Live data from Hacker News

Bitwarden Completes Third-Party Security Audit

blog.bitwarden.com

131–140 of 148 posts

Re: Bitwarden Completes Third-Party Security Audit

#131

Earlier quoted context omitted.

I used LastPass for roughly a year before making the switch. I also switched from Chrome to Firefox at the same time, on Windows and Android. Desktop - no issues! Android is evolving, and their changes seem to have put Firefox in a slightly behind position, which I think they're almost caught up on. Basically, there's legacy and modern autofill capabilities in Android, and Firefox is working on closing the gap. In th…

In Firefox, you can also open Bitwarden in a sidebar (which doesn't disappear thankfully).

Firefox for Android?

That's where my issues are. How do you open the sidebar?

Re: Bitwarden Completes Third-Party Security Audit

#132
has anyone here used Enpass? I use it and like it very much, because the UX is decent, and there is no "cloud" component whatsoever - it simply has a local DB which can be synced using Google Drive or Dropbox across all my devices. However, I am a concerned with their lack of a 3rd-party audit. So I've been eyeing BitWarden for that reason, but the need to run a server turns me off (especially since I'm not clear how that helps me sync the mobile clients). Those who host their own BitWarden instance: how do you approach the problems of backup and mobile sync?

Re: Bitwarden Completes Third-Party Security Audit

#133
post #7

Since Bitwarden added sub-domain support and fixed the speed-issues on large key-bases, I absolutely cannot live without Bitwarden it's been absolutely flawless. Previously used Lastpass for 8 years. So glad to see that it's security taken seriously by the developers!

>Previously used Lastpass for 8 years. As a longtime Lastpass user, this is the comment that made me go check it out. Are there any big pros or cons you have run in to compared to Lastpass (aside from the ones you listed)? I'm asking about actual functionality, not about the it being open source and such.

Here's my end user take on it. I have moved from LastPass after almost 10 years and going to stick to it for two main reasons:

1. It's cleaner and doesn't feel bloated

2. It's open source.

However I wish:

3. They would have some consistency between mobile (iOS) and extension (Safari) UI (because imho extension actually looks like a mobile UI, I find iOS UI less useable)

4. They would do away with load time that I often notice when I open extension even though data is stored locally.

5. It doesn't maintain state or save info when I leave the extension popped up and then move away and come back to it. Also, It also doesn't save auto generated passwords with the "url" it was generated on which often renders password history useless.

6. For everything I have to reach all the way to the browser bar extension button and I don't get any option in the text field itself which was pretty good in LastPass.

I wanted to move to KeePass and while it has an excellent app for desktop (native MacPass is fantastic!), but I could hardly find anything even close to useable for Safari or iOS.

Re: Bitwarden Completes Third-Party Security Audit

#134

has anyone here used Enpass? I use it and like it very much, because the UX is decent, and there is no "cloud" component whatsoever - it simply has a local DB which can be synced using Google Drive or Dropbox across all my devices. However, I am a concerned with their lack of a 3rd-party audit. So I've been eyeing BitWarden for that reason, but the need to run a server turns me off (especially since I'm not clear how…

I use Enpass and I like it, though I don't love it. I have a few pain points that make me consider looking elsewhere.

I like: No recurring price just buy once per platform and off you go, no hosted component it just uses my Google drive, ability to add additional items to the things it tracks like the places that insist on 5 "security questions", Android app with fingerprint is nice.

Things I don't like about Enpass:

- No ability to have multiple databases. I would really like to have the ability to have a database shared with my spouse, and one shared with my work.

- I never was able to get the Chrome integration to work on ChromeOS and that is my primary personal OS these days.

Generally it works well, but I'd love to get my wife using one, would like to have one I can share with my wife, and would like to replace our ancient work password vault that is Windows-only.

Re: Bitwarden Completes Third-Party Security Audit

#135
post #70

I've never used a password manager, I memorize them - dozens of them. And almost all of them are uniqe and "strong" passwords. Now I have a feeling that this situation is a real burden for my mind/brain and I consider using one; just trying to convince* myself. Up until this time, I was thinking that "it's a good mental exercise!", not any more. Maybe the reason is now I have too many things to ponder upon. I'd like…

Memorizing your passwords seems impossible to me. The passwords I've put in my new password vault over the last year probably number in the mid 3 digits, and I don't really think I have THAT big an online footprint. So either: You share passwords among sites (which I never do) or you have a WAY better memory than I do. Or, I guess, you just use the password reset a lot?

