Live data from Hacker News

Bitwarden: Free, open-source password manager

bitwarden.com

171–180 of 306 posts

Re: Bitwarden: Free, open-source password manager

#171
post #54

Earlier quoted context omitted.

The new CEO concerns me. I didn't know who the founder was but I always had the impression it was a lone hacker. They passed the baton. Now it's some old Web 1.0 guy who was the CEO of eFax in the 90's. That's not the type of service I thought I was using. I looked up their headquarters in Santa Barbara and it's a co-working space. That doesn't sound very secure. Though that could be their corp address and they're hi…

The "new" CEO has been at the helm since 2019. Long before the mentioned funding in 2022. We don't really have a HQ since we are a 100% remote company. Source: I am the Bitwarden founder.

Just want to echo other comments, thanks so much for bitwarden I've been using it for years and it has changed my family's life. Even managed to get my aging parents to use it instead of their paper notebook

Re: Bitwarden: Free, open-source password manager

#172

FYI - Bitwarden took $100M in VC money last year. At some point, the pressure to aggressively monetize will unfortunately happen. https://techcrunch.com/2022/09/06/open-source-password-manag...

My take in life: whenever VC or PE investors take over, start moving away from that product and pronto .

I used to think this kind of talk was bullshit grandpa paranoia. Sadly, I now agree with it 100%.

Re: Bitwarden: Free, open-source password manager

#173
post #125
post #116

Earlier quoted context omitted.

Can you maybe touch a bit on the intended relationship between you and the VC? Are there plans to do aggressive monetization of Bitwarden? As a long time user, I'm a bit concerned as well.

No company will eever say that thereyare plans for aggresive monetezation. They will always say everything stays the same - open-source mindset etc. Until 2 years later there is a license and pricing change. One that will make it 10 times more expensive - or the free/open-source version will be crippled.

And the UI will suck because they've made it an Electron app so they can have a universal platform...

Re: Bitwarden: Free, open-source password manager

#174
post #7

I am a happy user and find it very convenient but how safe is it really to have all your jewels centralized in the cloud, including 2FA. It seems such a worthwhile target. On the other hand keeping everything in sync manually seems a hassle and in the end you just encrypt on your machine and the syncing goes through the cloud anyway, so where's the difference? I'd be happy to hear thoughts on this.

Storing OTPs in your password manager is like 1.5FA. It still provides protection against phishing, brute-forcing, socially engineered password resets, so it isn’t totally useless. But it doesn’t protect against your vault getting compromised. I keep super important 2FA codes (email, github etc) elsewhere, and for less important services, I store the OTP in my password manager.

OTPs don't protect against phishing. You still type the TOTP in a browser window that sends it off to the attacker. Phishing SDKs automatically handle proxying the password over and then proxying the TOTP over.

Re: Bitwarden: Free, open-source password manager

#175

FYI - Bitwarden took $100M in VC money last year. At some point, the pressure to aggressively monetize will unfortunately happen. https://techcrunch.com/2022/09/06/open-source-password-manag...

They have been monetized for awhile now while their open source offering has been supported.

Re: Bitwarden: Free, open-source password manager

#176

Earlier quoted context omitted.

No. The user experience of 1Password is just frustrating. I use it daily for work and don’t like it. I’ve used it longer than I’ve used bitwarden.

I started with keepass, and switched to Bitwarden for personal use, and LastPass for work (before LastPass imploded). I now use 1password everywhere. I've got complaints, sure, but Bitwarden regularly fails at input field detection on mobile and web, regularly fails at login (particularly with biometric). If a tool can't reliably do it's core functionality, it's not fit for purpose.

Unsure what it’s like on android but it never fails on iOS. I think both 1Password and bitwarden are great on iOS. My issue is with the chrome and Firefox plugins for 1Password. I never have issues with bitwarden but 1Password I often need to refresh after logging in.

Re: Bitwarden: Free, open-source password manager

#177
post #164

Earlier quoted context omitted.

With a password manager, you only need to know 1 password to "deduce" all the others. So wouldn't a 3-password system be better anyway?

The difference is that the one password for the manager is kept in a location very difficult to attack, whereas various services are inevitably prone to be pwned.

Theoretically anyway. See LastPass.

Still, the algorithm method requires 3 services to be breached. Those services must be storing the passwords in plaintext or an otherwise retrievable method. The bad actor must put together the fact that your account is the same across all 3 services. Then they must analyze your password and reverse engineer your algorithm.

That seems a lot less likely than your master password getting nabbed.

The attack vector for a PW manager is a lot easier. They're obvious targets for both breaches and social hacks. One person looking over your shoulder at the coffee shop is as or more likely than anything else. They can even swipe your phone in that scenario to beat MFA.

I'm not advocating an algorithmic approach. The average person isn't going to understand this (heck, they don't understand PW managers either). And if they did, most algos would be something like ServiceName! anyway.

On the whole a password manager is a better solution, but it's not without its own trade offs, which don't get nearly enough discussion.

Re: Bitwarden: Free, open-source password manager

#178

Bitwarden is great. I use it everywhere and it manages passwords well. The key feature for me is the ease of use of "organizations", which allows me to share passwords with my wife easily. A lot of accounts regarding our financials or children are shared, so we both need the password. Bitwarden makes this trivial.

I also use the sharing feature (aka organizations) and maybe I am too dumb but it seems that you can't see or copy the password anymore once you have shared it (even the one you yourself shared with somebody else). Which is fine for when you can use the auto-fill but that just doesn't always work or isn't always feasible.

Re: Bitwarden: Free, open-source password manager

#179

I use and pay for Bitwarden. I want it to succeed, but I still find it weird. 1. Security. Bitwarden's documentation on its security model is quite thin. 1password has a great write-up about how it works in detail: https://1passwordstatic.com/files/security/1password-white-p... . Corresponding doc for Bitwarden is much lighter on detail: https://bitwarden.com/help/bitwarden-security-white-paper/ . The security audits…

Yeah, the extension data loss issue is especially bad, I save often to avoid it (it's also a bit weird to create a profile for a new site instead of saving entered data)

Re: Bitwarden: Free, open-source password manager

#180

Is there a desktop client for Bitwarden that isn't Electron-based yet? I tried this years ago and didn't like it. Not only because Electron, but I thought it was missing a lot of basic features (folders/organizing passwords was sorely lacking). I'm not looking to try it again, to be clear, just curious. KeepassXC won my heart.

Depends on if you count a command line tool as a desktop client or not [0]. I personally just use the browser extension instead of the desktop client (the GUI one) since it was a bit slow and the extension is fine.

[0] https://bitwarden.com/help/cli/

Post reply on HN