Live data from Hacker News

Get your passwords out of Bitwarden while you still can

osnews.com

21–30 of 203 posts

Re: Get your passwords out of Bitwarden while you still can

#22
post #21

Third-party password management as an isolated paid service (i.e. you don't get password management unless you pay specifically for the password management) is just a terribly bad idea all around. Waiting for people to get this.

A bad idea for you. My non-technical family members can barely use 1Password and it is the easiest of the lot. The idea you promote is just not realistic.

Re: Get your passwords out of Bitwarden while you still can

#24

I think this is a little hyperbolic. The product may drop features, increase prices, and squeeze its free tier users. Everything enshittifies. But the idea that password export might disappear or be degraded? Nah. You'll be able to jump ship any time you want.

I don't know why this is framed as "jumping ship" ... of course you can stop using it any time (and use your periodic export to go elsewhere).

The real issue is potential data loss. Remember LastPass? Bought by someone and downhill it went, with multiple security incidents.

Re: Get your passwords out of Bitwarden while you still can

#25
post #6

I think this is a little hyperbolic. The product may drop features, increase prices, and squeeze its free tier users. Everything enshittifies. But the idea that password export might disappear or be degraded? Nah. You'll be able to jump ship any time you want.

>You'll be able to jump ship any time you want. Famous last words...

I mean, LastPass was a train wreck after their breach, but they didn't go as far as trying to stop me from exporting my vault when I switched to BW.

The idea of BW doing a rug pull and suddenly removing the ability to export your vault I think would trigger a class-action lawsuit.

Re: Get your passwords out of Bitwarden while you still can

#26
post #22
post #21

Third-party password management as an isolated paid service (i.e. you don't get password management unless you pay specifically for the password management) is just a terribly bad idea all around. Waiting for people to get this.

A bad idea for you. My non-technical family members can barely use 1Password and it is the easiest of the lot. The idea you promote is just not realistic.

Not really. That something is convenient doesn't mean that it's a good idea. It's always a matter of convenience vs security.

Re: Get your passwords out of Bitwarden while you still can

#28
post #8

Earlier quoted context omitted.

- Authy - Google Authenticator

Not password managers of course, but thanks for reminding me that I should figure out how to ditch Authy. https://github.com/BrenoFariasdaSilva/Authy-iOS-MiTM is going to be my project for the afternoon.

Ente Auth

is a good alter. Works perfect for me.

Re: Get your passwords out of Bitwarden while you still can

#29
post #19

I store my passwords using this: https://www.passwordstore.org/ It's a shell script that stores passwords in a git repository, containing one file per entry. The files are encrypted using a GPG key. Because it's just a git repository, you can synchronise it between devices using whatever infrastructure you want. I use a FOSS client for it on iOS, and there was one for Android before I got an iPhone.

+1 for pass! I use this on my VPS to store secrets. I love that it syncs with GIT. Good stuff

Re: Get your passwords out of Bitwarden while you still can

#30

While I'm not _happy_ about the messaging changes, those alone are not enough to do more than start paying closer attention. I highly, highly doubt that vault export would be the first meaningful feature change, and so I think there will be stronger signals of actual issues before then. As I understand it, so far the only actual change is an announced increase in prices. Obviously, from the consumer perspective, chea…

I hear you, but I feel like it's a better safe than sorry situation. Exporting your passwords takes two seconds. I think you can export to an encrypted file, but I just did a plain-text json file and gpg'd it. Can't hurt to play it safe.
Post reply on HN