no longer feel comfortable trusting the product won’t fail again. I changed to BitWarden to handle my low-level net passwords, and that’s perfectly adequate.

Re: Bitwarden – Open Source Password Manager

#99
post #35

Earlier quoted context omitted.

Maybe it's just my phone (6) but you may find that once you get 1000+ logins, Bitwarden falls apart pretty quickly. I've heard the same from people with 800+ logins. I remember it used to be very quick when I initially used it with a few plugins. IIRC from their Github issue threads, Bitwarden is using Xamarin, and performant UI has been a consistent struggle with many login entries.

how in God's name do you end up with _thousands_ of logins, or even 800? I work in a pretty large MSP in IT with tons of different programs, websites, and clients. Even if I added every single password (which I most surely would not do), I can't imagine there being more than two or three hundred. Conservatively, if every of two hundred clients has thirty passwords, that's still only 600.

Well, I don’t have 1000+ logins. Especially not among those I use frequently. However, I use password manager for far more than just logins.

Also, having combed through my entire catalog by having to manually import Bitwarden to 1Password, I’ve realized all those random startups I’ve made a login for or various sites for applications (job/school/etc) really add up quickly!

Re: Bitwarden – Open Source Password Manager

#100
post #22

I really, really want to be a big fan of Bitwarden. I even used it for the past year and a half. However, the last time HN talked about Bitwarden 7 months ago, I listed some reasons[0] why Bitwarden still fell massively short of 1Password, and I feel that those three points have not been addressed (which I believe impacts the friction/convenience of using Bitwarden). My three points then were: 1. A stand-alone deskto…

Someone else pointed it out but it’s worth repeating that the convenience of having your 2FA on your laptop/desktop might be making a significant security trade off. It’s not really 2FA if it’s on the same device.

That’s true. I had lost sight of that... well, I wish more places would support a Yubikey!
Post reply on HN