Live data from Hacker News

The quiet renovation at Bitwarden

blog.ppb1701.com

181–190 of 333 posts

Re: The quiet renovation at Bitwarden

#181
post #165

IANAL but if a company advertises "always free" and then starts charging, how is that not either false advertising and/or a breach of contract?

It’s a “always a free option” which doesn’t clarify what you get with the free version.

IIRC LastPass did this by slowly reducing how many devices and what kinds you could sync. They made the free option increasingly painful.

Re: The quiet renovation at Bitwarden

#183

Earlier quoted context omitted.

Bitwarden hasn’t “enshittified” anything. It’s all entirely speculative

Does a bear shit in the woods?

Interesting, where are you from? Where does this proverb come from?

I know this proverb as (translating from Polish): You're asking the boar if he's shitting in the forest.

Re: The quiet renovation at Bitwarden

#184
post #78

I have moved to KeepassXC[1] on my desktop from Bitwarden. On phone, I use KeepassDX[2] which is Android client compatible with KeepassXC. On browser, I use KeepassXC Browser extension which connects with the desktop client. Since KeepassXC operates on a single file, you can use any Filesystem syncing tool to sync that file between devices or to store it in the cloud. I am really happy with the move. [1]: https://kee…

This is my exact plan too, if I ever have to leave the Apple ecosystem.

KeePassXC is cross-platform FYI

Re: The quiet renovation at Bitwarden

#185

Say what you will, but the Apple ecosystem's Passwords app and integration works great. It locks me into their services (iCloud), but I don't see them ever charging for it or sunsetting it. (watch me eat my words in the near future)

Google's is even better, as it is cross-platform (although same caveat of having even more dependency on your account is still true). Plus (not sure about Apple) but Google also does (portable) passkeys and OTP.

Re: The quiet renovation at Bitwarden

#186
post #153
post #143

How hard is it to fully migrate from Bitwarden to Apple Passwords / Google Passwords? I guess I'm going to have to spend 2 hours on this next weekend.

If you have Bitwarden installed on an iPhone, you can export directly to Apple Passwords with no intermediate steps or trying to figure out where to save the unencrypted CSV file. I just did this and it looks pretty good so far.

What about TOTP tokens?

Re: The quiet renovation at Bitwarden

#187

Earlier quoted context omitted.

Passwords in a notebook are arguably the most secure option. The notebook exists in exactly one place, behind locked doors, and cannot be leaked or hacked externally. Notionally a password manager is more secure, but is there anything stopping Bitwarden from updating the app to silently send your master password up to the mothership and selling your unencrypted vault? Even supposing they stay open source and get caug…

How did we as an industry go from "Passwords in notebooks are insecure, use a password manager" full circle back to "Password managers are insecure, write your passwords in notebooks"?

There has always been more nuance. The notebook is basically air gapped, but since using it is painful, most will rely on shorter, simpler, passwords and reuse them. That practice is highly insecure and was even more problematic in the days before widespread 2FA on the more crucial online services. As a teen I could have had for instance blizzard get breached and collaterally lose all of my csgo skins.

Re: The quiet renovation at Bitwarden

#188
post #27

I don't care about raising prices, I'm worried about the new CEO having a PE mindset. That means Bitwarden will now focus on extracting value while the product stagnates and degrades in quality. Time to jump ship before their security and quality goes down the drain.

Give it less than one financial quarter and I guarantee the website will be about “identity for AI agents.”

Re: The quiet renovation at Bitwarden

#189
post #132
post #78

I have moved to KeepassXC[1] on my desktop from Bitwarden. On phone, I use KeepassDX[2] which is Android client compatible with KeepassXC. On browser, I use KeepassXC Browser extension which connects with the desktop client. Since KeepassXC operates on a single file, you can use any Filesystem syncing tool to sync that file between devices or to store it in the cloud. I am really happy with the move. [1]: https://kee…

KeePass is such a backwards step in usability and features that I don’t even consider it a competitor. The whole reason I moved to 1Password was to get away from how easy it was to accidentally lose data with the KeePass clients. For example, one client I used had a temporary bug that just lost the notes field entirely. It was quickly fixed but it still affected me. I’m currently using 1Password, which I still think…

[deleted]
Post reply on HN