Live data from Hacker News

Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

fastcompany.com

111–120 of 150 posts

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#111
post #81

Just use vaultwarden https://github.com/dani-garcia/vaultwarden

I do, but this still uses the Bitwarden app and browser extensions. I'm now worried that in pursuit of monetization they'll start screwing with those. After all, the code in the clients have access to all recorded secrets and there would be nothing stopping them from accessing that unencrypted data.

I really doubt they would push a client that removes the master password based client side encryption. That could even be considered criminal.

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#113

Earlier quoted context omitted.

So what would you recommend to your friends and family that need a password manager? Genuinely curious. I pay for a service for my family because I need reliable and easy for my wife and daughter to use it.

- KeePass files synced between laptop and phone on OneDrive, DropBox, etc - KeePassXC on Windows and Mac - Keepass2Android mobile client - Browser integration on mobile. - On laptop, I prefer no browser integration; Copy username and password with Ctrl+B and Ctrl+C

Seconding this. I use KeePassXC on my PC, KeePassDX on Android (available on F-Droid), synced with Syncthing. Works very well.

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#114

Actually, the part of the article that made me prick my ears up was this paragraph: In February, longtime CEO Michael Crandell moved to an advisory role, according to LinkedIn, with no announcement from the company. His replacement, Michael Sullivan, former CEO of both Acquia and Insightsoftware, touts his experience with “all facets of mergers and acquisitions” on his own LinkedIn page, including experience working…

Well, it was nice while it lasted.

Hardly.

I wanted to like it, but didn’t.

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#115

Earlier quoted context omitted.

A small notebook. Unhackable. Yours forever. Use words based passwords to make entry easier. Suffers from physical presence security hacks. I argue those are far less frequent than online hacks. Wouldn’t recommend for people who are comfortable with Password managers. It is super easy to explain to people how to use it. And some security is better than none.

Extremely hackable on travel.

Shoot. I didn’t think of the TSA.

And wow… just even the cops.

I am more worried about “lawful” “government” “agencies” stealing my crap than actual criminals. And that makes me sad.

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#116

Actually, the part of the article that made me prick my ears up was this paragraph: In February, longtime CEO Michael Crandell moved to an advisory role, according to LinkedIn, with no announcement from the company. His replacement, Michael Sullivan, former CEO of both Acquia and Insightsoftware, touts his experience with “all facets of mergers and acquisitions” on his own LinkedIn page, including experience working…

When did they remove DEI language? And how is that relevant, either way?

To get approval for a merger under the current US admin, a company needs to show ideological purity.

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#117
post #108

Earlier quoted context omitted.

It's relevant because it was ostensibly a value of Bitwarden's at some point, but they've thrown it under the bus now that they're looking for a buyer.

[flagged]

Yes. Enshitification after an acquisition by private equity is a real threat to Bitwarden's perennity as a secure and free password manager.

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#118

How does the GPL licensing affect future versions of the open source clients? I use Vaultwarden right now. Part of the reason was that I wanted something where there was a minimum guarantee. In the case of Vaultwarden, I can always fall back to the web interface if needed. It wouldn't be convenient, but it guarantees no one can take away my password vault. I really hate the per user per feature per byte per year pric…

> What we need in the small business space is a tier of services where small businesses can self host using their own on-premise, vertically scalable infrastructure (ie: 1 server). In most cases they can tolerate some downtime and, even if they don't want to, a lack of resources usually means they don't have a choice (ex: they're not running HA network connections).

I think the same: Small service businesses care most about Time To Recovery (TTR) when doing services. As long as they communicate at least by phone and the website is up, they usually tolerate downtime when they know when their backoffice services are back online.

This is classic Business Continuity Management, 5-10 questions usually make clear what must work in every case when and what has to be available for supporting this process. Example: I got a customer which prints all logistics / distribution labels in batches. They can still work where money comes in (=shipping stuff) for quite a long time (4h min, 8h max) if the next batch of labels cannot be printed / some system is going down needed to support shipping. So no need for expensive HA around legacy software, but enough time for a good process to get back online with the latest backup on replacement hardware which is already there on-site.

The thing is: HA is FAR more expensive and complicated than e.g. getting another stand-by server as fast replacement, maintain the hypervisor on this second server e.g. every six month and test restoring backups on it once a month (best: automated: IMPI boot, restore without VM networks, testing, shutdown). Same with a firewall; two used Enterprise Servers + Proxmox VE Subscription, OPNSense + 2 x N150 Hardware and two consumer WANs (e.g. Cable and VDSL) is really not that expensive if only the WAN is a bit more complicated from the POV of a SME admin because of failover. Classi VLANs+ACL and services like surveillance as needed...

> Businesses with Exactly. This is why I do SME IT since ever, no matter for which $BigCorp I've done consulting and DevOps. I automate them. I consult them. My company (plug: https://foundata.com) does it for a few bugs per month (Hypervisor, Groupware (Calendar, Mail) Firewalling, VPN, Directory Services, Jitsi/OpenCloud/BBB) if they understand that they finance the high quality of the managed services ON THEIR HARDWARE with all other customers and we do not work per-hour but per-service + we run Open Source also for other reasons than "no or fewer licensing costs".

And I like it even this does not make you rich. Because I REALLY share your concerns ("owning all the small businesses of certain types; family doctors, dentists, optometrists, vets" -> I don't know where you are from, but it is the very same here in Germany... example: https://www.ndr.de/fernsehen/sendungen/panorama3/Spekulanten...)

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#119
post #76
post #61

Earlier quoted context omitted.

This feels like deja-vu with Lastpass. LogMeIn buys Lastpass, multiple massive breaches occur[, people move to Bitwarden].

Did Lastpass have a project like Vaultwarden behind it at the time? I'm hoping against hope that that will keep us with an open vault.

The issue is that a huge amount of value is tied up in the client applications, which do not have community-maintained equivalents.

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#120

Actually, the part of the article that made me prick my ears up was this paragraph: In February, longtime CEO Michael Crandell moved to an advisory role, according to LinkedIn, with no announcement from the company. His replacement, Michael Sullivan, former CEO of both Acquia and Insightsoftware, touts his experience with “all facets of mergers and acquisitions” on his own LinkedIn page, including experience working…

Well, it was nice while it lasted.

I use bitwarden, but it not being able to share a single secret is becoming an issue.

In my search for alternatived I stumbled across https://passbolt.com/ AGPLv3 and does support sharing single secrets, but no free hosted version. Free if you self host of course.

It guess it's a vaultwarden without "the man in Nebraska" problem.

Post reply on HN