Live data from Hacker News

The quiet renovation at Bitwarden

blog.ppb1701.com

281–290 of 333 posts

Re: The quiet renovation at Bitwarden

#281
post #100

Earlier quoted context omitted.

It's almost certainly ai written though. All the regular tells are there... Though he likely edited some out, like that "just" Also if it was handwritten, it'd have been a third in length, the rest was LLM fluff

Correct, that was my point

I see, i actually like these tells. It let's us easily distinguish garbage from someones thoughts.

And you can also see how brainrotten someone's gotten when they start accidentally sneaking in these tells into their normal communication.

As a matter of fact, after a full workday in which I'm essentially forced to read LLM garbage for 9h a day... I sadly notice myself adding the same fluff pointlessness to how I express myself. like I caught a viral contagion that's actively siphoning my humanity away.

And expectedly, when coming back to those opinions with a less infected mindset, I frequently have to reevaluate these thoughts later on

Re: The quiet renovation at Bitwarden

#282

> That’s not a software guy who happened to raise some money. That’s someone whose stated specialty is the PE integration and exit process. Holy smokes has that's not just -> THAT IS become one of my trigger words.

Do we need to keep pointing this out though? LLMs are not going anywhere any time soon and people will keep using them to generate articles. If the content is also nonsense then that's worth talking about, but otherwise comments about LLM style are about as interesting as remarks about typos.

Yes we do, continue keeping it a faux pas to reduce the over verbose LLM speak put elsewhere and ask people to just share the original prompt and save us all time. Label your LLM usage to respect other people's time.

Re: The quiet renovation at Bitwarden

#283
post #32

After the LastPass fiasco I switched to selfhosting a password manager (bw). Rapidly starting to think even a vibecoded solution may be a better plan relying on commercial options. High risk of don’t roll your own crypto mistakes but realistically that’s not the threat model here anymore for the random individual. It’s online breaches or perhaps a wrench attack not highly skilled crypto adversary. Plus there are prob…

Yeah, I'm thinking the same thing - wondering if security-by-obscurity may compensate for some lack of quality.

Re: The quiet renovation at Bitwarden

#284

Earlier quoted context omitted.

1Password for Business accounts all get an additional 1Password for Families license (5 seats), so you can absolutely keep your work and personal life separate.

What happens when you leave that business account? (e.g. change jobs, leave the company, get acquired and consolidate etc)

You keep your personal account, but it goes into either a read-only or trial mode until you subscribe or connect another free account source. You can export everything out if you want to switch to a different tool.

Re: The quiet renovation at Bitwarden

#285
post #12

Thank you for this post/link. I have been side eyeing Bitwarden since they started ensh*ttifying the desktop UX last year to make it more like everything else and take up too much space. It had been working perfectly well for browser autofill - super fast and staying out of the way. Now it is bloated white space, slow, standardized UX elements like any SaaS built by AI. Will check out Vaultwarden, Proton Pass, Keepas…

As mentioned, enshittifying doesn't mean "make shitty" or "make worse". It's a specific exploitative company MO, like taking a product like Bitwarden and the goodwill it's generated with open source contributions, free plans, etc., and exploiting that trust by selling it to private equity, unbeknownst to the users, in order to squeeze the most out of it they can and then scrap it.

I agree with you that "enshittification" has a more specific meaning than just "make worse". Yet, the enshittification of Windows doesn't really follow the mold you described, even though I'd also call it enshittification.

Re: The quiet renovation at Bitwarden

#286
post #112

I got my parents using bitwarden a few years ago. This was a massive improvement over them writing passwords in a little notebook in a drawer (yes, really!). But Keepass is a bridge too far for them. I'm not that enthusiastic about it myself to be honest. The UX is a bit meh (for the clients/extensions I've tried) and file syncing and handling is not something I can in good conscience push to a non technical user. It…

KeepassXC is much better than older keepass clients. Syncthing runs quietly in the background. It's really not much harder to use that other password managers once you set it up

Syncthing is pretty much a non starter in it's current form. I use it myself. But it's one of those things that is too hard to figure out for normal users. And with the discontinued/half-assed support for mobile, it's just not great.

Too bad, because it's one of those things that could be great but just isn't in its current form.

Re: The quiet renovation at Bitwarden

#287
There is one underrated feature that I switched to Bitwarden for, away from KeePass: the emergency contact access. You can designate contacts that can request access to your account. If you don't deny the request within a time frame, they are granted access.

So much of our lives is now digital. Important accounts of all kinds, banking, etc.

Waiting on several giant corps to grant your loved ones access after they go through the bureaucratic hole of documentation is... rough.

Putting my master password in my will feels the same as just writing it on a note on my desk. Putting it in a note in a safety deposit box is high effort and cost.

Anyone got a better alternative way to set this up if self-hosting and not going with Vaultwarden?

Re: The quiet renovation at Bitwarden

#288

Earlier quoted context omitted.

I use syncthing-fork from fdroid, works great

same. Recommend as long as the house doesn't catch fire, or as long i run outside with 1 of my syncthing devices (have several), local cloud is the best.

Can I ask questions about your setup? I don't intend to grill you on it or pick it apart - I would like to go down this route further, but find myself gradually moving away from it. I switched from Keepass to Bitwarden in 2020, knowing it was just a move towards convenience.

I suppose you realised you could protect against the scenario where you run outside without any devices, by just having a copy of the encrypted data sent to some cloud service, e.g. iCloud/OneDrive/Google Drive, but decided you couldn't trust any?

I know everyone's threat models are different, but I'm still curious to know your thoughts. There's no one you would trust with an encrypted copy?

Do you have any automated backup of your phone to a cloud service, or only local? If a cloud service, do you make sure it excludes your password manager? If no cloud backup, then do you make sure you have a copy of your data outside the house?

I have incomplete thoughts about the robustness of my password/OTP code backups. It is the 2-factor codes, which one day in the distant future, when I am overseas holding a new replacement for a lost phone, looking at the text "Enter the 6‑digit verification code", I will wish I'd thought about more carefully.

Re: The quiet renovation at Bitwarden

#289
post #268
post #205

At this point it is too high of a risk to store my password elsewhere. I've been screwed over by dashlane, lastpass, potentially bitwarden now, I am with 1password now, but I've had my passwords in all these places, and I've had to change them each time, probably missing a few. I like 1password, it is by far the highest quality product I've used in this category. I moved from BitWarden back then because their browser…

Serious questions: what's wrong with just using Firefox built in password manager?

It is limited to ... well ... Firefox! Sometimes you need passwords elsewhere. Besides that Firefox (or other browser password managers) doesn't support more advanced use cases like shared vaults.

Re: The quiet renovation at Bitwarden

#290
post #268
post #205

At this point it is too high of a risk to store my password elsewhere. I've been screwed over by dashlane, lastpass, potentially bitwarden now, I am with 1password now, but I've had my passwords in all these places, and I've had to change them each time, probably missing a few. I like 1password, it is by far the highest quality product I've used in this category. I moved from BitWarden back then because their browser…

Serious questions: what's wrong with just using Firefox built in password manager?

If you only need to manage online passwords, only use Firefox, and aren't using an iOS device, then it's probably fine. But most people may also need to use native apps, other browsers, and iOS devices.
Post reply on HN