Here are some things that make it really hard to remember all the passwords I need to:

- One bank requires me to change my password every month that I login. Don't even get me started.

- Many sites require 3-5 "security questions", which I consider to be effectively passwords and generate/manage them as such.

- Different sites have different allowed formulas of what they require for passwords

Memorizing passwords seems like a recipe for reuse of the same passwords on multiple sites, which is terrible.

Re: Bitwarden Completes Third-Party Security Audit

#136

Earlier quoted context omitted.

From your experiences is there any downside or drawbacks with switching? I've been considering it, particularly as Lastpass's Firefox app has been flakey and unreliable. In general Lastpass has become less reliable since the LogMeIn take-over, and they've now added ads to the vault which bug me from a security perspective (even if I happily pay $2/month, it is the principle of putting profits over security).

Another LastPass user of ~5 years. I was actually dreading the switch, just because of the amount of time I had spent using it (mostly always Premium). That and I have a workflow within the family for sharing, etc. I planned on a week long switch over to make sure things went smooth. However after switching, and validating all common accounts has been imported correctly I just never had to open LastPass again. This t…

Was there an import/export process you used to transfer your existing safe?

Re: Bitwarden Completes Third-Party Security Audit

#137
post #68

Earlier quoted context omitted.

You can do "free" sync to Dropbox or a folder, which you can mount with SSH-FS. "Free", as in no additional cost.

Which one are you talking about?

I think he's talking about 1password. You can sync to dropbox or any folder (that can be controlled by dropbox/spideroak/sshfs/nfs/whatever)

Re: Bitwarden Completes Third-Party Security Audit

#139

has anyone here used Enpass? I use it and like it very much, because the UX is decent, and there is no "cloud" component whatsoever - it simply has a local DB which can be synced using Google Drive or Dropbox across all my devices. However, I am a concerned with their lack of a 3rd-party audit. So I've been eyeing BitWarden for that reason, but the need to run a server turns me off (especially since I'm not clear how…

I use Enpass exclusively. Having switched from Lastpass a couple years ago. I neglected to pay the premium, and was unable to access some really needed data in the middle of a situation, but couldn't because the premium expired. After that situation, I said fuck you to paid services. While I get the benefits of them, it's not useful if you run into a situation like this where you are locked out of your own data for failure to pay on time.

Enpass was worth the cost for mobile access. But that's all I had to pay. I can now use it on every Win/Lin/Mac/Phone system available to me. Sync seamlessly in the background with my preferred cloud provider, which also requires 2FA to access. So I feel reasonably secure.

Re: Bitwarden Completes Third-Party Security Audit

#140

Earlier quoted context omitted.

>Previously used Lastpass for 8 years. As a longtime Lastpass user, this is the comment that made me go check it out. Are there any big pros or cons you have run in to compared to Lastpass (aside from the ones you listed)? I'm asking about actual functionality, not about the it being open source and such.

Here's my end user take on it. I have moved from LastPass after almost 10 years and going to stick to it for two main reasons: 1. It's cleaner and doesn't feel bloated 2. It's open source. However I wish: 3. They would have some consistency between mobile (iOS) and extension (Safari) UI (because imho extension actually looks like a mobile UI, I find iOS UI less useable) 4. They would do away with load time that I oft…

Thanks for the info.

I tested out Bitwarden after I posted this question yesterday. Regarding #6, that did bother me as well. I wanted to let you know there's a fix for that (at least in Chrome there is, I don't know about Safari).

Settings > Options > Enable Auto-fill On Page Load - that will automatically fill out the login forms like LastPass does by default. But I do wish they had the option to disable this on a per-secret password like LP does.

Also right clicking on the page will give you a Bitwarden context menu which provides an auto-fill option (Right Click > Bitwarden > Auto-fill > Pick the secret). This is actually more steps than clicking the extension button at the top (Click extension button > click secret), but at least you don't have to move all the way to the top of the page.

Again, this is in Chrome.

Post reply on HN