Live data from Hacker News

Evaluation of five password managers

medium.com

201–210 of 216 posts

Re: Evaluation of five password managers

#201

Hi folks, That's a thorough comparison. I just wanted to make an attempt on why someone should consider using Zoho Vault for password management. Zoho Vault is an online password manager for teams, used by more than 20,000 small and medium sized companies across the globe. We offer client-side encryption, multi-platform support, auto-fill, auto login websites and cloud apps, fine-grained password sharing, bulk folder…

I've added Zoho Vault to the comparison grid.

Re: Evaluation of five password managers

#202
post #52

In the end I've just been using the Unix pass password manager [1]. It's just cobbling together of GPG and git with shell scripts but it works like a normal git repository so you get all your synchronization, from that, your security from GPG which are all things I know and trust without introducing other components that I don't know / understand. [1] https://www.passwordstore.org/

I've been using a similar one: https://github.com/gopasspw/gopass. Only problem is getting non-technical people to use it is hard. And it is not super intuitive to get it working on mobile.

Re: Evaluation of five password managers

#203
post #184

Earlier quoted context omitted.

U2f support is badly hampered by half-assed browser support. Only chrome enables it by default, Firefox disables it by default, and no love from safari. Even LastPass in the browser uses yubico’s proprietary otp algorithm rather than u2f.

U2F support in Firefox should work out of the box if the developers use the WebAuthn API and not the old JS library: https://hacks.mozilla.org/2018/01/using-hardware-token-based...

That was not my experience on google and github.

Re: Evaluation of five password managers

#204
post #116

Earlier quoted context omitted.

I recently starting using Firefox again, and getting my passwords out of Chrome was by far the most difficult part of the process for me. A few things I learned: Chrome has a feature to export passwords to a CSV file, but I had to enable it via a chrome:flag, so who knows if/when support for this will disappear. This created a bit of a sense of urgency for me, as Google aggressively removes features that they don't w…

Does firefox not import passwords from chrome as part of the profile import? It's... certainly supposed to. EDIT: Oh, you probably didn't mean getting them out and into firefox, you probably wanted to use something different to avoid the same issue (but with firefox) if you switch browsers again in the future.

Actually, at the time, I would've been perfectly happy to have just imported the passwords into Firefox!

But I don't think it is able to import them, at least not on my machine. I'm using the latest Chromium/Firefox on the latest Ubuntu, and I just had another look. When I select the option to import data from another browser, I get a dialog that says:

Import Preferences, Bookmarks, History, Passwords and other data from: Chromium

When I select Chromium, I see a list of things I can import:

Select which items to import: [x] Cookies [x] Browsing History

For some reason, "Passwords" does not appear in the list, and when I browse to a site in Firefox, it doesn't use the password that Chromium had stored.

Maybe this is an OS-dependent thing?

Re: Evaluation of five password managers

#205
post #184

Earlier quoted context omitted.

U2F support in Firefox should work out of the box if the developers use the WebAuthn API and not the old JS library: https://hacks.mozilla.org/2018/01/using-hardware-token-based...

That was not my experience on google and github.

Google and Github both built their U2F support for Firefox before WebAuthn was released, and as you've pointed out, the U2F support in Firefox is gated out by default. Presumably Google, Github, and other companies that coded to U2F will migrate to WebAuthn eventually.

Re: Evaluation of five password managers

#206
post #176
post #85

Glad to see Bitwarden up on top. They tick all the boxes for me - open source, transparent security (including recently published audit), feature-rich, optional self-hosted, and easy to use.

Except there isn't much info on who 8 bit solutions is. It seems like a 1 man effort and apparently he doesn't want to reveal much. A few requests aren't exactly answered. https://github.com/bitwarden/website/issues/12 https://community.bitwarden.com/t/who-is-hosting-bitwarden/1...

This is informative: https://opensource.com/article/18/3/behind-scenes-bitwarden

My impression is that Kyle cares more about spending time writing software than about hyping his company. ;-)

It's an unfortunate flaw in a founder, but not a fatal one if he hires people to do the communication that he doesn't want to be doing. It feels to me like he's moving in that direction.

Re: Evaluation of five password managers

#207
post #196
post #119

Earlier quoted context omitted.

