Live data from Hacker News

The quiet renovation at Bitwarden

blog.ppb1701.com

121–130 of 333 posts

Re: The quiet renovation at Bitwarden

#121

Earlier quoted context omitted.

Not my project but Vaultwarden is an open source (in Rust) alternative backend for Bitwarden. I believe its been around a while, and is still maintained. https://github.com/dani-garcia/vaultwarden

Question for anyone self-hosting vaultwarden: how reliable is it and how do you harden it? I'm thinking about running it in a container (Podman Quadlet with systemd) behind a VPN, with daily backups with borg. Anything I'm overlooking here?

I’ve used Vaultwarden for at lesst 7 years, I’m sure for longer but I’m not sure how long.

Never had an issue with Vaultwarden itself. Restored from backups several times for a variety of reasons (migrating host, corrupt hard disk, re-installs) and that always worked first try.

In regards to hardering, the wiki has a good guide: https://github.com/dani-garcia/vaultwarden/wiki/Hardening-Gu....

Re: The quiet renovation at Bitwarden

#122
post #40

Earlier quoted context omitted.

I believe they added it back after people noticed, archive.org has versions where its gone

Yeah, to me this isn't about whether or not it's "always free". It's about the rug pull. "They put some of the rug back!" isn't enough to restore goodwill in my case.

What did they pull exactly? Nothing has changed about the product except for a small price increase (but free version is still great)

Re: The quiet renovation at Bitwarden

#123
post #2

what are some bitwarden alternatives?

Proton Pass. Not ideal but actively developing and IMO its UX is way better than what I had with Bitwarden.

Doesn’t it cost much more than BW? I don’t really understand if the main complaint is people worrying about losing the free option (which hasn’t even happened)

Re: The quiet renovation at Bitwarden

#126

Earlier quoted context omitted.

Yes, but vaultwarden isn't something you can casually run by yourself without some careful thinking. You are hosting secrets whose longevity is important, so if deploying yourself, take good care of backups and do regular drills, so you validate that the backups work, that they aren't corrupted and that you keep a copy off-site.

IMO a paper print-out of all passwords and backup codes is the most reliable backup. No bit-rot, no third party, and "degradation" is obvious - fire, flood, etc. Theft is also usually obvious. If self-hosting, keep at a separate location than your hard drives.

[deleted]

Re: The quiet renovation at Bitwarden

#127
post #67

Earlier quoted context omitted.

I'm getting really tired of the enshittification cycle. Learning about android verification and captcha changes recently has been another big frustration point. I moved to android as a more open alternative to apple just a few years ago, and to bitwarden from lastpass around the same time. I would like to just have these infrastructural services work well and quietly without thinking about them for many years. Do I r…

Bitwarden hasn’t “enshittified” anything. It’s all entirely speculative

Does a bear shit in the woods?

Re: The quiet renovation at Bitwarden

#128

It does seem like most password managers have no moat for import/export, so I’m kinda banking on the idea that I can quickly migrate to Proton Pass or vaultwarden if things get ugly. I just don’t want to self-host if I can avoid it. Staying on top of managing the application and the environment is a whole different level of diligence when the thing I’m self hosting is the keys to my life. At a minimum it would have t…

Does Proton Pass use a wireguard tunnel? Or does Bitwarden? TLS should suffice.

Yes, you want to guard the machine that hosts your passwords. You can even physically keep it at home, and only proxy its port 443 wherever you have a presence in the public Internet.

Re: The quiet renovation at Bitwarden

#129

What a shame. I've been a paying Bitwarden customer since 2018. I really don't have time to move off yet, but I'll need to keep an eye out for where to jump. It sucks that this seems to just be the logical conclusion of all great projects.

Literally nothing has been taken away from BW yet, it’s all just speculative for now

We all know where it's going

Re: The quiet renovation at Bitwarden

#130

Earlier quoted context omitted.

Yes, but vaultwarden isn't something you can casually run by yourself without some careful thinking. You are hosting secrets whose longevity is important, so if deploying yourself, take good care of backups and do regular drills, so you validate that the backups work, that they aren't corrupted and that you keep a copy off-site.

Is there anything stopping a commercial Vaultwarden host?

Competing with the authority bitwarden the company has over the bitwarden open source project. That's just the first thing off the top of my head. Very few people go to the competitor offering the exact same thing but with less say on the popular codebase.
Post reply on HN