Live data from Hacker News

The quiet renovation at Bitwarden

blog.ppb1701.com

261–270 of 333 posts

Re: The quiet renovation at Bitwarden

#261
post #67

Earlier quoted context omitted.

I'm getting really tired of the enshittification cycle. Learning about android verification and captcha changes recently has been another big frustration point. I moved to android as a more open alternative to apple just a few years ago, and to bitwarden from lastpass around the same time. I would like to just have these infrastructural services work well and quietly without thinking about them for many years. Do I r…

Bitwarden hasn’t “enshittified” anything. It’s all entirely speculative

PE's entire modus operandi is enshittification. If there's no enshittification to be done there would be no point in purchasing the company

Re: The quiet renovation at Bitwarden

#262
post #216

Earlier quoted context omitted.

I’ve used Vaultwarden for at lesst 7 years, I’m sure for longer but I’m not sure how long. Never had an issue with Vaultwarden itself. Restored from backups several times for a variety of reasons (migrating host, corrupt hard disk, re-installs) and that always worked first try. In regards to hardering, the wiki has a good guide: https://github.com/dani-garcia/vaultwarden/wiki/Hardening-Gu... .

That guide is wild. By default it allows public registration, shows password hints, requires a reverse proxy for robust TLS but then passes tokens via GET params, runs in the container as root. Recommends fail2ban because it doesn't have any coverage against brute force. Recommends using a custom path for security. This feels less like a guide on hardening Vaultwarden than a guide on why I should be skeptical about i…

Requiring a reverse proxy for TLS is pretty standard, but the rest of those findings are egregious (if they haven't been addressed yet.)

Re: The quiet renovation at Bitwarden

#263
post #219

Earlier quoted context omitted.

> Anything I'm overlooking here? Not technical, but the person behind that project now works for Bitwarden so there's some risk of a rugpull. Of course it's OSS but you'll need to trust a fork or maintain it yourself if said rugpull happens.

The expansion of "rugpull" to encompass "a company or open source developer changing the roadmap or level of investment in something they develop" is fascinating.

I think that term refers more to the conflict of interest that now exists.

Re: The quiet renovation at Bitwarden

#264
post #27

I don't care about raising prices, I'm worried about the new CEO having a PE mindset. That means Bitwarden will now focus on extracting value while the product stagnates and degrades in quality. Time to jump ship before their security and quality goes down the drain.

I'm so fucking tired of jumping ship with these password vault providers. This will be my third jump in so many years.

Exactly what value do they think they have left to extract from me? I'm a paying customer for a product that essentially just stores an indexed list of strings with at-rest encryption.

Their official App's autofill on my phone hasn't worked for several months now., I literally have to login to it once every couple hours just to manually copy and paste my usernames and passwords separately. I guess enshitification knows no bounds?

Re: The quiet renovation at Bitwarden

#265
post #174

Earlier quoted context omitted.

It's very simple, just don't make it accessible outside your home network. Clients sync when the server is accessible and use last synced data otherwise.

The effort required to set this up far outweighs the price to pay someone to do it for me. I pay a cleaner, I have a dishwasher, I pay someone to do my taxes, I pay for companies to host software. Then again, I never order food and almost never get takeaway, as cooking is nice and I value my food enough to care what goes in it. Cheaper too, easily offsetting what I pay for my password manager.

Tailscale for your laptop, phone, etc. to be able to talk to the other computers when away from your home WiFi. (Optional, but makes syncing easier).

Syncthing, talking to your Tailscale IP addresses if you use it, or your private WiFi network addresses if you don't use Tailscale.

One folder synced, containing keyfile2.kdbx.

30 minutes to set up and then you almost never need to think about it again. If you don't trust Tailscale, you can run a Headscale server or just not use it. And the syncing is entirely run on your machines; your data never ends up written to someone else's SSD.

It's really not much effort.

Re: The quiet renovation at Bitwarden

#266

Earlier quoted context omitted.

It's an extremely common phrase in the US, along with "Is the Pope Catholic?" Sometimes the two phrases are humorously mixed together.

I've never heard it mixed (not from US)... "Is bear a Catholic?" doesn't seem very funny. But a notion that everyone knows how Pope is regularly shitting in the woods absolutely is :)

We say "are bears Catholic?" when in more polite company and we can't get away with asking if the Pope shits in the woods :)

Re: The quiet renovation at Bitwarden

#267
post #216

Earlier quoted context omitted.

I’ve used Vaultwarden for at lesst 7 years, I’m sure for longer but I’m not sure how long. Never had an issue with Vaultwarden itself. Restored from backups several times for a variety of reasons (migrating host, corrupt hard disk, re-installs) and that always worked first try. In regards to hardering, the wiki has a good guide: https://github.com/dani-garcia/vaultwarden/wiki/Hardening-Gu... .

That guide is wild. By default it allows public registration, shows password hints, requires a reverse proxy for robust TLS but then passes tokens via GET params, runs in the container as root. Recommends fail2ban because it doesn't have any coverage against brute force. Recommends using a custom path for security. This feels less like a guide on hardening Vaultwarden than a guide on why I should be skeptical about i…

Those problems are endemic to all web apps.

e.g. You can’t just provide software to people that obtains TLS certs on their behalf: you have no idea how their infra is setup.

Hosting any app on your own infra is a serious skill set.

Re: The quiet renovation at Bitwarden

#268
post #205

At this point it is too high of a risk to store my password elsewhere. I've been screwed over by dashlane, lastpass, potentially bitwarden now, I am with 1password now, but I've had my passwords in all these places, and I've had to change them each time, probably missing a few. I like 1password, it is by far the highest quality product I've used in this category. I moved from BitWarden back then because their browser…

Serious questions: what's wrong with just using Firefox built in password manager?

Re: The quiet renovation at Bitwarden

#269
post #27

I don't care about raising prices, I'm worried about the new CEO having a PE mindset. That means Bitwarden will now focus on extracting value while the product stagnates and degrades in quality. Time to jump ship before their security and quality goes down the drain.

Not my project but Vaultwarden is an open source (in Rust) alternative backend for Bitwarden. I believe its been around a while, and is still maintained. https://github.com/dani-garcia/vaultwarden

No matter where Bitwarden ends up, passwords are one of these few things I am very hesitant to self-host. The stakes are just too high, and my knowledge of security has too many unknown unknowns to take that risk.

Re: The quiet renovation at Bitwarden

#270
post #67

Earlier quoted context omitted.

I'm getting really tired of the enshittification cycle. Learning about android verification and captcha changes recently has been another big frustration point. I moved to android as a more open alternative to apple just a few years ago, and to bitwarden from lastpass around the same time. I would like to just have these infrastructural services work well and quietly without thinking about them for many years. Do I r…

Bitwarden hasn’t “enshittified” anything. It’s all entirely speculative

Red flags are always speculative.

The point is that if there are only one or two red flags, you can risk assess them and continue as is if the risk is low. But if there are a large number of red flags, then you need to consider your exit strategy as well.

Post reply on HN