Live data from Hacker News

The quiet renovation at Bitwarden

blog.ppb1701.com

141–150 of 333 posts

Re: The quiet renovation at Bitwarden

#141

I got my parents using bitwarden a few years ago. This was a massive improvement over them writing passwords in a little notebook in a drawer (yes, really!). But Keepass is a bridge too far for them. I'm not that enthusiastic about it myself to be honest. The UX is a bit meh (for the clients/extensions I've tried) and file syncing and handling is not something I can in good conscience push to a non technical user. It…

Passwords in a notebook are arguably the most secure option. The notebook exists in exactly one place, behind locked doors, and cannot be leaked or hacked externally. Notionally a password manager is more secure, but is there anything stopping Bitwarden from updating the app to silently send your master password up to the mothership and selling your unencrypted vault? Even supposing they stay open source and get caug…

How did we as an industry go from "Passwords in notebooks are insecure, use a password manager" full circle back to "Password managers are insecure, write your passwords in notebooks"?

Re: The quiet renovation at Bitwarden

#142
is there an enshittification watch site? or something to track acquisition and red flags in products/oss projects? itsenshittifiedyet.info if not, what would it take to do that? i think it can be vibed in a weekend.

edit: s/of/and

Re: The quiet renovation at Bitwarden

#144
post #78

I have moved to KeepassXC[1] on my desktop from Bitwarden. On phone, I use KeepassDX[2] which is Android client compatible with KeepassXC. On browser, I use KeepassXC Browser extension which connects with the desktop client. Since KeepassXC operates on a single file, you can use any Filesystem syncing tool to sync that file between devices or to store it in the cloud. I am really happy with the move. [1]: https://kee…

Recently moved to a KeePass setup after 1Password raised their prices. Feels good to be in complete control.

Re: The quiet renovation at Bitwarden

#145
post #128

It does seem like most password managers have no moat for import/export, so I’m kinda banking on the idea that I can quickly migrate to Proton Pass or vaultwarden if things get ugly. I just don’t want to self-host if I can avoid it. Staying on top of managing the application and the environment is a whole different level of diligence when the thing I’m self hosting is the keys to my life. At a minimum it would have t…

Does Proton Pass use a wireguard tunnel? Or does Bitwarden? TLS should suffice. Yes, you want to guard the machine that hosts your passwords. You can even physically keep it at home, and only proxy its port 443 wherever you have a presence in the public Internet.

Those at least have people whose literal jobs are to protect that stuff. The service, the clients, the transport, the environments, etc. That’s what I don’t have if I self host.

That’s not to say anything is bulletproof… nothing useful is… just that I don’t entirely trust myself to be 100% on top of something like that as a hobby hosting endeavor.

Re: The quiet renovation at Bitwarden

#146

When I first learnt about Bitwarden about 3 years ago, I started hosting Vaultwarden right away. Right now I have one instance for myself and another for my friend's company. Everything runs as smooth as butter. If you can self-host something, do self-host a Vaultwarden instance. If you are (like me) somewhat paranoid about the fact that Vaultwarden hasn't got a proper security audit on its codebase, just run it behi…

Yes, but vaultwarden isn't something you can casually run by yourself without some careful thinking. You are hosting secrets whose longevity is important, so if deploying yourself, take good care of backups and do regular drills, so you validate that the backups work, that they aren't corrupted and that you keep a copy off-site.

Me and some friends have each been hosting vaultwarden casually for years now. What problem do you see? I mean if the Server goes down and gets completely corrupted, worst case, all my devices still have the version of the vault they recently used. Technically every device has it's own backup of the vault.

Re: The quiet renovation at Bitwarden

#147
post #100

> That’s not a software guy who happened to raise some money. That’s someone whose stated specialty is the PE integration and exit process. Holy smokes has that's not just -> THAT IS become one of my trigger words.

It's almost certainly ai written though. All the regular tells are there... Though he likely edited some out, like that "just" Also if it was handwritten, it'd have been a third in length, the rest was LLM fluff

Correct, that was my point

Re: The quiet renovation at Bitwarden

#148
post #146

Earlier quoted context omitted.

Yes, but vaultwarden isn't something you can casually run by yourself without some careful thinking. You are hosting secrets whose longevity is important, so if deploying yourself, take good care of backups and do regular drills, so you validate that the backups work, that they aren't corrupted and that you keep a copy off-site.

Me and some friends have each been hosting vaultwarden casually for years now. What problem do you see? I mean if the Server goes down and gets completely corrupted, worst case, all my devices still have the version of the vault they recently used. Technically every device has it's own backup of the vault.

If I stay offline for more than 30 days, can I still access my local passwords? Honest question, because if that's the case it's nice, but I think you'd need to somehow authenticate before accessing your local vault.

Re: The quiet renovation at Bitwarden

#149

Earlier quoted context omitted.

Question for anyone self-hosting vaultwarden: how reliable is it and how do you harden it? I'm thinking about running it in a container (Podman Quadlet with systemd) behind a VPN, with daily backups with borg. Anything I'm overlooking here?

> Anything I'm overlooking here? Not technical, but the person behind that project now works for Bitwarden so there's some risk of a rugpull. Of course it's OSS but you'll need to trust a fork or maintain it yourself if said rugpull happens.

Kind of makes a lot of sense that they wound up working there too.

Re: The quiet renovation at Bitwarden

#150
post #136
post #66

Earlier quoted context omitted.

+1 I am a paid subscriber. I am kind of ok with the price increase. The "coincident" with change of CEO and remove of "always free" tag worries me though.

I just sent them a message along these lines. I’m happy to pay for good services, but M&A means cost-cutting measures to make the company look good for acquisition and that makes me uncomfortable with letting them store secure data for me. Switching is going to be a pain.

It is really easy to self-host, and do so securely...
Post reply on HN