Live data from Hacker News

Bitwarden – Open Source Password Manager

bitwarden.com

131–140 of 163 posts

Re: Bitwarden – Open Source Password Manager

#131
post #79

https://github.com/bitwarden/core/blob/master/README.md SQL Server 2017, really? Interesting choice. Open source but we have to pay licenses for the database if we want to self host. I wonder what was wrong with PostgreSQL or MySQL even if they're using .NET Core as a language. Edit: there is an issue for that https://github.com/bitwarden/core/issues/10

Having worked with many RDBMSs in the past, MSSQL is one of the very few that I would recommend for new installations.

Basically, my flow chart for DB selection:

Do you have an enterprise worth of money to burn on the deployment and maintenance? Oracle.

Are you deploying to Windows? MSSQL.

Else: Postgres.

Re: Bitwarden – Open Source Password Manager

#132
post #75

Earlier quoted context omitted.

Very thorough argument.

Matches the question, but should be obvious why. I do not have the inclination or resources to secure and keep my server up to date, unless we are talking about a periodic "apt upgrade" that I could configure to run automatically, but no more than that. And at the very least I know how to reasonably secure a Linux server, at least initially. If running your own server gives you peace of mind in terms of security, the…

> running your own Wordpress is one of the worst thing you can do on your own server, putting your whole server at risk, not just your website.

My personal experience says this is 100% true.

Even when I've managed to stay on top of WP updates my server is invariably targeted more often by automated attacks more often than others that are hosting static sites and other frameworks. I strongly suspect that attackers maintain lists of server addresses that host WordPress sites and use that to make assumptions about their running services. If they know that it's a "self-hosted" webserver, even if they can't break WordPress there's a very good chance that some other unmatched vulnerability exists.

Re: Bitwarden – Open Source Password Manager

#133
post #75

Earlier quoted context omitted.

Very thorough argument.

Matches the question, but should be obvious why. I do not have the inclination or resources to secure and keep my server up to date, unless we are talking about a periodic "apt upgrade" that I could configure to run automatically, but no more than that. And at the very least I know how to reasonably secure a Linux server, at least initially. If running your own server gives you peace of mind in terms of security, the…

> If running your own server gives you peace of mind in terms of security, then read more about how security works and the threat model you'll face.

I don't know about this argument. On the one hand you can configure something as secure as you like/can, on the other hand you have to trust other people to do their best. If you don't trust them with your passwords, you would also not trust them to do their best.

If you host yourself a paranoid me would host their instance accessible only inside a stable VPN xor by tunneling a port via SSH.

Re: Bitwarden – Open Source Password Manager

#134

Earlier quoted context omitted.

I'm not in the Microsoft stack so I have no idea how much SQL Server and SQL Server Express are compatible. I only know they exist. The README requires SQL Server so I might be excused thinking that it would work only with that software. Nice to know that it does work on the free version too. I googled and looked on MS site and didn't find out if SQL Server Express exists for Linux too, but I'm on my phone right now.…

> I googled and looked on MS site and didn't find out if SQL Server Express exists for Linux too, but I'm on my phone right now. There you go: https://hub.docker.com/r/microsoft/mssql-server-linux/ :)

Thanks. Same binary for both versions but setting an environment variable makes it switch to Express.

Re: Bitwarden – Open Source Password Manager

#135
post #104
post #39

Earlier quoted context omitted.

I've been a 1Password user for about 10 years, but I never moved to 1Password 6, as I didn't want to sync my vault to their servers (even if it's E2E encrypted). I've moved from being primarily an OSX user to Linux, and as a result, my experience has progressively gotten worse enough on 1PW (broken FF extension, general jankiness running on Wine) that I'm finally looking switch off, either to KeePassXC or to Bitwarde…

You don't have to sync your vault in 1Password 6.

Nor in 1Password 7 (the latest version). They do push it pretty hard, and given their evasiveness/dishonesty about the business implications of subscriptions and the push I wouldn't blame anyone for being concerned that stand alone license+vault support might be removed in a future version (they have said there will be no more free version updates IIRC though). However, for the time being subscriptions and 1P's cloud service remain optional and possibly disappointing only in terms of eliminating what might have been, not anything that already existed.

Re: Bitwarden – Open Source Password Manager

#136
post #26

This looks like it could be better than LastPass. Bitwarden is the only password manager that I've seen that officially supports Opera, Vivaldi, and Brave. I wonder what the browser support on Android is like. LastPass seems to work only on Chrome on Android, but I like to use Firefox, Opera, and Samsung's optimized browser.

> Bitwarden is the only password manager that I've seen that officially supports Opera, Vivaldi, and Brave.

Brave bundles their extensions, and have gone months between updates in the past. Be aware of that if you use it, as it's a potential security issue with a password manager.

> I wonder what the browser support on Android is like.

Android support is excellent. The only nagging issue I had was that the "URL" for an app is usually something like "com.github", while the URL stored in the login is "github.com". Bitwarden is good about partial matches, so it's rare that I had to search for the login I wanted.

> LastPass seems to work only on Chrome on Android, but I like to use Firefox, Opera, and Samsung's optimized browser.

I moved off Android a few months ago, but I was using Brave and Bitwarden integrated seamlessly. It ties in to the "accessibility" framework I think, and offers an option in the system dropdown menu when a login is detected.

Re: Bitwarden – Open Source Password Manager

#137

I switched from LastPass to bitwarden in November, and I love it. - it's FOSS, and audited, so it's software I can trust - great UX on Firefox, chrome, and even Edge. I had my issues, but the project improved them away very quickly. - sharing support for families or organizations. - convenient standalone clients for win/Mac/Linux... And even the CLI. - built in 2FA code generation for each entry, so I don't need a se…

Can it import Keepass DBs? I dread retyping all my passwords.

Re: Bitwarden – Open Source Password Manager

#138

I like Enpass. Syncs to my own nextcloud. What other password managers can do that out of interest?

I also use Enpass. It needs more of a mention in these threads.

I suspect Enpass doesn't get much mention on HN threads because it is not (or at least, does not obviously appear to be) open source, which I've observed is of paramount interest to a large number of HN readers -- full disclosure: including me.

Because it is not open source [0], we must take statements like the following purely on faith in their PR department, rather than being able to independently verify:

https://www.enpass.io/kb/if-enpass-is-an-offline-password-ma...

"Indeed Enpass is an offline password manager and saves your data locally on your device and in any case, we do not (and we can not) access any of your data. But yes, Enpass does connect to the internet with the sole purpose to give best user experience."

I'm sure they're really nice people, and do their best, etc, etc, but passwords are the linchpin crown jewels. Enpass could secretly and instantaneously become bad actors or incompetent stewards of said crown jewels, and we wouldn't know, since we cannot see what they are doing. One of many risks I would not take.

[0] Please correct me if my search-engine-fu is weak today, but I can find no official Enpass open source repos or code anywhere.

Re: Bitwarden – Open Source Password Manager

#139
What I really like about Bitwarden is, that you can define several URLs for one entry, I have some services which can be accessed from several addresses (same account) though.

It is also possible to define how a URL is matched which is a nice feature too.

Re: Bitwarden – Open Source Password Manager

#140

Earlier quoted context omitted.

> I googled and looked on MS site and didn't find out if SQL Server Express exists for Linux too, but I'm on my phone right now. There you go: https://hub.docker.com/r/microsoft/mssql-server-linux/ :)

Thanks. Same binary for both versions but setting an environment variable makes it switch to Express.

right.
Post reply on HN