Live data from Hacker News

Bitwarden: Free, open-source password manager

bitwarden.com

161–170 of 306 posts

Re: Bitwarden: Free, open-source password manager

#161

FYI - Bitwarden took $100M in VC money last year. At some point, the pressure to aggressively monetize will unfortunately happen. https://techcrunch.com/2022/09/06/open-source-password-manag...

What could a password managing service possibly need this amount of money for - or worse - what could they possibly plan to be doing with it to convince the VC that they will get even more money back from this deal?

1password is going enterprise.

Re: Bitwarden: Free, open-source password manager

#162
post #127

Earlier quoted context omitted.

Bitwarden has had VC investors for years, long before the mentioned 2022 funding. I think our track record to date shows how we operate in this relationship. We specifically choose partners that align with our vision, not just anyone that comes off the street wanting to throw money at us (though there are many). Our health as a company afford us this luxury. Bitwarden is and has been monetized since the beginning. Th…

Thanks, then this all seems to be much ado about nothing. Cheers!

that or check back in a year when the founder will say, "... the realaties of the market..."

Re: Bitwarden: Free, open-source password manager

#163

I wanted to like Bitwarden, due to its “open source” nature. But 1Password is really miles ahead, and it's a little ironic, as 1Password 8 went through a major refactoring to a Node-enabled UI, which many people disliked, and it's still miles and miles ahead. I tried teaching my father to use Bitwarden for the sole reason that it seemed to be translated into my native tongue. In his use, Bitwarden turned out to be co…

Kind of apples to orange with 1Password not being open source or having a free tier.

There are small issues with autocomplete on mobile here and there, which I have never seen a password manager do a perfect job at. Otherwise I have never had any issues with BW and the 2fa on the paid tier is great.

Re: Bitwarden: Free, open-source password manager

#164
post #79

Earlier quoted context omitted.

Interesting. If say 3 passwords using that algorithm leaked, would it be possible to deduce the algorithm itself? Edit: what about digit-only password?

With a password manager, you only need to know 1 password to "deduce" all the others. So wouldn't a 3-password system be better anyway?

The difference is that the one password for the manager is kept in a location very difficult to attack, whereas various services are inevitably prone to be pwned.

Re: Bitwarden: Free, open-source password manager

#165
For anyone that's interested in self-hosting Bitwarden on your server, I would highly recommend checking out the Rust implementation, Vaultwarden. It takes less resources to run, doesn't paywall certain features (I.E MFA logins), and (in my experience) has been a lot easier to work with compared to the official client.

https://github.com/dani-garcia/vaultwarden

Re: Bitwarden: Free, open-source password manager

#166

FYI - Bitwarden took $100M in VC money last year. At some point, the pressure to aggressively monetize will unfortunately happen. https://techcrunch.com/2022/09/06/open-source-password-manag...

The flack bitwarden takes in almost every submission about how they are tainted because of VC investments is getting boring.

Re: Bitwarden: Free, open-source password manager

#167
post #92

Earlier quoted context omitted.

Unfortunately 1Password doesnt have the main feature that most of us are probably using bitwarden for, self hosting. EDIT: I have just noticed this. Everyone whos interest should submit! https://survey.1password.com/self-host/

and 1Password doesn't work from behind corp proxies with custom traffic inspection certs

It does fine here

Re: Bitwarden: Free, open-source password manager

#168
post #157
post #57

The title is misleading. This is not fully "free and open-source". I'm actually puzzled by the licensing structure. Bitwarden server is dual-licensed [1] - part of it is licensed with AGPL (Open Source) - some features are licensed with a source available Bitwarden license Now, even the Open Source core requires you to register if you want to self host. This is to provide you with complementary services like security…

Why does everyone assume that if something is open source it must also be free and licensed under permissive license allowing you whatever? Briefly looking at their website I got the impression that it was meant for transparency reasons rather than in the spirit of free and open-source.

I didn't assume it must be free of charge. I only mentioned it isn't, to point that this is not a possible reason they chose AGPL.

I did, however, assume the Open Source OSI approved license. How else to define Open Source?

Transparency alone could be achieved with their own Source Available license, so it doesn't seem like a reason for double licensing.

Re: Bitwarden: Free, open-source password manager

#169

FYI - Bitwarden took $100M in VC money last year. At some point, the pressure to aggressively monetize will unfortunately happen. https://techcrunch.com/2022/09/06/open-source-password-manag...

What could a password managing service possibly need this amount of money for - or worse - what could they possibly plan to be doing with it to convince the VC that they will get even more money back from this deal?

They are adding new products like an enterprise Secrets Manager for deployed applications.

Re: Bitwarden: Free, open-source password manager

#170
post #7

I am a happy user and find it very convenient but how safe is it really to have all your jewels centralized in the cloud, including 2FA. It seems such a worthwhile target. On the other hand keeping everything in sync manually seems a hassle and in the end you just encrypt on your machine and the syncing goes through the cloud anyway, so where's the difference? I'd be happy to hear thoughts on this.

You absolutely must be able to create unique and reasonably strong passwords for each of the services you use. This is the absolute most critical first step in account management.

From here, we can have a discussion about broad behavior and individual behavior. We observe that at scale people reuse passwords if they are not using a password manager. End of story. Getting people to use a password manager at scale is the single largest practical improvement in account security for the general population that we have available to us right now. This is even true with the risk of a vault being stolen and unlocked. I've never seen any data that even remotely challenges this point.

Cloud management of passwords is basically non-negotiable for most people. "Oh fuck, my vault was on my computer and I dropped it on the floor and the disk broke" will be a constant occurrence. Getting everybody to properly back up their vaults is not feasible at scale.

You can separately talk about specific people if you want. If you are capable of creating unique and sufficiently strong passwords for all of your accounts, then go ahead and avoid a password manager. This will mitigate a marginal risk for you.

Post reply on HN