Live data from Hacker News

Get your passwords out of Bitwarden while you still can

osnews.com

181–190 of 203 posts

Re: Get your passwords out of Bitwarden while you still can

#181
post #178

Earlier quoted context omitted.

> What's the security risk? If anything, it's SaaS password managers that seem to semi-regularly get hit with breaches (well, mostly LastPass). Talk to your local security engineer :) On a venting note, this mentality is a frustration I have with SV, because I see it a lot. They don’t know what they don’t know, and think they can just stand up businesses without understanding the domain.

> Talk to your local security engineer :) You made the claim - I'm interested to hear why you believe it, because I suspect it's based on a misunderstanding of how KeePass works. > and think they can just stand up businesses without understanding the domain Using KeePass is not analogous to standing up a business.

Ok - I made the assumption that your (s)FTP was publicly available over the internet. (It’s safer if not, but then you don’t get the benefits of syncing from anywhere that I get.)

If your FTP is open to the internet, you are now responsible for alerting / monitoring, IPS/IDS, proper config management, routine automated patching, IP allow/blocklisting… all of these things require regular maintenance. Even if you stick it behind a VPN, you will need to patch, alert on, and configure the VPN and everything behind it as well, as VPNs can be compromised.

That’s why, unless I really wanted to spend time hardening the spit out of it, there’s no way I’m self hosting my passwords. I’m happy to just pay a password manager to handle all of that.

Re: Get your passwords out of Bitwarden while you still can

#182
post #22
post #21

Third-party password management as an isolated paid service (i.e. you don't get password management unless you pay specifically for the password management) is just a terribly bad idea all around. Waiting for people to get this.

A bad idea for you. My non-technical family members can barely use 1Password and it is the easiest of the lot. The idea you promote is just not realistic.

Losing control and ownership of technology isn’t a prerequisite for ease of use. That’s just the narrative big tech has been selling for 20 years.

Re: Get your passwords out of Bitwarden while you still can

#183

Earlier quoted context omitted.

You can get rid of the element of hope by using KeepassXC and syncthing. Bonus is you can use this FOSS stack completely offline.

And not be able to use it on your phone or share it with people you work with. Vaultwarden is the way. Easy to host docker. Solid. And if bitwarden blocks the clients there will be a fork. It's leading to it anyway.

KeepassDX works great on my phone. I use LocalSend to move around keyfiles fully offline as well.

Re: Get your passwords out of Bitwarden while you still can

#184
post #95
post #77

Serious question - how come free is a requirement for a password manager? Everyone's gotta eat, including the maintainers of password managers. Tech has generous TC, lots of high-end laptops and phones worth thousands, AI & cloud spend, and yet the only acceptable price for secrets management is $0 it seems at times.

Passwords are critical, losing them because you forget to pay or run out of money would be a disaster. I suspect they would still provide access in read only mode to non-paying users so it wouldn’t be a disaster if they didn’t offer a free version but I think it’s pretty easy to see why someone thinks it should always have a free offering.

That's what the backups are for, and also local password copies remain even without internet/subscription?

Re: Get your passwords out of Bitwarden while you still can

#185
post #41

So I have an admission here: I keep seeing HN stuff about these networked password managers and I don't quite understand the appeal. Is it because everybody else is swapping between several different computers, and you need the synchronization? I just have everything in KeepassXC, and the ciphertext is subject to the same kind of backup regime I use for other files, [edit: and also additionally] a copy kept on a USB…

> everybody else is swapping between several different computers, and you need the synchronization?

So you do understand it!

Re: Get your passwords out of Bitwarden while you still can

#186

Earlier quoted context omitted.

And not be able to use it on your phone or share it with people you work with. Vaultwarden is the way. Easy to host docker. Solid. And if bitwarden blocks the clients there will be a fork. It's leading to it anyway.

You can use it on your phone what are you talking about?

That's what I'm saying, a lot of people are coping with a product they admit will need a fork.

Not only is it incurring the cost of project fragmentation, but also incurring an always online cost with overly-complicated docker solutions, when a fully offline and airgapped solution already exists.

Furthermore, staying with the same ecosystem invokes the sunken cost fallacy. But the migration from Bitwarden couldn't be simpler (just export Bitwarden json file). It's almost a form of battered woman syndrome people are inflicting on themselves when quite simply they can hop onto an already proven ecosystem that doesn't bait and switch.

Re: Get your passwords out of Bitwarden while you still can

#187

Earlier quoted context omitted.

The Apple Passwords app does all this just fine. The only thing it's missing is secure notes to store my 2FA recovery codes in.

That works if all your devices are Apple devices.

Yes

Re: Get your passwords out of Bitwarden while you still can

#189

Sometimes I think when a startup announces that they are being acquired their competitors have a meeting that morning and announce that they're going to start dialing for dollars. Since acquisitions almost always hurt customers I wonder if we can start creating "poison pills" that deter them.

A successful sequel or reboot is its own poison pill

https://automaton-media.com/en/news/kadokawa-reports-sharp-d...

Re: Get your passwords out of Bitwarden while you still can

#190
post #178

Earlier quoted context omitted.

> Talk to your local security engineer :) You made the claim - I'm interested to hear why you believe it, because I suspect it's based on a misunderstanding of how KeePass works. > and think they can just stand up businesses without understanding the domain Using KeePass is not analogous to standing up a business.

Ok - I made the assumption that your (s)FTP was publicly available over the internet. (It’s safer if not, but then you don’t get the benefits of syncing from anywhere that I get.) If your FTP is open to the internet, you are now responsible for alerting / monitoring, IPS/IDS, proper config management, routine automated patching, IP allow/blocklisting… all of these things require regular maintenance. Even if you stick…

> you are now responsible for [...] there’s no way I’m self hosting my passwords

You don't need to host anything new or take on any patching responsibilities for anything you weren't before. I already had an FTP server, so put it on there. Wherever you already access arbitrary files across devices (you didn't answer what you do for files outside of your filetype-specific subscriptions, but I'd assume you just have iCloud or something) should work fine.

Not that there are zero reasons to use a SaaS password manager, just that I disagree Keepass is somehow insecure or prohibitively technical for regular users. The solution a lot of people already seem to gravitate towards (if not just password reuse) is "passwords.txt on Google Drive".

Post reply on HN