Earlier quoted context omitted.
I self-host Vaultwarden. I'm sure someone will be happy to explain to me how foolish my implementation is, but I'm comfortable with it from a security perspective. I run it as a Docker instance on my home Synology NAS. This turned out to be pretty easy to do. The only part that was a slight hassle was buying a cert, creating an FQDN and making the DNS entries to get an SSL connection to the NAS. Also, I wish updating…
> The only part that was a slight hassle was buying a cert, creating an FQDN and making the DNS entries to get an SSL connection to the NAS Note that Synology DSM has built-in Let's Encrypt support
Bitwarden Acquires Passwordless.dev
141–150 of 399 posts
Re: Bitwarden Acquires Passwordless.dev
#142Earlier quoted context omitted.
I'm happy for the one dev who's been lone rangering as I hope it means he's finally getting paid, but the pressure is going to be on to get an ROI.
Insane radical idea: Businesses can actually make a profit by having income higher than expenses. You can pay yourself that way.
Re: Bitwarden Acquires Passwordless.dev
#143Earlier quoted context omitted.
> Bitwarden recently raised 100M from VC I wasn’t aware of this, but I’m glad I am now. If that’s the case it’s time to look elsewhere or self host, VC funds and acquisitions are rarely good for users so I’ll assume the worst.
> VC funds and acquisitions are rarely good for users Where does this sentiment come from? I know very few applications I use that are VC funded or haven't gone through acquisitions...
If the user base does not increase at some rate determined by the investor, then growth comes in the form of advertising, partnerships, or similar that negatively affect the _product_ existing customers signed up for.
Re: Bitwarden Acquires Passwordless.dev
#144Your passwords shouldn't leave your device. Chrome's password manager is pushing it. Everything else should be considered malware. I don't understand how such a 'techy' crowd here on HN can be so belligerent with this security vs convenience trade off. KeePass locally, gmail yourself an encrypted backup. That's it. FFS.
Re: Bitwarden Acquires Passwordless.dev
#145I like where passwordless.dev is going. However, I don't think I'd like to build a business on top of that. Is there a similar implementation that's open-source that doesn't depend on a third party?
Re: Bitwarden Acquires Passwordless.dev
#146Earlier quoted context omitted.
Ideally I'd want to keep my _personal_ personal stuff separate from my "work personal" (ie my personal logins, but the one for work accounts) separate from my shared work stuff. So I'd want two accounts, one for my truly personal accounts, and then one for my work-personal and have the work-shared connected to that.
There doesn't seem to be a security benefit of doing this if you encounter having to swap between personal-personal and work-personal. It doesn't take me many seconds to swap accounts. LastPass allows you to be signed into two accounts at the same time in the same browser?
Re: Bitwarden Acquires Passwordless.dev
#147Re: Bitwarden Acquires Passwordless.dev
#148Earlier quoted context omitted.
Also Bitwarden recently raised 100M from VC so yeah, the clock is ticking now.
Ah for fuck's sake. It keeps happening to all the software I love. I guess I'll have to stop relying on convenience (I was a 1Password user years ago) and go 100% open-source. None of the libre offerings seem to be as convenient and polished, but at least they're not into some VC's pocket ready to squeeze as much profit as possible out of my paid membership. What's a good OSS alternative that works with iOS and Linux…
I agree, and I wish we had more power in these things than just forking. Now that I know Bitwarden took VC money, I'm also fucking out of this mess, and here I was about to renew for the 5th year in a row.
Fuck VC's, they ruin everything good. Can I say that here? It's true.
Re: Bitwarden Acquires Passwordless.dev
#149Earlier quoted context omitted.
I just switched password managers from LastPass, and Bitwarden's lack of multiple accounts on their browser plugin was a dealbreaker for me. Such a basic feature, especially if they want to get widespread adoption. Otherwise, anyone whose work uses Bitwarden basically can't also use it for their personal stuff without jumping through hoops.
Aren’t you supposed to have your personal Bitwarden account and get work passwords shared to your account? I thought that’s how Bitwarden for organisations worked.
Not sure why the web extension doesn't. Might have something to do with autofilling or adding credentials to HTTP Basic Auth?
Re: Bitwarden Acquires Passwordless.dev
#150Earlier quoted context omitted.
Ah for fuck's sake. It keeps happening to all the software I love. I guess I'll have to stop relying on convenience (I was a 1Password user years ago) and go 100% open-source. None of the libre offerings seem to be as convenient and polished, but at least they're not into some VC's pocket ready to squeeze as much profit as possible out of my paid membership. What's a good OSS alternative that works with iOS and Linux…
KeepassXC has served me well for many years, synced via my Nextcloud but could just as easily use dropbox or icloud, or even syncthing.