Live data from Hacker News

The quiet renovation at Bitwarden

blog.ppb1701.com

221–230 of 333 posts

Re: The quiet renovation at Bitwarden

#221

Earlier quoted context omitted.

Proton Pass. Not ideal but actively developing and IMO its UX is way better than what I had with Bitwarden.

Doesn’t it cost much more than BW? I don’t really understand if the main complaint is people worrying about losing the free option (which hasn’t even happened)

Not sure it makes sense on its own at $5 a month (currently discounted so $3), but as part of the Proton Ultimate package which gives you mail, VPN etc in addition it's not bad in my view. YMMV.

Worked well for me, I use it for non-critical web accounts and such. KeePass for the few core accounts etc.

Re: The quiet renovation at Bitwarden

#222
post #112

Earlier quoted context omitted.

KeepassXC is much better than older keepass clients. Syncthing runs quietly in the background. It's really not much harder to use that other password managers once you set it up

Ehh.. much as I love syncthing, I wouldn't recommend it to nontechnical people. I mean, here the dad has android the mom iphone amd they want to sync a keepass file? Maybe with a browser addon on a desktop as well? And the most popular third party android app is discontinued (I use the nerdily named syncthing-fork) and the ios apps i never managed to get to work for my family (maybe sushitrain works now?). But if you…

I use keepass and have for years and I wanted to switch from using google drive to something more self hosted so I tried sync-thing. I have been a C and C++ developer for over 40 years and I found it one of the most obtuse things I have ever tried. I'll have to get back to it. :) It's still running but somehow never syncs a single file between the desktop and the linux server. I don't think the android client can run on a modern pixel phone anyway anymore due to security constraints.

Re: The quiet renovation at Bitwarden

#223
post #32

After the LastPass fiasco I switched to selfhosting a password manager (bw). Rapidly starting to think even a vibecoded solution may be a better plan relying on commercial options. High risk of don’t roll your own crypto mistakes but realistically that’s not the threat model here anymore for the random individual. It’s online breaches or perhaps a wrench attack not highly skilled crypto adversary. Plus there are prob…

Vibecoding a password manager might be the worst idea ever. You'd be better off with an encrypted Excel sheet. But otherwise, 1Password is great imo and there are other free open source password managers.

>Vibecoding a password manager might be the worst idea ever.

I mean I'm just spitballing here, but not convinced this is true.

From a formal security theory perspective certainly, but practically...nobody with half an ounce of skill is going to spend their time breaking one individual's custom solution that almost certainly just contains their hn password. That's if you can even get to it - selfhosted password managers are usually on LAN/behind vpn.

Risk profile wise the thing could be a god damn plain text .txt on a LAN network drive and still outperform a Lastpass.com that by definition has a giant hack-me sign on it's back.

The crypto part barely moves the needles here

Re: The quiet renovation at Bitwarden

#224
post #146

Earlier quoted context omitted.

Me and some friends have each been hosting vaultwarden casually for years now. What problem do you see? I mean if the Server goes down and gets completely corrupted, worst case, all my devices still have the version of the vault they recently used. Technically every device has it's own backup of the vault.

You need a VPS, correct? Are there any concerns about hardening your VPS from attackers? I worry about my ability to harden a public - facing service that is handling something so critical for myself.

Don't make it public facing! Put it behind a VPN!!

Re: The quiet renovation at Bitwarden

#225

Earlier quoted context omitted.

> Anything I'm overlooking here? Not technical, but the person behind that project now works for Bitwarden so there's some risk of a rugpull. Of course it's OSS but you'll need to trust a fork or maintain it yourself if said rugpull happens.

The maintainer has said that they've been given permission to maintain it in their free time. All it takes is a bad quarter and the CEO decides they don't want to be supporting a competitor and that goes away. It's possible that a community continuation could happen but I wouldn't rely on something so uncertain for something as important as credentials.

It’s a bad strategy. I am capable so I host an instance of vaultwarden for myself and spouse (only available via our vpn)

But when friends and family ask for my recommendation I send them to Bitwarden and they pay for the service.

If it wasn’t for vaultwarden and the clients being open source I would not be using it nor recommending it.

I’d probably still be using keepass with manual sync and when friends and family ask for suggestions I’d probably shrug and say I don’t trust any of them.

Re: The quiet renovation at Bitwarden

#226
post #174

Earlier quoted context omitted.

It's very simple, just don't make it accessible outside your home network. Clients sync when the server is accessible and use last synced data otherwise.

The effort required to set this up far outweighs the price to pay someone to do it for me. I pay a cleaner, I have a dishwasher, I pay someone to do my taxes, I pay for companies to host software. Then again, I never order food and almost never get takeaway, as cooking is nice and I value my food enough to care what goes in it. Cheaper too, easily offsetting what I pay for my password manager.

I mean does it? I have set it up before but I just set it up for my new small office team. I already had an internal server and WireGuard vpn in our office and it took 2 minutes to create a quadlet to run vaultwarden and a few more to configure it. The “hardest” part was training the team on how to use collections.

Re: The quiet renovation at Bitwarden

#227
Wild to me that Bitwarden raised > $100m from VC. Seems like the kind of thing that would make a nice lifestyle business.

The enterprise version never went beyond password management so I'm not sure how this could have generated a viable ROI.

Re: The quiet renovation at Bitwarden

#228
post #205

At this point it is too high of a risk to store my password elsewhere. I've been screwed over by dashlane, lastpass, potentially bitwarden now, I am with 1password now, but I've had my passwords in all these places, and I've had to change them each time, probably missing a few. I like 1password, it is by far the highest quality product I've used in this category. I moved from BitWarden back then because their browser…

Keepass has been my go to since forever, highly recommend. I never jumped on the SaaS password manager train when they started coming out, always just kept it local. There were times I thought I was missing out on some convenience but I'm glad I never moved. Depending on your threat model, you can even just keep the .kdbx in cloud storage somewhere and point your keepass client to that. I'd recommend using a keyfile…

I’ve found being able to share passwords with my spouse very valuable which we couldn’t easily do with keepass. Also the syncing strategy on iOS is a disaster and corrupted my wife’s keepass db causing her to lose everything.

Re: The quiet renovation at Bitwarden

#230
This will probably finally push me to migrate away from Bitwarden. Somehow over the years the UI was getting worse and worse too. It's more steps to add custom hidden fields than it used to, etc.
Post reply on HN