Live data from Hacker News

Bitwarden: Free, open-source password manager

bitwarden.com

121–130 of 242 posts

Re: Bitwarden: Free, open-source password manager

#121
post #48
post #29

Earlier quoted context omitted.

It has asked me lots of times, but just yesterday it didn't for a new account in none less than google.com. Its code to detect when to ask must be... weak, to say the least. So I went on to add a new entry manually. Oh my, the UX to do so is quite bad. There is such low hanging fruit here for improvement, like copying the "UI on a new tab" style that LastPass does... meanwhile Bitwarden insists on doing everything on…

Bitwarden has quite a few of these sad quirks. It doesn't work very well in Firefox's private browsing. Only thing you can do is autofill by right clicking a text field and autofill from there, or the keyboard shortcut. But you cannot unlock it in private browsing. Stateless UI is annoying at best. There's a few times where this has slipped my mind, so I paste a generated password in a new item, and then go to copy t…

The Bitwarden browser extension has a page with the history of generated passwords which might help

Re: Bitwarden: Free, open-source password manager

#122
post #103

Earlier quoted context omitted.

1Password's servers also cannot read your data. They use a client generated secret key in addition to your usual password to encrypt your vaults. It's been detailed pretty well https://support.1password.com/secret-key-security/

Are all clients open source? If I loose all my keys is there no way to recover the data? And how does this work when I share passwords with my colleagues in a vault? They dont have my "client generated secret key", so how can they read my passwords? I know companies write stuff to sell their products, but I dont trust that, I prefer open source and the laws of logic over marketing.

1Password has a pretty good white paper explaining their security design (PDF behind the link): https://1passwordstatic.com/files/security/1password-white-p.... The parts "How Vault Items Are Secured" and "How Vaults Are Securely Shared" go into sharing passwords in a vault.

For the record, Bitwarden's white paper is a good read as well. Available at https://bitwarden.com/help/article/bitwarden-security-white-....

(edit: fixed typos)

Re: Bitwarden: Free, open-source password manager

#124
post #37

> The most trusted open source password manager for business I expected a blog article with actual feedbacks from companies and data, but ended up on bitwarden.com main page. Baseless claims can be quite common when it comes to marketing, but I'm genuinely curious: which password manager is used in your workplace, if any? I've personally never seen in my (for now short) career anything else than Keepass.

> I've personally never seen in my (for now short) career anything else than Keepass. KeePass ( https://keepass.info/ ) is excellent for personal usage or for infrequently changing credentials in a team setting, which is why i've also had a good run with it! That said, for something a bit more centralized and more easily manageable, i've seen solutions like TeamPass be used: https://teampass.net/ Well, TeamPass in pa…

The nice thing with keepass is that you manage the password database and key yourself.

Re: Bitwarden: Free, open-source password manager

#125
post #96
post #90

There’s a critical feature missing from Bitwarden that is keeping my on 1Password: - history It’s saved me enough times that I can’t move to a manager that doesn’t record history.

Wait, you mean password history? As in being able to see the old password once you generate a new one or otherwise update it? Because Bitwarden definitely has that.

Spun up a Vaultwarden docker and gave it a try. You are correct, it does have password history. That's great. It was probably there the whole time and I didn't notice when I evaluated last.

I see it doesn't have history anywhere else, such as secure notes, which 1password does have.

Might still be too tough to give up the extra types and tags, but having history on the passwords is a great step. Quite tempting indeed.

Re: Bitwarden: Free, open-source password manager

#126
post #98
post #90

There’s a critical feature missing from Bitwarden that is keeping my on 1Password: - history It’s saved me enough times that I can’t move to a manager that doesn’t record history.

Seems like they have some version of it implemented: > Q: I need an old password! Can I view the history of a password that I changed in Bitwarden? > A: Yes! You can view the last 5 passwords for any Login Item. Open the item in question and select the “1” next to Password History near the bottom of the window. https://bitwarden.com/help/article/product-faqs/

Seems like only on passwords, but great that it does at least have it on passwords!

Re: Bitwarden: Free, open-source password manager

#127
I frankly thing password managers are the most stupid thing.

We fake users inputing text to input boxes and spend crazy time figuring out how to do that and how to get around various sites trying to block that, so the site can still pretend it’s actual user inputting the password. Plus the manager needs to work around arbitrary password rules. Plus they usually don’t work at OS level; so you still need to remember that stupid iTunes password, that stupid Windows password, that stupid Google password on Android login. Plus you still need random PINs in random banks and other systems.

It’s better than memorizing, of course, and slightly better than writing it on paper somewhere (although that’s actually not that horrible honestly).

It’s just, they feel like a patch-fix from 1990s to a problem from 1990s.

I don’t want password manager. I wish I didn’t need password manager.

Re: Bitwarden: Free, open-source password manager

#128
post #37

> The most trusted open source password manager for business I expected a blog article with actual feedbacks from companies and data, but ended up on bitwarden.com main page. Baseless claims can be quite common when it comes to marketing, but I'm genuinely curious: which password manager is used in your workplace, if any? I've personally never seen in my (for now short) career anything else than Keepass.

LastPass, everyone hates it including me.

Re: Bitwarden: Free, open-source password manager

#129

Earlier quoted context omitted.

I wouldn't consider 4 $ per month a low cost for a password manager

Of course it's all relative. $4 is infinitely more than $0. On the other hand, $4 for keeping my most important secrets safe is cheap.

It's not only about money, but also privacy. Services like these shouldn't know who their customers are.

Re: Bitwarden: Free, open-source password manager

#130
post #37

> The most trusted open source password manager for business I expected a blog article with actual feedbacks from companies and data, but ended up on bitwarden.com main page. Baseless claims can be quite common when it comes to marketing, but I'm genuinely curious: which password manager is used in your workplace, if any? I've personally never seen in my (for now short) career anything else than Keepass.

Any experience with Secret server from thycotic?

I've used it before, it sucks.

It does the job, but very poorly. Same as LastPass.

I use 1Password now. If I didn't want to pay for it I'd use KeePass.

Post reply on HN