Live data from Hacker News

The quiet renovation at Bitwarden

blog.ppb1701.com

201–210 of 333 posts

Re: The quiet renovation at Bitwarden

#201

Say what you will, but the Apple ecosystem's Passwords app and integration works great. It locks me into their services (iCloud), but I don't see them ever charging for it or sunsetting it. (watch me eat my words in the near future)

Password App surely is a good alternative, however i don’t think there are clients for Linux or Windows? …and that is where Bit/Vaultwarden comes into play.

That's correct; I only use MacOS and iOS.

Re: The quiet renovation at Bitwarden

#202
post #172

Earlier quoted context omitted.

> how do you harden it? By not exposing it to the wider internet. When I use a client (iPhone, browser, etc.) while on the home network, it syncs. While off the network, the last synced data is still there. That's been good enough for me.

When the server can’t be accessed, you can’t create a secret, right? This has been quite annoying in my experience. I’d still recommend Bitwarden clients with self-hosted Vaultwarden.

Mobile wireguard clients are very good as a solution to the access problem.

Re: The quiet renovation at Bitwarden

#203
post #12

Thank you for this post/link. I have been side eyeing Bitwarden since they started ensh*ttifying the desktop UX last year to make it more like everything else and take up too much space. It had been working perfectly well for browser autofill - super fast and staying out of the way. Now it is bloated white space, slow, standardized UX elements like any SaaS built by AI. Will check out Vaultwarden, Proton Pass, Keepas…

As mentioned, enshittifying doesn't mean "make shitty" or "make worse". It's a specific exploitative company MO, like taking a product like Bitwarden and the goodwill it's generated with open source contributions, free plans, etc., and exploiting that trust by selling it to private equity, unbeknownst to the users, in order to squeeze the most out of it they can and then scrap it.

Re: The quiet renovation at Bitwarden

#204

> That’s not a software guy who happened to raise some money. That’s someone whose stated specialty is the PE integration and exit process. Holy smokes has that's not just -> THAT IS become one of my trigger words.

Do we need to keep pointing this out though? LLMs are not going anywhere any time soon and people will keep using them to generate articles.

If the content is also nonsense then that's worth talking about, but otherwise comments about LLM style are about as interesting as remarks about typos.

Re: The quiet renovation at Bitwarden

#205
At this point it is too high of a risk to store my password elsewhere. I've been screwed over by dashlane, lastpass, potentially bitwarden now, I am with 1password now, but I've had my passwords in all these places, and I've had to change them each time, probably missing a few.

I like 1password, it is by far the highest quality product I've used in this category. I moved from BitWarden back then because their browser integration was quite poor.

I think I'll move to something custom, or a selfhosted keepass server, with the rugpulls, incidents, and whatnot, it is becoming too high of a risk.

Re: The quiet renovation at Bitwarden

#206
post #205

At this point it is too high of a risk to store my password elsewhere. I've been screwed over by dashlane, lastpass, potentially bitwarden now, I am with 1password now, but I've had my passwords in all these places, and I've had to change them each time, probably missing a few. I like 1password, it is by far the highest quality product I've used in this category. I moved from BitWarden back then because their browser…

How were you screwed over by these products?

Re: The quiet renovation at Bitwarden

#207
post #27

I don't care about raising prices, I'm worried about the new CEO having a PE mindset. That means Bitwarden will now focus on extracting value while the product stagnates and degrades in quality. Time to jump ship before their security and quality goes down the drain.

Not my project but Vaultwarden is an open source (in Rust) alternative backend for Bitwarden. I believe its been around a while, and is still maintained. https://github.com/dani-garcia/vaultwarden

It is still maintained, but I believe the maintainer is employed by Bitwarden now, and is working on projects in addition to Vaultwarden.

Re: The quiet renovation at Bitwarden

#208
post #206
post #205

At this point it is too high of a risk to store my password elsewhere. I've been screwed over by dashlane, lastpass, potentially bitwarden now, I am with 1password now, but I've had my passwords in all these places, and I've had to change them each time, probably missing a few. I like 1password, it is by far the highest quality product I've used in this category. I moved from BitWarden back then because their browser…

How were you screwed over by these products?

Rug-pulls, security incidents, lost passwords, I also don't know if they've kept my passwords behind when i deleted my accounts. The risk of them having them is too high, so i had to swap all of them.

Re: The quiet renovation at Bitwarden

#209
post #205

At this point it is too high of a risk to store my password elsewhere. I've been screwed over by dashlane, lastpass, potentially bitwarden now, I am with 1password now, but I've had my passwords in all these places, and I've had to change them each time, probably missing a few. I like 1password, it is by far the highest quality product I've used in this category. I moved from BitWarden back then because their browser…

keepass files + syncthing works very nicely for me.

For non technical people, I just recommend to use the browser built in password managers. traviso has a good writeup why: https://lock.cmpxchg8b.com/passmgrs.html

Re: The quiet renovation at Bitwarden

#210
post #174
post #156

Earlier quoted context omitted.

I’m not buying hosting from a password manager, I’m buying security. I don’t have complete confidence that I can secure a self-hosted password manager and it’s not an area where I want to take risks.

It's very simple, just don't make it accessible outside your home network. Clients sync when the server is accessible and use last synced data otherwise.

The effort required to set this up far outweighs the price to pay someone to do it for me.

I pay a cleaner, I have a dishwasher, I pay someone to do my taxes, I pay for companies to host software.

Then again, I never order food and almost never get takeaway, as cooking is nice and I value my food enough to care what goes in it. Cheaper too, easily offsetting what I pay for my password manager.

Post reply on HN