Live data from Hacker News

The quiet renovation at Bitwarden

blog.ppb1701.com

231–240 of 333 posts

Re: The quiet renovation at Bitwarden

#232
post #146

Earlier quoted context omitted.

Me and some friends have each been hosting vaultwarden casually for years now. What problem do you see? I mean if the Server goes down and gets completely corrupted, worst case, all my devices still have the version of the vault they recently used. Technically every device has it's own backup of the vault.

If I stay offline for more than 30 days, can I still access my local passwords? Honest question, because if that's the case it's nice, but I think you'd need to somehow authenticate before accessing your local vault.

If you’re self-hosting,

and not using their official clients,

your database stays functional in perpetuity.

Re: The quiet renovation at Bitwarden

#233
post #146

Earlier quoted context omitted.

Me and some friends have each been hosting vaultwarden casually for years now. What problem do you see? I mean if the Server goes down and gets completely corrupted, worst case, all my devices still have the version of the vault they recently used. Technically every device has it's own backup of the vault.

You need a VPS, correct? Are there any concerns about hardening your VPS from attackers? I worry about my ability to harden a public - facing service that is handling something so critical for myself.

Use a host that takes care of this for you.

My host has prebuilds for Vaultwarden.

Re: The quiet renovation at Bitwarden

#234
If the price ever became unresaonable i'd host my own VaultWarden instance.

I'm sure if BitWarden ever went closed source, it would be forked and maintained by the community and that most would migrate to the open source solution.

BitWarden being open source and auditable is one of the main reasons I use it, no hidden backdoors from them or three letter government agencies.

Re: The quiet renovation at Bitwarden

#235
post #67

Earlier quoted context omitted.

I'm getting really tired of the enshittification cycle. Learning about android verification and captcha changes recently has been another big frustration point. I moved to android as a more open alternative to apple just a few years ago, and to bitwarden from lastpass around the same time. I would like to just have these infrastructural services work well and quietly without thinking about them for many years. Do I r…

Bitwarden hasn’t “enshittified” anything. It’s all entirely speculative

[deleted]

Re: The quiet renovation at Bitwarden

#236
post #222

Earlier quoted context omitted.

Ehh.. much as I love syncthing, I wouldn't recommend it to nontechnical people. I mean, here the dad has android the mom iphone amd they want to sync a keepass file? Maybe with a browser addon on a desktop as well? And the most popular third party android app is discontinued (I use the nerdily named syncthing-fork) and the ios apps i never managed to get to work for my family (maybe sushitrain works now?). But if you…

I use keepass and have for years and I wanted to switch from using google drive to something more self hosted so I tried sync-thing. I have been a C and C++ developer for over 40 years and I found it one of the most obtuse things I have ever tried. I'll have to get back to it. :) It's still running but somehow never syncs a single file between the desktop and the linux server. I don't think the android client can run…

Syncthing-fork is running perfectly fine on my Pixel 9. The web interface is definitely better than the default app interface, it's a shame they even bothered with that app interface.

All you have to do is exchange "keys" with the two machines you want to sync and then it's mostly set and forget

Re: The quiet renovation at Bitwarden

#237

Say what you will, but the Apple ecosystem's Passwords app and integration works great. It locks me into their services (iCloud), but I don't see them ever charging for it or sunsetting it. (watch me eat my words in the near future)

One day they could decide to suddenly block your account for no reason they would like to communicate to you or just you lose your password.

And then you will be screwed very hard with not recourse...

Re: The quiet renovation at Bitwarden

#238
Tried everything and love 1pass. Dont want to have to think about it too much.

I think this is tentatively good for bitwarden - making money means you can more easily invest in the team and product. Counter to the prevailing notion in comments here, I much prefer a vc/paid product for security-critical tools.

Hope they didn't wait too long before deciding to kill the free tier.

Re: The quiet renovation at Bitwarden

#240
post #27

I don't care about raising prices, I'm worried about the new CEO having a PE mindset. That means Bitwarden will now focus on extracting value while the product stagnates and degrades in quality. Time to jump ship before their security and quality goes down the drain.

I jumped to Bitwarden because of 1P's new pricing doing exactly that. Circle of live, I guess.

Me too precisely. But after getting acclimated to a self hosted vaultwarden for the backend and beginning to explore some of the 3rd party Bitwarden frontends that implement its API, I’d recommend hanging in there a bit longer. I think there may be a moat around BW already for self-hosting.

What’s next in the circle is keepass I guess? And it’s just not friendly/robust enough yet for me to switch to it with my family who will probably just go back to using the same passwords on multiple sites if they hit resistance in ease of use.

Post reply on HN