More bugs and the support was horrible. I moved my entire company from LP to 1Password. I'm impressed with the quality of 1Password. They get huge props from me for telling me, in the upgrade dialog, what the changes are, before I agree to upgrade.

>More bugs and the support was horrible. ^^^Yes, this. In 2018, we reported nine different substantive security holes to LastPass. At least two of them were security issues. All of them took far too long to fix; some of them still aren't fixed. There's a tenth bug which impacts many of our users on a regular basis which we haven't bothered to report to them because by the time we started running into it, our users we…

I don't have access to my account anymore, but once I scrolled through my tickets, that I had created over the years. There were like 50 of them. Hardly any of those I felt good about after they were closed.

I've had maybe 2-3 with 1Password, and all but one was resolved quickly and satisfactorily. The one that wasn't: them telling my Basic Authentication dialogs would not be supported any longer. (The same response from LP, just before I quit them.) I can't really hate on either for this, since BA seems to be quite insecurely done and changes all the freaking time in Chrome (it broke regularly when LP supported it, due to Chrome changes).

Re: Evaluation of five password managers

#208
post #206
post #176

Earlier quoted context omitted.

Except there isn't much info on who 8 bit solutions is. It seems like a 1 man effort and apparently he doesn't want to reveal much. A few requests aren't exactly answered. https://github.com/bitwarden/website/issues/12 https://community.bitwarden.com/t/who-is-hosting-bitwarden/1...

This is informative: https://opensource.com/article/18/3/behind-scenes-bitwarden My impression is that Kyle cares more about spending time writing software than about hyping his company. ;-) It's an unfortunate flaw in a founder, but not a fatal one if he hires people to do the communication that he doesn't want to be doing. It feels to me like he's moving in that direction.

It's not about hyping.

Just a general "About" page of where it's located, who's behind and a photo of CEO with added bonus if there's a photo of their office.

It's a very security oriented product. Not showing who they're can be taken as hiding.

Re: Evaluation of five password managers

#209
post #208
post #206

Earlier quoted context omitted.

This is informative: https://opensource.com/article/18/3/behind-scenes-bitwarden My impression is that Kyle cares more about spending time writing software than about hyping his company. ;-) It's an unfortunate flaw in a founder, but not a fatal one if he hires people to do the communication that he doesn't want to be doing. It feels to me like he's moving in that direction.

It's not about hyping. Just a general "About" page of where it's located, who's behind and a photo of CEO with added bonus if there's a photo of their office. It's a very security oriented product. Not showing who they're can be taken as hiding.

In this day in age it is common for a two-year-old SaaS startup not to have an office. I mean, I suppose it's possible that they have one, but my assumption is that the entire company is remote.

I don't see why their location is particularly important, but if you care, you can look on Kyle's LinkedIn profile, which I was able to browse my way to in about 45 seconds from a standing start from their web site.

The article I just linked to makes it perfectly clear "who's behind" Bitwarden, and you can find it out easily with a few seconds of Googling like what I just did. They're not trying to hide anything from anyone who cares to spend 30 seconds trying to find out.

I care a lot more about the fact that hundreds of vulnerabilities have been submitted to LastPass's bug bounty program and they haven't chosen to disclose any of them, whereas a much smaller number have been submitted to Bitwarden's program and they've disclosed several. P.S. I, personally have reported three different security issues to LastPass, none of which have been fixed (https://medium.com/@QuantopianCyber/hi-george-a16d88a37355).

It's clear to me that LogMeIn, which owns LastPass and has a big-deal, flashy "About" page, is much less security-focused than Bitwarden. What you're asking for feels more like security theater than anything that's actually relevant to security.

Re: Evaluation of five password managers

#210

Just idle curiosity, but I'd be curious to see BitWarden's commit on GitHub: > ...at one point during our evaluation we submitted a bug report about Bitwarden through its Github project; one of the product’s maintainers committed a bug fix seventeen minutes later , and just a few days after that the fix was released to the public.

That tells me that their testing is either extremely excellent , or extremely nonexistent. Rumors seem to point towards the latter, which is concerning for security software.

For enterprise software, a couple days is indeed strange. For OSS, it's standard in good communities I'd say. When I filed bug fixes against Tomcat, I often had fix within that day (though it was released only during the typical release schedule of Tomcat)
Post reply on HN