Live data from Hacker News

Bitwarden: Free, open-source password manager

bitwarden.com

251–260 of 306 posts

Re: Bitwarden: Free, open-source password manager

#251
post #184

Earlier quoted context omitted.

And the UI will suck because they've made it an Electron app so they can have a universal platform...

The clients are fully FOSS, and there is a FOSS server reference application, too. What could go wrong? (Famous last words Inc.) FWIW: I've been using this application for the past years. I pay 12 USD or so a year, though I self-host. I just pay as a thank you since I still use the FOSS client, and the price is very reasonable. 1Password is hardly even a competitor as it is a completely different price range, and dif…

And 1Password does not propose self-hosting anymore, which is why I am stuck to version 7 for my personal vault. At work, we use Bitwarden self-hosted solution. I could even use an encrypted text file to store my passwords if there were no self-hosting solution anywhere. It gives you an idea at how much I do not want my infos to be on the Internet somewhere.

Re: Bitwarden: Free, open-source password manager

#252
This is incredibly superficial, but I wish Bitwarden used the system font stack for its apps instead of forcing Open Sans on everyone. I found that it helped make Bitwarden slightly nicer to use for me and some others I provided a one-time fork of the Mac app to try.

If I could figure out how to sign and ship Mac and iOS apps, I'd ship a fork that continually pulled from upstream, with just the two `variables.scss` files patched.

Re: Bitwarden: Free, open-source password manager

#253
post #231

Earlier quoted context omitted.

1Password’s additional secret password to log in is an absolute non-starter for our corporation. I could barely understand it myself let alone explain it to our lowest understanding employees.

What are you using then? Because Bitwarden also requires an additional secret.

Not sure what you are using because my bitwarden does not have a secondary key.

Re: Bitwarden: Free, open-source password manager

#254

Earlier quoted context omitted.

Oh sure yes they are indeed here.

Fairly sure that was meant tongue in cheek, as HN is literally run by a VC firm for all intents and purposes. Moderators seems to do a pretty well done making it impartial, but worth keeping in mind that Y Combinator ultimately run this website.

Who should keep that in mind?

Re: Bitwarden: Free, open-source password manager

#255
post #229

I'm still looking for a product that offers a completely passwordless SSO and has a good and simple UI (keeweb, anyone?) Unfortunately, Bitwarden fails at both.

You can try https://www.heylogin.com if you are looking for a new approach without a Master Password. I am one of the founders.

Re: Bitwarden: Free, open-source password manager

#256
post #250

Earlier quoted context omitted.

Why would a password manager need $1B? Cloud password manager functionality can be accomplished in 6U of server space. Vault files are measured in kilobytes or megabytes, millions of customers could be handled by a single SSD RAID and a fast Xeon. Infrastructure and software to make it secure, reliable, and user friendly, add expense but not 9 digits of it.

I would be more interested in knowing why would a password manager _get_ $1B.

My mental model of that situ is "money chasing eyeballs" since having a curated list of folks to market to is the value - it's all about the user list

Re: Bitwarden: Free, open-source password manager

#258
post #38
post #5

Here, I also want to mention vaultwarden which is an open-source Rust implementation of the server: https://github.com/dani-garcia/vaultwarden

Only thing missing from Vaultwarden is SSO/Oauth. There’s a PR for it that’s been open for years. I’ve lost hope that it’ll ever land.

Have you considered just merging it into your own fork? I guess it depends on what their specific concerns are, but if it's political and not technical, I'd for sure just keep rebasing that change on top of releases and let them do as they see fit

Re: Bitwarden: Free, open-source password manager

#259

I use and pay for Bitwarden. I want it to succeed, but I still find it weird. 1. Security. Bitwarden's documentation on its security model is quite thin. 1password has a great write-up about how it works in detail: https://1passwordstatic.com/files/security/1password-white-p... . Corresponding doc for Bitwarden is much lighter on detail: https://bitwarden.com/help/bitwarden-security-white-paper/ . The security audits…

The fact that you can't access your passwords when offline really blew my mind.

Also that one time when they randomly blocked my IP and wont do anything about it, wtf?! From then on I've started occasionally exporting the JSON file and keeping it somewhere safe, just in case. Like... I'm the person behind this account, I own the email.. I don't even ask you for a password or whatever! I'm asking you to unblock my IP. This shouldn't take more than 5 minutes!

I also want BitWarden to succeed, but does it want itself to succeed?

Re: Bitwarden: Free, open-source password manager

#260
post #231

Earlier quoted context omitted.

What are you using then? Because Bitwarden also requires an additional secret.

Not sure what you are using because my bitwarden does not have a secondary key.

What is the primary login method? Because I'm using SSO, and it still requires a master password.
Post reply on HN