Live data from Hacker News

Concerns raised over Bitwarden moving further away from open source

phoronix.com

31–40 of 61 posts

Re: Concerns raised over Bitwarden moving further away from open source

#31
post #21

I'm paying for BitWarden because I want to support them. But it's pretty clear that they're backsliding. This is understandable, the password manager market is saturated and implementing new features like Passkeys is far from trivial. Still, they are the only real option for a one-click mostly open source password manager that works across all the major platforms and that supports modern features.

Isn't passkey support already in? I am using that in day-to-day basis. Bugs exists, but it is not that far.

Re: Concerns raised over Bitwarden moving further away from open source

#32
I was concerned about BitWarden when it started copying or acting like 1Password. Their marketing text, features, etc., are similar. I understand there isn’t much to differentiate between Password Management tools. BitWarden was supposed to be the Open-Source alternative to 1Password and better than Keepass.

I’m a customer of both services. I started with 1Password since its early days and have been using the family plan for the past 5+ years.

I used BitWarden when starting with Teams, as it is cheaper and presumably scalable. I hope that if things grow up, we can either host it ourselves or the pricing is affordable enough.

If Bitwarden becomes as “successful” as 1Password, people/companies will actually just use 1Password.

I think, now, the idea would be to start moving all critical ones to Keepass; and use a better UX client on top of the database.

Re: Concerns raised over Bitwarden moving further away from open source

#33
post #9

Earlier quoted context omitted.

Yes, via the KeePassium client: https://github.com/keepassium/KeePassium As with all iOS apps, there’s no guarantee that the open source app code on GitHub corresponds to what you install from the App Store. I have been very satisfied with KeePassium, it integrates with all the cloud storage providers I’d want and the app itself works well.

Notably though, Keepassium from the App Store is licensed differently than the version on GitHub. Only the Keepassium team can ever actually submit to the App Store as GPL software is banned, and so they do not accept contributions so that they have the ability to submit under a proprietary license.

GPL software isn't banned. Is this just your speculation?

Re: Concerns raised over Bitwarden moving further away from open source

#34
post #16

Earlier quoted context omitted.

KeepassXC. https://keepassxc.org/ Recently switched over from a premium Bitwarden account to it. Import from Bitwarden was a breeze. Note that KeepassXC only writes to a local encrypted db file. Syncing that across devices is left to you. I used Syncthing for that.

No support for passkeys, either.

I wouldn't trust passkey myself [0] [0]: https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shatt...

Re: Concerns raised over Bitwarden moving further away from open source

#35

I never understood the appeal of web-based password managers. KeePass all the way, all offline, no randomly changing UI, everything in a single .db file. Need syncing? Use Cloud storage service.

> Use Cloud storage service.

It works until you have conflict edits on different device and need merging.

Re: Concerns raised over Bitwarden moving further away from open source

#36

I never understood the appeal of web-based password managers. KeePass all the way, all offline, no randomly changing UI, everything in a single .db file. Need syncing? Use Cloud storage service.

Agreed. Too many places where things can go wrong.

Re: Concerns raised over Bitwarden moving further away from open source

#37

I never understood the appeal of web-based password managers. KeePass all the way, all offline, no randomly changing UI, everything in a single .db file. Need syncing? Use Cloud storage service.

You can do the same with Bitwarden by having the vault in your local computer.

Re: Concerns raised over Bitwarden moving further away from open source

#38
post #35

I never understood the appeal of web-based password managers. KeePass all the way, all offline, no randomly changing UI, everything in a single .db file. Need syncing? Use Cloud storage service.

> Use Cloud storage service. It works until you have conflict edits on different device and need merging.

I stick to adding entries on my desktop and distributing copies to my clients. Its better for me to limit syncing between devices.

Re: Concerns raised over Bitwarden moving further away from open source

#39

Earlier quoted context omitted.

KeepassXC. https://keepassxc.org/ Recently switched over from a premium Bitwarden account to it. Import from Bitwarden was a breeze. Note that KeepassXC only writes to a local encrypted db file. Syncing that across devices is left to you. I used Syncthing for that.

I think the thing we need to learn about security is that usability matters. I think this is easy for pretty much anyone that's an active HN user, but is it for your parents or grandparents? It's they who matter a lot. It's why WhatsApp was so successful, it passed the Grandma check. Signal might, but onboarding is "hard" (and the nerds argue and that's all others hear and then do what... Use telegram? Lol). But it's…

This is fair, though in my answer, I wasn't answering the question from the perspective of applicability for a general audience.

For a general audience, even Bitwarden doesn't pass the "grandma check". If you've used Bitwarden for a while you have probably been met with a stern warning about "KDF Iterations too low".

So I pitched the answer assuming "able to use Bitwarden" as a base level of tech savvy.

Also, seeing as I am on HN, I assumed the following:

1. Security matters, even if it comes at a slight cost in convenience

2. User can figure out their own syncing mechanism

Post reply on HN