Live data from Hacker News

Get your passwords out of Bitwarden while you still can

osnews.com

171–180 of 203 posts

Re: Get your passwords out of Bitwarden while you still can

#171

The original creator of Bitwarden still works there as a CTO. I am curious whether he has any failsafes/poison pills in his contract when he took VC money that allows him to fork the product and start over in the event that they decide they want to lock everything down. Or did he sign all of those rights away when he took the $100M "fuck you" VC funding in 2022.

Do you need a contract like that when the product is open source? The only thing he couldn’t keep would be the name.

Re: Get your passwords out of Bitwarden while you still can

#172

The original creator of Bitwarden still works there as a CTO. I am curious whether he has any failsafes/poison pills in his contract when he took VC money that allows him to fork the product and start over in the event that they decide they want to lock everything down. Or did he sign all of those rights away when he took the $100M "fuck you" VC funding in 2022.

Do you need a contract like that when the product is open source? The only thing he couldn’t keep would be the name.

There would be nothing preventing him in the source license, but I'm saying he may be prevented as part of the contract he signed when he sold the company.

Re: Get your passwords out of Bitwarden while you still can

#173
post #113

Earlier quoted context omitted.

I had checked as soon as I found out about the news the other day and it was there. I just checked on wayback machine and you're right, it was removed for some time. However, if they're willing to put back that claim immediately, I doubt that their intention was to drop the free plan anytime soon, but probably it was to incentivize people to use the paid plans. Enshittification must happen sooner or later afterall, b…

> Enshittification must happen sooner or later afterall There are a fair amount of multi-hundred year old companies out there.

Companies can enshittify without dying, ahem microslop. Bitwarden likely isn't large enough to survive though.

Re: Get your passwords out of Bitwarden while you still can

#175
post #135

Earlier quoted context omitted.

Not really. That something is convenient doesn't mean that it's a good idea. It's always a matter of convenience vs security.

When people had to rotate passwords every month and choose a new one according to insane complex rules and dictionary tests, well, that was not convenient. You would probably say it's good. Reality: people started writing their passwords on sticky notes by their computer. Possibly the worst outcome. Convenience is part of good security.

Why the worst outcome, though? "Sticky notes" are absolutely superior to third-party password managers in regard to "attackers."

Third-party password managers INCREASE your threat surface by orders of magnitude more than sticky notes, period. They change the number of holders of secrets from two to three, and that third one is now a juicy target. This is not theory, this has happened frequently.

Sticky notes (even better, a little private physical notebook) keep this limited to your physical location which is much easier to secure; the grandmas and grandpas I know who do this (I do similar) have a far better track record than anything else.

Re: Get your passwords out of Bitwarden while you still can

#176
post #124

Earlier quoted context omitted.

Well it did happen - and then unhappened when people noticed.

There have been plenty of cases like this over time too. Company makes controversial change. Company rolls it back after outrage. Company slowly shifts over time until they've restored what's essentially the original controversial change. When a company tells you their intention by announcing a change, it's often a good idea to listen. Even if their PR department does some good cleanup work in the aftermath.

Yeah exactly. When a company announces some money making scheme and it gets backlash they don't think "oops that was a mistake we won't do that"; they think "oops that was a mistake - we'll have to do it in a way that gets less backlash".

Another recent example is GitHub charging for self-hosted CI. They backtracked, but they're still going to end up doing something. They kind of have to because of all the "get 10x cheaper actions runners by changing one line" people.

Re: Get your passwords out of Bitwarden while you still can

#177
post #166

Earlier quoted context omitted.

For other types of files, I have different apps: Obsidian Vaults with Syncthing, but that’s not accessible from the internet. And I like having my passwords across all my devices, updating anywhere I am. And for me, it’s just not worth the headache (and security risk) of hosting my own password manager.

> For other types of files, I have different apps How many separate services do you have for accessing files across devices, and what do you do for filetypes outside of what they cover? > And I like having my passwords across all my devices, updating anywhere I am. That's how it works for me with a passwords.kdbx file on my FTP server (but any cloud storage works). Same for any filetype. > And for me, it’s just not w…

> What's the security risk? If anything, it's SaaS password managers that seem to semi-regularly get hit with breaches (well, mostly LastPass).

Talk to your local security engineer :)

On a venting note, this mentality is a frustration I have with SV, because I see it a lot. They don’t know what they don’t know, and think they can just stand up businesses without understanding the domain.

Re: Get your passwords out of Bitwarden while you still can

#178
post #166

Earlier quoted context omitted.

> For other types of files, I have different apps How many separate services do you have for accessing files across devices, and what do you do for filetypes outside of what they cover? > And I like having my passwords across all my devices, updating anywhere I am. That's how it works for me with a passwords.kdbx file on my FTP server (but any cloud storage works). Same for any filetype. > And for me, it’s just not w…

> What's the security risk? If anything, it's SaaS password managers that seem to semi-regularly get hit with breaches (well, mostly LastPass). Talk to your local security engineer :) On a venting note, this mentality is a frustration I have with SV, because I see it a lot. They don’t know what they don’t know, and think they can just stand up businesses without understanding the domain.

> Talk to your local security engineer :)

You made the claim - I'm interested to hear why you believe it, because I suspect it's based on a misunderstanding of how KeePass works.

> and think they can just stand up businesses without understanding the domain

Using KeePass is not analogous to standing up a business.

Re: Get your passwords out of Bitwarden while you still can

#179
post #77

Serious question - how come free is a requirement for a password manager? Everyone's gotta eat, including the maintainers of password managers. Tech has generous TC, lots of high-end laptops and phones worth thousands, AI & cloud spend, and yet the only acceptable price for secrets management is $0 it seems at times.

It doesn’t have to be free, but it can’t be set up so they can take it away from me. I self-host Vaultwarden to get that right now. Even if they break client compatibility, I still have the web vault with access to my passwords.

As soon as a company positions themselves to hold your data hostage, assume they will. I have no problem paying, but I’m not going to pay anyone trying to trap me. That’s the goal of most of these tech companies now.

My opinion and stubbornness doesn’t matter though. Identity control is getting lobbied into government legislation everywhere. Everyone’s going to pay no matter what, probably twice; once directly, once via taxes.

Re: Get your passwords out of Bitwarden while you still can

#180

I'm taking a "wait and see" approach with Bitwarden. I've been a paying customer for a while, happy with it, and hoping the leadership changes won't be too user hostile. Still, a major reason I chose Bitwarden to begin with is they have a decent "Export" button, and all of this news reminded me that my offline backup of the vault was a few months old. Regardless of their product roadmap, they could have an incident t…

> I'm taking a "wait and see" approach with Bitwarden.

I won’t. The optics look bad and that alone is enough to show the leadership is either hostile to users or too inept to understand why their recent actions signal a change away from what people value in their product. If they don’t understand or care about the same things as the community / customers, there’s no reason to think they’ll make choices that continue to be a good value proposition for their customers.

The only thing that’s going to stop tech companies from pulling this crap is if a hint of private money coming in to ruin everything ends up ruining things before everyone gets to cash in. Basically, a mass exodus and bankruptcy would be the only outcome that makes the next company think twice about using the enshitiffication playbook.

We need some companies built around fair value instead of extortion and they need to be run like Steam. Steam has an unbreakable hold on gaming because they’ve never screwed their users.

Post reply on HN