Live data from Hacker News

Bitwarden: Free, open-source password manager

bitwarden.com

181–190 of 306 posts

Re: Bitwarden: Free, open-source password manager

#181
Huh, more negative than I expected. For some reason I had Bitwarden as an HN darling in my head. Not sure where I got that from. I pay for premium for $10 a year. Not sure what I actually take advantage of with that honestly but I just really like the product. That said, it's not based on a lot of competition searching. Am I missing out on some big benefits in other managers?

Re: Bitwarden: Free, open-source password manager

#182

I wanted to like Bitwarden, due to its “open source” nature. But 1Password is really miles ahead, and it's a little ironic, as 1Password 8 went through a major refactoring to a Node-enabled UI, which many people disliked, and it's still miles and miles ahead. I tried teaching my father to use Bitwarden for the sole reason that it seemed to be translated into my native tongue. In his use, Bitwarden turned out to be co…

> But 1Password is really miles ahead, and it's a little ironic, as 1Password 8 went through a major refactoring to a Node-enabled UI, which many people disliked, and it's still miles and miles ahead. I use both. It’s far from “miles ahead”

+1

I use BW for my personal use with my SO and 1P at work. I hit some errors in 1P that were crypting, stuff like "Failed to add this record" with no details, no help button, I had to fire up the chrome console for the extension to find out it was a 401 to our 1P portal. Very poor experience, probably related to our SSO setup but still.

Never had any weird issue like this with BW and I love the autofill shortcut and the absence of a popup when I access a password field like 1P.

So yea, YMMV as usual but definitely not miles ahead.

Re: Bitwarden: Free, open-source password manager

#183
post #179

I use and pay for Bitwarden. I want it to succeed, but I still find it weird. 1. Security. Bitwarden's documentation on its security model is quite thin. 1password has a great write-up about how it works in detail: https://1passwordstatic.com/files/security/1password-white-p... . Corresponding doc for Bitwarden is much lighter on detail: https://bitwarden.com/help/bitwarden-security-white-paper/ . The security audits…

Yeah, the extension data loss issue is especially bad, I save often to avoid it (it's also a bit weird to create a profile for a new site instead of saving entered data)

> it's also a bit weird to create a profile for a new site instead of saving entered data

Doesn't always work reliably with Bitwarden ;)

Re: Bitwarden: Free, open-source password manager

#184
post #125

Earlier quoted context omitted.

No company will eever say that thereyare plans for aggresive monetezation. They will always say everything stays the same - open-source mindset etc. Until 2 years later there is a license and pricing change. One that will make it 10 times more expensive - or the free/open-source version will be crippled.

And the UI will suck because they've made it an Electron app so they can have a universal platform...

The clients are fully FOSS, and there is a FOSS server reference application, too. What could go wrong? (Famous last words Inc.)

FWIW: I've been using this application for the past years. I pay 12 USD or so a year, though I self-host. I just pay as a thank you since I still use the FOSS client, and the price is very reasonable.

1Password is hardly even a competitor as it is a completely different price range, and different product. It isn't FOSS at all, there's a vendor lock-in (in contrast to Bitwarden), and it is 3x as expensive at the very least. They're miles apart.

Re: Bitwarden: Free, open-source password manager

#185

I really like Bitwarden, but I found it buggy in terms of user experience, and I'm now considering switching. Some annoying bugs I've experienced: * Desktop app not focusing correctly when opening it * Browser extension asking to save password even if it's already there * Log-In suggestions not showing * Slow and laggy on iOS * Biometrics log-in breaks half of the times I try to use it I like the fact it's open-sourc…

If I create a new login on mobile it never syncs to the vault/desktop correctly. I have so many empty vault items that then sync back to mobile. Nothing seems to fix it.

Re: Bitwarden: Free, open-source password manager

#187

Open source and easy to use https://www.passwordstore.org/

Easy to use...for computer professionals. Try introducing pass to your family, even 1Password is not easy to set up for regular people. We have a long way to go before everyone is using passoword managers. The more realistic alternative is probably passkeys.

Re: Bitwarden: Free, open-source password manager

#188
post #116

Earlier quoted context omitted.

Can you maybe touch a bit on the intended relationship between you and the VC? Are there plans to do aggressive monetization of Bitwarden? As a long time user, I'm a bit concerned as well.

Bitwarden has had VC investors for years, long before the mentioned 2022 funding. I think our track record to date shows how we operate in this relationship. We specifically choose partners that align with our vision, not just anyone that comes off the street wanting to throw money at us (though there are many). Our health as a company afford us this luxury. Bitwarden is and has been monetized since the beginning. Th…

Then why raise an additional $100m?

Re: Bitwarden: Free, open-source password manager

#189
post #157
post #57

The title is misleading. This is not fully "free and open-source". I'm actually puzzled by the licensing structure. Bitwarden server is dual-licensed [1] - part of it is licensed with AGPL (Open Source) - some features are licensed with a source available Bitwarden license Now, even the Open Source core requires you to register if you want to self host. This is to provide you with complementary services like security…

Why does everyone assume that if something is open source it must also be free and licensed under permissive license allowing you whatever? Briefly looking at their website I got the impression that it was meant for transparency reasons rather than in the spirit of free and open-source.

Yesterday I was listening to The Changelog podcast with Steve O'Grady called "Open Source is at a Crossroads". In it he says something along the lines of: We have companies come to us saying they want to release their source under an encumbered license and we tell them that they can definitely do that but they can't call it open source, because open source means something fairly specific to developers. We work with them on getting their specific license terms set up but they come back saying "We really want to call it open source, because developers find open source cool, and we want to attract developers." Developers like it because of what open source means.

https://changelog.com/podcast/558

Re: Bitwarden: Free, open-source password manager

#190

I am a KeepassXC user, yet this sounds interesting. What does Bitwarden offer to make me want to switch?

As a long-time user of KeePassXC, I switched because of the difficulty of syncing databases. Basically, I used the sneakernet and a thumb drive whenever I thought I needed to for five or six devices - it became wearing. At first after the change I kept the critical account - banks, email, and the like - solely on KeePassXC. As I began to trust Bitwarden I began to slowly add those accounts, too.

Also, while I trust Bitwarden sync, I'm not quite as sure of the various apps that implement the KeePassXC on iOS. I'm still not aware that any have been audited, so to my mind Bitwarden is more secure.

Still, the possibility of a change of management philosophy at Bitwarden also wore on me, so not wishing to be solely dependent on an app that I might no longer trust, I continued to maintain my KeePassXC vault, duplicating any new Bitwarden entries. It's a simple way to backup Bitwarden, though a bit time-consuming.

Syncing KeePassXC is simpler now than before I migrated; sneakernet is no longer required, having been replaced by Signal and "Note to Self." It's still not as simple as Bitwarden's sync, so I'll maintain that unless I have a trust reason to change. FWIW

Post reply on HN