Earlier quoted context omitted.
The new CEO concerns me. I didn't know who the founder was but I always had the impression it was a lone hacker. They passed the baton. Now it's some old Web 1.0 guy who was the CEO of eFax in the 90's. That's not the type of service I thought I was using. I looked up their headquarters in Santa Barbara and it's a co-working space. That doesn't sound very secure. Though that could be their corp address and they're hi…
The "new" CEO has been at the helm since 2019. Long before the mentioned funding in 2022. We don't really have a HQ since we are a 100% remote company. Source: I am the Bitwarden founder.
Bitwarden: Free, open-source password manager
171–180 of 306 posts
Re: Bitwarden: Free, open-source password manager
#172FYI - Bitwarden took $100M in VC money last year. At some point, the pressure to aggressively monetize will unfortunately happen. https://techcrunch.com/2022/09/06/open-source-password-manag...
My take in life: whenever VC or PE investors take over, start moving away from that product and pronto .
Re: Bitwarden: Free, open-source password manager
#173Earlier quoted context omitted.
Can you maybe touch a bit on the intended relationship between you and the VC? Are there plans to do aggressive monetization of Bitwarden? As a long time user, I'm a bit concerned as well.
No company will eever say that thereyare plans for aggresive monetezation. They will always say everything stays the same - open-source mindset etc. Until 2 years later there is a license and pricing change. One that will make it 10 times more expensive - or the free/open-source version will be crippled.
Re: Bitwarden: Free, open-source password manager
#174I am a happy user and find it very convenient but how safe is it really to have all your jewels centralized in the cloud, including 2FA. It seems such a worthwhile target. On the other hand keeping everything in sync manually seems a hassle and in the end you just encrypt on your machine and the syncing goes through the cloud anyway, so where's the difference? I'd be happy to hear thoughts on this.
Storing OTPs in your password manager is like 1.5FA. It still provides protection against phishing, brute-forcing, socially engineered password resets, so it isn’t totally useless. But it doesn’t protect against your vault getting compromised. I keep super important 2FA codes (email, github etc) elsewhere, and for less important services, I store the OTP in my password manager.
Re: Bitwarden: Free, open-source password manager
#175FYI - Bitwarden took $100M in VC money last year. At some point, the pressure to aggressively monetize will unfortunately happen. https://techcrunch.com/2022/09/06/open-source-password-manag...
Re: Bitwarden: Free, open-source password manager
#176Earlier quoted context omitted.
No. The user experience of 1Password is just frustrating. I use it daily for work and don’t like it. I’ve used it longer than I’ve used bitwarden.
I started with keepass, and switched to Bitwarden for personal use, and LastPass for work (before LastPass imploded). I now use 1password everywhere. I've got complaints, sure, but Bitwarden regularly fails at input field detection on mobile and web, regularly fails at login (particularly with biometric). If a tool can't reliably do it's core functionality, it's not fit for purpose.
Re: Bitwarden: Free, open-source password manager
#177Earlier quoted context omitted.
With a password manager, you only need to know 1 password to "deduce" all the others. So wouldn't a 3-password system be better anyway?
The difference is that the one password for the manager is kept in a location very difficult to attack, whereas various services are inevitably prone to be pwned.
Still, the algorithm method requires 3 services to be breached. Those services must be storing the passwords in plaintext or an otherwise retrievable method. The bad actor must put together the fact that your account is the same across all 3 services. Then they must analyze your password and reverse engineer your algorithm.
That seems a lot less likely than your master password getting nabbed.
The attack vector for a PW manager is a lot easier. They're obvious targets for both breaches and social hacks. One person looking over your shoulder at the coffee shop is as or more likely than anything else. They can even swipe your phone in that scenario to beat MFA.
I'm not advocating an algorithmic approach. The average person isn't going to understand this (heck, they don't understand PW managers either). And if they did, most algos would be something like ServiceName! anyway.
On the whole a password manager is a better solution, but it's not without its own trade offs, which don't get nearly enough discussion.
Re: Bitwarden: Free, open-source password manager
#178Bitwarden is great. I use it everywhere and it manages passwords well. The key feature for me is the ease of use of "organizations", which allows me to share passwords with my wife easily. A lot of accounts regarding our financials or children are shared, so we both need the password. Bitwarden makes this trivial.
Re: Bitwarden: Free, open-source password manager
#179I use and pay for Bitwarden. I want it to succeed, but I still find it weird. 1. Security. Bitwarden's documentation on its security model is quite thin. 1password has a great write-up about how it works in detail: https://1passwordstatic.com/files/security/1password-white-p... . Corresponding doc for Bitwarden is much lighter on detail: https://bitwarden.com/help/bitwarden-security-white-paper/ . The security audits…
Re: Bitwarden: Free, open-source password manager
#180Is there a desktop client for Bitwarden that isn't Electron-based yet? I tried this years ago and didn't like it. Not only because Electron, but I thought it was missing a lot of basic features (folders/organizing passwords was sorely lacking). I'm not looking to try it again, to be clear, just curious. KeepassXC won my heart.