Live data from Hacker News

Bitwarden: Free, open-source password manager

bitwarden.com

291–300 of 306 posts

Re: Bitwarden: Free, open-source password manager

#291
post #220

Earlier quoted context omitted.

FYI - Your two primary alternatives are LastPass and 1Password. The former of which is melting down due to security flaws, and the latter has raised roughly $1B in VC money: https://techcrunch.com/2022/01/19/1password-series-c-funding... At a certain point, you just have to live your life. To accept that products you use might change in the future, and you might need to migrate to something else down the road. The al…

I've found ProtonPass to be useful. Depending on how you feel about the proton ecosystem. I don't know how much VC money they've taken though.

If you look at the total financial means Proton has spent to develop and grow, >98% came from the community, making VC funding less than 2%. In fact, the total amount of VC money is actually even less than the money we have given away in various donations (you can learn more about those here: https://proton.me/blog/2022-lifetime-fundraiser-results).

Re: Bitwarden: Free, open-source password manager

#292

Earlier quoted context omitted.

Have you ever tried Psono? (I am the main developer behind it). Its open source, client side encryption, offers free versions for individuals, regular audited and and bootstrapped / no VC money. Would be happy to hear your opinion how it compares to 1password.

I just had a look if psono would be for me. One thing that I discover all too often (and that is also the case here) is that SSO (openid Salm...) is considered enterprise (sorry for calling you out here right now, this is a general frustration). If I selfhost i want to not have to manage all my services with individual logins. Selfhosting with e.g. Authentik to provide SSO and identity management is really a perfect…

SSO is the same login/password authentication flow, isn't it? Just its session is shared between services. Any password manager can handle that password-based authentication just fine.

Re: Bitwarden: Free, open-source password manager

#293
post #260

Earlier quoted context omitted.

What is the primary login method? Because I'm using SSO, and it still requires a master password.

A master password isn’t what we’re talking about though. 1Password last I used it, asked for a master, and a secret extra password. I still cannot explain why. Granted my setup was for corporate but I am pretty sure it’s the same for everyone. My best guess is that they are trying to cover for weak masters in the way that LastPass was enforcing but failing to update their PBKDF2 interations. Which IMO is stupid and a…

Something like "reenter your password to check you know what you're typing"?

Re: Bitwarden: Free, open-source password manager

#294
post #290
post #283

Earlier quoted context omitted.

You do realize that Web 1.0 and Web 2.0 aren't that far apart in time, right? Tim Berners-Lee invented the web 1.0 when he was in his thirties in 1989. Tim O'Reilly and Dale Doughterty, both in their 40s, coined the concept of Web 2.0 in 2004. Tim Berners-Lee, then in his 50s, coined the semantic or executable web aka Web 3.0 in 2006. Web 4.0 has no known origin, but the chase for artificial intelligence and machine…

> I think, sadly, you're incredibly far down the rabbit hole of ageism. That doesn't make me wrong. Is it ageism to say I'd rather have a 23 year old baseball player than a 60 year old one? What about a 23 year old model instead of a 60 year old model? Ageism? Ok. Then I'm an ageist. I'll take the 23 year olds. 'But being a model or a baseball player and working at a tech company are not the same thing' Ya, I know. B…

> That doesn't make me wrong.

Yeah, it does. Just like racism and sexism, being ageist is wrong. You should really re-asses how you look at the world, because your current view stinks.

> Is it ageism to say I'd rather have a 23 year old baseball player than a 60 year old one? What about a 23 year old model instead of a 60 year old model? Ageism? Ok. Then I'm an ageist. I'll take the 23 year olds.

There are 60 year old models, what is wrong with that? Only somebody who is ageist thinks somebody can't be model at 60. As for the baseball player, they are not discriminated by age, but by physical condition. If a 60 year old player could have the same physical impact as a 23 year old, then why not?

When it comes to the industry we're in, physical condition is not a discriminator. We are knowledge workers. Older workers tend to (not always) have much more knowledge and experience. Which is why they are paid more and end up in leadership positions (as in this case).

Your comments assume that the guy stopped learning in 1989. How do you know that he's not keeping up with the times? How do you know that he can't understand the modern world, as you imply? And do you even know what it means to be an executive? It doesn't mean knowing all the latest features of the React. It means setting a strategy (with fellow executives) for successful growth of the business. These things are as old as time (well, as old as capitalism). Having a talented CTO paired with a shrewd/experienced CEO is a good setup. It doesn't guarantee success, but it's more likely to succeed than with inexperienced executives.

