Live data from Hacker News

Bitwarden: Free, open-source password manager

bitwarden.com

171–180 of 242 posts

Re: Bitwarden: Free, open-source password manager

#171
post #21
post #11

Earlier quoted context omitted.

Absolutely. Keepass gives you only a file that you have to sync by yourself and when you have multiple device editing the same file... Well... On the other hand, Bitwarden lets you self-host a complete server that handles everything. If you want something less resources intensive you can take a look at Vaultwarden which is a re-implementation of the server in Rust instead of C#. The main advantage is that it uses MyS…

It is funny, because to me "only a file you have to sync (and backup)" sounds more like an advantage than setting up an entire server environment just so you can access your passwords.

Meh, heavily depends on your setup. The lack of good apps on mobile devices that integrate with their respective OS (iOS/android) is a bit of a problem. It's also 3rd party apps (some closed source) and not official ones which is its own problem (-> trust).

Apart from that bitwarden is just wayyy easier, you simply tell the (official) app the URL to your vault and it's basically good to go. You don't have to worry about synchronization one bit. The app is also fairly nice and has all the features you need. Bitwarden also does the browser integration well, unlike keepass where it's a major pia.

Re: Bitwarden: Free, open-source password manager

#172
I’ve strongly considered to migrate from Keepassxc to Bitwarden for making things simpler. At the moment, the way I use Keepass is: password + only storing the db on Google Drive + adding the key file to any device I want to access from (smartphone and laptop) via usb cable. This way I can keep the db up to date across devices while keeping it “safe” as the key file is not being shared across the network.

So, as I said, I’ve considered Bitwarden for being open source and cheap and for simplicity but despite reading the implementation they do and knowing they have had successful audits the paranoid in my cannot stop thinking on the “what ifs”. I have all my life on Keepass: from access to the bank, to government taxes stuff, to the pi-hole web ui etc etc. I feel I have more control now with my clunky approach. If I migrate to a managed solution and for any reason my data gets compromised on their side I would be utterly fucked.

Probably it’s just me being irrational.

Re: Bitwarden: Free, open-source password manager

#174
post #21

Earlier quoted context omitted.

It is funny, because to me "only a file you have to sync (and backup)" sounds more like an advantage than setting up an entire server environment just so you can access your passwords.

Meh, heavily depends on your setup. The lack of good apps on mobile devices that integrate with their respective OS (iOS/android) is a bit of a problem. It's also 3rd party apps (some closed source) and not official ones which is its own problem (-> trust). Apart from that bitwarden is just wayyy easier, you simply tell the (official) app the URL to your vault and it's basically good to go. You don't have to worry ab…

Are you using Vaultwarden?

Re: Bitwarden: Free, open-source password manager

#175
post #103

Earlier quoted context omitted.

Are all clients open source? If I loose all my keys is there no way to recover the data? And how does this work when I share passwords with my colleagues in a vault? They dont have my "client generated secret key", so how can they read my passwords? I know companies write stuff to sell their products, but I dont trust that, I prefer open source and the laws of logic over marketing.

If you loose bitwarden keys what will they do to recover data? They have similar security protocols so I doubt being open source would help that. It's not about being open source or not. That's just security 1Password says explicitly that you're not sharing the actual item in your vault and that it's creating a copy of it. It's probably generated client side and pushed to an external sharing service I mean, I underst…

>If you loose bitwarden keys what will they do to recover data?

They cannot. That's closely related to why it is so secure, and why they can never see you data. That's why I use it.

It's sometimes called "zero knowledge".

> 1Password has been audited and has been an industry standard for a while.

MSFT products were also audited, and much used, and very insecure. Also 1Pass may be subpoena'd into sharing your data. I do not trust 1Pass, but you do you and feel free to do trust them :)

Re: Bitwarden: Free, open-source password manager

#176
post #37

> The most trusted open source password manager for business I expected a blog article with actual feedbacks from companies and data, but ended up on bitwarden.com main page. Baseless claims can be quite common when it comes to marketing, but I'm genuinely curious: which password manager is used in your workplace, if any? I've personally never seen in my (for now short) career anything else than Keepass.

I agree, this is the sort of statement that should be backed up by... something.

But we do use Bitwarden where I work (large enterprise software vendor). Adoption is not consistent, but it's the IT supported solution here.

Re: Bitwarden: Free, open-source password manager

#177
post #141

Earlier quoted context omitted.

We use Lastpass; I've never been a big fan of the sharing features. I use Bitwarden for personal use.

I moved to Bitwarden from Lastpass last year. Ironically I remember needing some premium feature, and having issues subscribing to premium. Support was 0/10, and made me move to Bitwarden, but I was really happy with Lastpass. Feature I miss today is security checkup.

Glad it wasn't just me. I was trying to get a repeatable issue with a particular site resolved, and support was beyond useless, i.e. unresponsive for up to two weeks, repeating the same scripted BS they had sent me previously, etc. Despite my pleading I was never able to get to a level 2 where someone could actually look at my problem.

Re: Bitwarden: Free, open-source password manager

#178
post #122
post #103

Earlier quoted context omitted.

Are all clients open source? If I loose all my keys is there no way to recover the data? And how does this work when I share passwords with my colleagues in a vault? They dont have my "client generated secret key", so how can they read my passwords? I know companies write stuff to sell their products, but I dont trust that, I prefer open source and the laws of logic over marketing.

1Password has a pretty good white paper explaining their security design (PDF behind the link): https://1passwordstatic.com/files/security/1password-white-p... . The parts "How Vault Items Are Secured" and "How Vaults Are Securely Shared" go into sharing passwords in a vault. For the record, Bitwarden's white paper is a good read as well. Available at https://bitwarden.com/help/article/bitwarden-security-white-... .…

So I'm reading on pg 22. The red block. How hard is it for 1Pass --basically a mandated MITM-- to send a false request to Alice when Bob made a request?

That whitepaper is a piece of marketing text. Not saying their audit did not take place. But they are soooooo powerful in their own system that they basically have access to everything.

BitWarden: not so much.

Re: Bitwarden: Free, open-source password manager

#180
post #4

Earlier quoted context omitted.

I just switched to it from LastPass which, well, has even worse UX in my opinion. It's an extremely low bar to clear and I agree Bitwarden is quirky too, but for me it's still firmly been an upgrade. The only thing I miss is an "add to bitwarden?" dialog when I sign up somewhere. Their docs say it exists but I've never managed to get it to appear :-)

Is there a simple way to make this transition from LastPass to BW?

[deleted]
Post reply on HN