I use bitwarden/vaultwarden (self hosted), and didn't even know there was an attachment option, so haven't used it upto now. I did use notes (for storing stuff like ssh/gpg keys), and can confirm that these are exported correctly. Attachments are also not exported in vaultwarden as far as I can see. I'll just stick to stuffing files in notes for now, as I had been doing.
> Attachments are also not exported in vaultwarden as far as I can see. Understandable, since sibling comments are saying export happens on the client side, and Vaultwarden is merely a server-side replacement Although also relevant is the sibling observation that if you're already running Vaultwarden isn't "backup" less "export from some faceless corporation" and more "take a backup of the vaultwanden database"?
Tell HN: Bitwarden does not export attachments in backups
101–110 of 128 posts
Re: Tell HN: Bitwarden does not export attachments in backups
#102Earlier quoted context omitted.
I hope it wasn't really one of your motivations, because Vaultwarden implements the server API. The lack of attachment backup occurs at the Bitwarden client level.
If you Control the server, you can certainly control backups at a root level
Re: Tell HN: Bitwarden does not export attachments in backups
#103Earlier quoted context omitted.
Thank you for saying something about this. I make up answers to "security" questions like: first pet's name? Favorite teacher? and so on but that means that I have to record what the answer is. I've been doing that in the notes section for LastPass. I think that I'm going to have to move to doing it in the Notes app since that works on all my Apple devices. And it looks like I can lock one Note without having to lock…
In case you haven't already seen it, 1P has effectively a "click button, get fake security question answers" and I love it: https://support.1password.com/generate-security-questions/ They use the "battery horse stable" scheme so you don't have to read crazy ascii over the phone to customer support
Re: Tell HN: Bitwarden does not export attachments in backups
#104Earlier quoted context omitted.
If you Control the server, you can certainly control backups at a root level
I really hope not. Why would the server have the keys needed to decrypt the vault?
I actually wanted that functionality for my own installation but it was rejected.
Re: Tell HN: Bitwarden does not export attachments in backups
#105Earlier quoted context omitted.
> The project is open-source, maybe send them a pull request? Just because a project is open-source doesn't mean they'll accept a pull request with your feature request in it.
Indeed. Few things are worse than spending time and effort figuring out a complex repository, making and testing changes to the code and sending in a patch only to get ignored .
Re: Tell HN: Bitwarden does not export attachments in backups
#106Earlier quoted context omitted.
My experience is that 1P has a lot more polish and consideration for the user (err, I mean before the "8" debacle). I cannot recall a single time I have lost an autogenerated password, whereas with BW it happened about 50% of the time. Filling up my vault with hundreds of unnecessary password captures is better than losing a single one, because they don't know how important any one password is in order to gauge how "…
What's the issue with 1Password 8? Upgraded today to get the SSH agent and so far it seems alright.
Re: Tell HN: Bitwarden does not export attachments in backups
#107Earlier quoted context omitted.
Indeed. Few things are worse than spending time and effort figuring out a complex repository, making and testing changes to the code and sending in a patch only to get ignored .
Good to see open source hasn't changed in 20 years. This has been my biggest gripe. You have an idea, you present real world use cases, you submit a patch.. Only to have your idea ridiculed or ignored as you point out. THEN, a few weeks/months/years later, your same patch is accepted by someone else with a twitter blue checkmark to rave reviews.
Re: Tell HN: Bitwarden does not export attachments in backups
#108> A simple solution would be to b64 encode each file and add it into an array! An individual file attachment can be as large as 500 MB[0]. It would make the JSON file too big to use. Still, I do think that Bitwarden should warn users about it when exporting. Just mentioning it in the Help Center doesn't seem so helpful. [0]: https://bitwarden.com/help/attachments/
> An individual file attachment can be as large as 500 MB[0]. It would make the JSON file too big to use. The backup would be too big to use if it included all the data it's a backup of? What?
Re: Tell HN: Bitwarden does not export attachments in backups
#109Earlier quoted context omitted.
In case you haven't already seen it, 1P has effectively a "click button, get fake security question answers" and I love it: https://support.1password.com/generate-security-questions/ They use the "battery horse stable" scheme so you don't have to read crazy ascii over the phone to customer support
Bitwarden has the same. I just generated wobble-swaddling-reflex-repost
I do believe you that it's possible to generate a password using battery-horse-stable but BW places the burden upon the user to create a "security questions" section, fill in the security question prompt, now save the item at this point because fuck the user, and then go to some other section to generate the battery-horse-staple password, copy it to the clipboard, go back into the item, edit it, go back to the section, paste the generated password, and now repeat that for the other 3 fucking required security questions
And people ask me why I pay for 1P ... I'll just link them to this process in the future, because it's a night-and-day difference how much BW hates its users
Re: Tell HN: Bitwarden does not export attachments in backups
#110This is very salient, I just left some feedback related to lack of functionality, in their community forums yesterday. I bought a subscription to use Bitwarden against 1Password, trying to switch from 1P to BW. I dislike 1P's arrogant customer service (Read their community forums for about an hour, and look at many of the responses from staff regarding feature requests) and my attitude towards them really soured when…
Those 3 points are valid but not even the worst bits. It sounds like you are just griping about the switching cost issues, and didn't get much further than initial setup. Once you actually try to use BW in earnest, you'll find it's noticeably worse than 1PW in most ways. The most glaring is that it is meh at detecting login forms and poor at detecting new account signup. These are the 2 primary flows for a pw manager…
100%
My rule-of-thumb is that onboarding has to be *incredibly* easy; it's the front door of an application, the user's first substantial interactions. If it's not easy or streamlined, I start wondering how the rest of the UX is. And in this case, the front door muddied the carpet inside the doors of the software, and I couldn't figure out how to make the process easy for myself, as BW is feature-gapped in many places.
>Once you actually try to use BW in earnest, you'll find it's noticeably worse than 1PW in most ways. The most glaring is that it is meh at detecting login forms and poor at detecting new account signup. These are the 2 primary flows for a pw manager!
Yes, exactly. I'd argue that login form management is the single most important selling point of a password manager. I can roll my eyes, but deal with new account signup forms. But login forms with stellar autofill is what separates the wheat from the chaff, IMO.
>They've had quite long enough time already to do that. How long will you hold out hope?
Competition makes better product for all of us, I don't want to go back to the days of LastPass, So I'll cross my fingers for them, but won't return as a customer after this initial billing cycle.
>Anyway the primary use case I care about is sharing, not self-mgmt.
I'm the inverse; self-management is more important. The only sharing I need is with my partner, which we don't do much of, considering most important shared stuff has accounts for each of us. KeePass is simply for backup purposes, but I haven't decided one way or another where I'll land between them and Vault. I lean towards Vault (Full disclosure: I work for Hashicorp) mostly because I'm more familiar with the APIs than I am with KeePass's plugin/extension frameworks.