Live data from Hacker News

Bitwarden SDK relicensed from proprietary to GPLv3

github.com

101–110 of 381 posts

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#101
post #70

Earlier quoted context omitted.

It's not end-to-end encrypted (if you enable account sync), so Microsoft can technically see your passwords. Feel free to switch or not switch based on that information.

Firefox isn't end-to-end encrypted either anymore, IIRC.

It still is, as is all Firefox Account data

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#102
post #43

Earlier quoted context omitted.

Doesen't having the seeds available on all of the devices make it not 2FA? You now need only one device to login at any given time.

The second factor isn’t a second device, it’s the TOTP code.

No, factors are supposed to have different qualities, such as:

"Something you know"; "something you have"; "something you do"; "something you are [biometrics]"; "somewhere you are [geolocation]".

Passwords are in your head - "something you know".

TOTP codes are generated by a hardware token - "something you have".

If the TOTP codes are crammed into your password manager, then the factors are no longer distinguished by these qualities, but they're now the same factor, and it's not true MFA anymore, whether or not they're split up across devices, or apps.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#103
post #34

Earlier quoted context omitted.

Keepass file on Google drive is kind of trivial though.

Never store anything remotely important on a Google service.

I know we are kidding but damn the news Google Drive is being sunsetted by December would ruin a lot of people's days

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#104
post #96

Thank you to Bitwarden for relicensing a thing to Free/Open License! Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good. But for anyone with more advance needs (or who doesn't trust a password manager built into a web browser, I always recommend Bitwarden because KeepassXC + syncing is way too difficult for normal people.

What finally brought me to using BW was that I simultaneously needed to backup/sync my TOTPs across mobile/desktop devices, and came to have the need for sharing an increasing number of passwords with my SO. It delivered beautifully on all of that.

This isn't an area I know much about, but wouldn't there be a security risk involved with storing the TOTP seeds alongside the passwords? Or is that not a real concern?

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#105
post #51

Earlier quoted context omitted.

> because KeepassXC + syncing is way too difficult for normal people I've been debating for ages if this is a hurdle that can be overcome by packaging or even hand-holding support. When I show "normal people" my pass+sync setup they beg me to implement it for them. Once it's running it's near-zero maintenance.

Password management is like exercise. Even when people say they understand the value and want to do it, they don't. Even if you implement it for them, if it's not something that slots perfectly into their existing routine, they're not going to do it. Thankfully passkeys are here.

It's fine, even bad password management is better than passkeys.

Thankfully the incredible hype for passkeys has been dead for years now and people are starting to question it.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#106

Earlier quoted context omitted.

can you share how do you set this up?

I store the password vault in dropbox. Done.

> store the password vault in dropbox

No local backup? Do you rely on the network working all the time?

I do something similar on the mobile phone (the reasining is, if there's no network, there's nothing I need to login to) but I also keep a local copy on my laptop (that I sometimes operate with limited connectivity). Without any automatic syncing, one of the two copies will be stale.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#107

Thank you to Bitwarden for relicensing a thing to Free/Open License! Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good. But for anyone with more advance needs (or who doesn't trust a password manager built into a web browser, I always recommend Bitwarden because KeepassXC + syncing is way too difficult for normal people.

> Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good Interesting, I've always felt that browser-based password managers provided remarkably little value for most people. Using them on mobile is tricky and platform dependent, it's easy to have local-only, non-synced data and then lose it, and being multi-device is trickier, especially in a work…

> Interesting, I've always felt that browser-based password managers provided remarkably little value for most people.

They provide the value of "you should, by design, have no idea what most of your passwords are; if you know any significant number of your passwords you probably have bad passwords".

And both Firefox and Chrome sync passwords between devices.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#108

Earlier quoted context omitted.

Does it require a Firefox account? Does it only store them locally if you haven't signed in to Firefox? This is the sort of failure I've seen, where people think their passwords are synced but because they didn't sign in years ago it's actually not backed up at all. At least on Chrome you get reminded of that all the time on YouTube/Google search, etc. I know for Safari all the sync is via iCloud meaning if you're no…

Firefox reminds you a bunch of times, too. Would be nice if you could just link a new device via QR code (creating an account for you in the background).

The original Firefox sync worked like this (with a unique code and pairing instead of an explicit account) (this is so on the nose I suspect you may know this).

This blog post goes over some of that history: https://blog.mozilla.org/services/2014/04/30/firefox-syncs-n...

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#109
post #34

Earlier quoted context omitted.

Keepass file on Google drive is kind of trivial though.

Never store anything remotely important on a Google service.

Never store the only copy of anything remotely important on any online service.

Storing copies is ok, though, provided that sensitive information is encrypted.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#110
post #50

Earlier quoted context omitted.

> Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good Interesting, I've always felt that browser-based password managers provided remarkably little value for most people. Using them on mobile is tricky and platform dependent, it's easy to have local-only, non-synced data and then lose it, and being multi-device is trickier, especially in a work…

Firefox password sync just works. It's one of those things I never think about. Watching friends and family struggle with bespoke, poorly integrated password managers makes me cringe and is one of the big reasons I enjoy the seamless experience of the built-in Firefox password manager.

it just works for websites. it does not "just work" for apps where as the platform ones do or have a chance to work with apps.

Kind of hope regulation will force apple/google/ms to allow iterations for 3rd parties to integrate with the os but on the other hand that will open a host of issues

Post reply on HN