Here's another way of looking at it. Replace "old" in your original sentence with "black", "woman", or "gay":

- Now it's some black Web 1.0 guy who was the CEO of eFax in the 90's.

- Now it's some Web 1.0 woman who was the CEO of eFax in the 90's.

- Now it's some gay Web 1.0 guy who was the CEO of eFax in the 90's.

How do those sentences make you feel?

Your comments are ageist and you should realise that discrimination is unacceptable. It would be wise to stop digging.

Re: Bitwarden: Free, open-source password manager

#295

Earlier quoted context omitted.

When was the last time you used it? They just had a UI change here recently and it's better than the original. It's cheaper for personal and family accounts compared to 1password. I've been a paying customer of Bitwarden for a long time now and have never experienced any of these issues. FYI, 1password has taken almost 1 billion dollars in vc investment. They have an obscene amount of pressure to grow.

Why would a password manager need $1B? Cloud password manager functionality can be accomplished in 6U of server space. Vault files are measured in kilobytes or megabytes, millions of customers could be handled by a single SSD RAID and a fast Xeon. Infrastructure and software to make it secure, reliable, and user friendly, add expense but not 9 digits of it.

Because storage, even globally replicated, isn't the core cost or the core function of a security company.

Your app, the detection of forms (when total idiots try to prevent password managers being used), the security audits, active intrusion detection, etc... those are yet to be handled by an AI, so these cost a lot.

Re: Bitwarden: Free, open-source password manager

#296

Earlier quoted context omitted.

Bitwarden has had VC investors for years, long before the mentioned 2022 funding. I think our track record to date shows how we operate in this relationship. We specifically choose partners that align with our vision, not just anyone that comes off the street wanting to throw money at us (though there are many). Our health as a company afford us this luxury. Bitwarden is and has been monetized since the beginning. Th…

Then why raise an additional $100m?

To grow faster. To be able to fund new projects that could be of higher value to people willing to pay extra.

You know, how you don't just save all of your life for a house - but get a mortgage and enjoy a house now, not in 50 years.

Re: Bitwarden: Free, open-source password manager

#298

I wanted to like Bitwarden, due to its “open source” nature. But 1Password is really miles ahead, and it's a little ironic, as 1Password 8 went through a major refactoring to a Node-enabled UI, which many people disliked, and it's still miles and miles ahead. I tried teaching my father to use Bitwarden for the sole reason that it seemed to be translated into my native tongue. In his use, Bitwarden turned out to be co…

I was on Bitwarden for a bit. I really really like the secure notes feature, it's great for storing secrets like keys that aren't used in a browser or android app. But Google is so much more convenient. I still wonder why there's no completely P2P password manager using SyncThing plus a layer of encryption. We have this near perfect tool for making multidevice apps but we don't use it for much!

I mean, you could use pass, which stores all your passwords in a gpg encrypted file. It works very well out of the box with syncthing, or anything else that can move around files, like git-annex.

https://www.passwordstore.org/

KeePassX works fairly well with syncthing as well, if I remember.

https://www.keepassx.org/

Re: Bitwarden: Free, open-source password manager

#299

I'm surprised no one's mentioned Padloc [1] yet. It's end-to-end encrypted, open source, easy to self host, and with a really UI + UX. I got all my family to use it and used it for a over a year, before eventually contributing actively to it. There's even a Tauri-based desktop app! Full disclosure: I have "contributing power" but do not make money from its sales or anything like it. [1]: https://padloc.app

Does it have WiFi sync? Seems like all the big players are committed to removing that, and that’s like the one single thing I want from a password manager: don’t store all my passwords in the cloud.

Nope. It stores the data end-to-end encrypted in the devices locally and synchronizes that to the cloud. I personally liked the wi-fi sync a long time ago with 1Password (before it was a subscription-based business), but since this is e2ee and open source, I'm fine with the cloud storage.

Re: Bitwarden: Free, open-source password manager

#300
post #286
post #195

Earlier quoted context omitted.

Hosting at data centers is expensive, hosting at home is not expensive. You probably already pay for internet, why not use it. My home server costs me about 3 euro per month in electricity (and it is quite beefy for a home server) and it runs many services, not just Vaultwarden. Add homeassistant for smart home, nextcloud for document cloud, jellyfin for media, immich for photo backups, etc. Maintenance using docker…

Do you pay yourself an SRE salary? Including all the taxes? Infrastructure costs are not just AWS / DataDog / OpenAI bills.

What is this nonsense? If you own a car and know how to drive, do you always call a taxi? And if you drive your own car, do you pay yoursef a salary for being a driver? Including all the taxes?
Post reply on HN