Live data from Hacker News

Get your passwords out of Bitwarden while you still can

osnews.com

161–170 of 203 posts

Re: Get your passwords out of Bitwarden while you still can

#161
post #107

Earlier quoted context omitted.

It’s about the backpedaling. No one says it has to be free, they said that. They just have to keep their promise.

And, honestly, if they came out with a statement that said (effectively), "Look, we're losing money here... we just _can't_ support free going forward. Here's our plan" that would be understandable. Sometimes you have a plan/goal, and you realize later that you were wrong and things need to change. But that's not what they did.

I disagree, there is always a way to keep it free, if you care about keeping your promises. Especially in this case where the service is essentially locally encrypted json blob storage. There’s already plenty of premium functionality not included. If you have runaway costs due to abuse, just make up new limits to solve it.

Re: Get your passwords out of Bitwarden while you still can

#162
post #147

Earlier quoted context omitted.

> in 5 years when bitwarden disables exports i think this is the overreaction - getting worked up about these sort of risks in general isn’t worth your time. Otherwise you’d end up self-hosting everything strictly on OSS from maintainers you personally know and trust. This is like someone saying, “don’t use AWS because they might raise prices some day”

With the escalating abusive practices on display, going towards ‘self hosting everything strictly on OSS’ at least is exactly where this is all going.

This is like the tech version of being a prepper

Re: Get your passwords out of Bitwarden while you still can

#163
post #153

Earlier quoted context omitted.

> I assume non-technical people ought at least be able to put their KeePass files on DropBox? Non-technical people would not do something this complicated. They don’t even have password managers, let alone a setup like this. Shoot, even a lot of technical people (like me) wouldn’t bother with this. It’s why I pay for a cloud-based password manager.

> > I assume non-technical people ought at least be able to put their KeePass files on DropBox? > Non-technical people would not do something this complicated. They don’t even have password managers, let alone a setup like this. Google Drive/iCloud/OneDrive/Dropbox are already used by non-technical users - moreso than SaaS password managers. > Shoot, even a lot of technical people (like me) wouldn’t bother with this.…

For other types of files, I have different apps: Obsidian Vaults with Syncthing, but that’s not accessible from the internet. And I like having my passwords across all my devices, updating anywhere I am.

And for me, it’s just not worth the headache (and security risk) of hosting my own password manager.

Re: Get your passwords out of Bitwarden while you still can

#164

This is an incredible overraction over a minor change that did not even happen. You can still find "Always free" in the pricing line of the very same page everyone keeps linking as proof https://bitwarden.com/products/personal/#whats-the-differenc... Edit: it actually disappeared for some time but they put it back on May 18 snapshot from May 15: https://web.archive.org/web/20260515190646/https://bitwarden... snapshot…

Well it did happen - and then unhappened when people noticed.

So what does it matter?

If they are going to make it not free, they can just remove it right before they make it not free.

If it was somehow a binding promise, then it doesn’t matter if they remove it or not, the promise was already made.

If it isn’t a binding promise, then it doesn’t matter if they remove it or not, the promise was not binding anyway.

Re: Get your passwords out of Bitwarden while you still can

#165
post #41

So I have an admission here: I keep seeing HN stuff about these networked password managers and I don't quite understand the appeal. Is it because everybody else is swapping between several different computers, and you need the synchronization? I just have everything in KeepassXC, and the ciphertext is subject to the same kind of backup regime I use for other files, [edit: and also additionally] a copy kept on a USB…

I use vaultwarden hosted on my own server.

I use it to sync between my phone, tablet, laptop, and two desktops.

I want to be able to add a login from any of those, and have it be updated on all of them.

I might have more machines than most, but everyone has at least a computer and a phone, seems reasonable to want to link those two.

Re: Get your passwords out of Bitwarden while you still can

#166
post #153

Earlier quoted context omitted.

> > I assume non-technical people ought at least be able to put their KeePass files on DropBox? > Non-technical people would not do something this complicated. They don’t even have password managers, let alone a setup like this. Google Drive/iCloud/OneDrive/Dropbox are already used by non-technical users - moreso than SaaS password managers. > Shoot, even a lot of technical people (like me) wouldn’t bother with this.…

For other types of files, I have different apps: Obsidian Vaults with Syncthing, but that’s not accessible from the internet. And I like having my passwords across all my devices, updating anywhere I am. And for me, it’s just not worth the headache (and security risk) of hosting my own password manager.

> For other types of files, I have different apps

How many separate services do you have for accessing files across devices, and what do you do for filetypes outside of what they cover?

> And I like having my passwords across all my devices, updating anywhere I am.

That's how it works for me with a passwords.kdbx file on my FTP server (but any cloud storage works). Same for any filetype.

> And for me, it’s just not worth the headache (and security risk) of hosting my own password manager.

What's the security risk? If anything, it's SaaS password managers that seem to semi-regularly get hit with breaches (well, mostly LastPass).

You don't need to host anything for KeePass - just plop the file next to your notes/etc.

Headache seems greater overall if you're juggling a large number of subscriptions, particularly when they start ramping up payment or moving features you rely on to higher tiers.

Re: Get your passwords out of Bitwarden while you still can

#167
post #41

So I have an admission here: I keep seeing HN stuff about these networked password managers and I don't quite understand the appeal. Is it because everybody else is swapping between several different computers, and you need the synchronization? I just have everything in KeepassXC, and the ciphertext is subject to the same kind of backup regime I use for other files, [edit: and also additionally] a copy kept on a USB…

> I just have everything in KeepassXC Me too, but I rarely add/edit anything in .kdbx file, it rarely changes. So I just keep a copy on my phone and use KeePassDroid to open it sometimes. If you change/edit your passwords all the time, and you like autofill and I assume other features, networked solutions are much better.

Who doesn’t like autofill? It makes everything SO MUCH easier.

And it isn’t about changing/editing passwords all the time, it is about all the new passwords that are constantly being added.

Re: Get your passwords out of Bitwarden while you still can

#168
post #59

Earlier quoted context omitted.

Having a password manager synced to phone, desktop, laptop, browsers is handy. I used Keepass 10 years ago but I prefer integrated experiences now, particularly since I often pull them up on mobile. Also consider teams or multiple teams across an org sharing secrets. Flat files are a tough sell, so these apps eliminate almost all the hassle. We pay for a lot of 1Password accounts, and I couldn’t imagine rolling our o…

The Apple Passwords app does all this just fine. The only thing it's missing is secure notes to store my 2FA recovery codes in.

That works if all your devices are Apple devices.

Re: Get your passwords out of Bitwarden while you still can

#169

Clients are OSS, I wonder why nobody did a Vaultwarden-style fork of them yet that would watch over upstream changes.

Probably because there is no need to fork until you have to. Why do it prematurely and have to keep it up to date when you can just do it when it is needed?
Post reply on HN