Live data from Hacker News

I Do Not Recommend Bitwarden

xn--gckvb8fzb.com

31–40 of 62 posts

Re: I Do Not Recommend Bitwarden

#31
post #8

Probably my biggest tech hill-i'll-die-on is: Password management involving a 3rd party is dumb and should never ever have been a thing. Before two parties had the secret (or something related to it) and now three parties have it and that's objectively worse -- even taking into account "the lazy user" or whatever. I know we're past that in a lot of places for a lot of people, but nope, my dad and his printed out shee…

>3rd party is dumb and should never ever have been a thing. Before two parties had the secret (or something related to it) and now three parties have it and that's objectively worse

There seems to be a misunderstanding of how typical cloud password vaults work. The 3rd parties like Bitwarden, 1Password, Apple iCloud Keychain, etc don't have access to the users' passwords. The scheme is based on Zero-Knowledge End-2-End-Encryption. The 3rd-party cloud is just a mechanism to store an encrypted blob and sync them to various devices. The client devices (users' desktop, users' smartphone) are the only ones that can decrypt the passwords. There are still only 2 parties with knowledge of the actual passwords.

In contrast, the type of 3rd parties that do have knowledge/access to unencrypted plain text passwords would be Amazon storing users' wi-fi passwords, and Plaid storing users' bank account credentials & passwords. Gmail and MS Outlook.com would also be a 3rd party having a copy of users' passwords when they act as web clients to fetch email from other IMAP servers.

>, my dad and his printed out sheet of password next to his desk is still beating every company out there.

That doesn't work for users when they're not sitting at their desk and need passwords. Printing out a hardcopy sheet of passwords and carrying it the wallet or purse is a massive security risk.

Re: I Do Not Recommend Bitwarden

#32
post #23

Earlier quoted context omitted.

The Bitwarden UI/X changed relatively recently so that detail view is the default click action now, rather than fill. I don't think I've ever actually used the detail view, because the edit view does the same job. Never mind that 'fill' is 100x more common as an action. So why on earth is that not the default? It is indeed an unfathomably stupid UI decision, beyond what I regularly see in other apps that I use. I sti…

There's a setting to make the old behavior default.

Yes (after user protest as I recall) but then the new UI just diverges over time, and quite possibly gets features not in the old one. I want the latest UI, and ideally the default UI, I just also want that not to be stupid.

To be clear I don't even think I'm talking about taste here, although people did complain about that. I can't think of any good reason that 'fill' is not the default action on an app/extension whose core purpose is to fill things.

Re: I Do Not Recommend Bitwarden

#33

I'm a free Bitwarden user, I don't plan to self-host stuff, and... honestly I have no idea what this person is going on about. And "Aside from the aforementioned technical details, Bitwarden is (and has always been) one of the subjectively worst applications on my phones and my desktop in terms of user interface. " Really!!? How many apps has this person used?

I love Bitwarden and use it every day, but I pretty much also agree with his post. I have Bitwarden for personal stuff and 1password for my, and the 1password experience is night and day better. It's just so good, it always works. Bitwarden sometimes (especially on Android) will just not autofill. On my PC sometimes it won't recognise the domain correctly even though I've got an entry set for "base domain" etc. I am…

And I could tell you the opposite about 1Password. About half of the time, the extension does not realize ond which domain it is and autofill is broken.

To each their own (bugs).

Re: I Do Not Recommend Bitwarden

#34

As a tangent, this site will overwrite its and favicon if your browser changes tab to one of many random options, as well as showing an overlay highlighting the risk of keeping javascript enabled for once you're back. I dug around and found them listed within the `kill.js` file[0]. It uses the visibilitychange[1] API and swaps it to one of the following: Official Church of Scientology: Difficulties on the Job - Onlin…

I giggled but it’s dangerous as a prank (say if you were on that site during a break, then shared a screenshot of a design from your browser)

Re: I Do Not Recommend Bitwarden

#35

I'm a free Bitwarden user, I don't plan to self-host stuff, and... honestly I have no idea what this person is going on about. And "Aside from the aforementioned technical details, Bitwarden is (and has always been) one of the subjectively worst applications on my phones and my desktop in terms of user interface. " Really!!? How many apps has this person used?

I love Bitwarden and use it every day, but I pretty much also agree with his post. I have Bitwarden for personal stuff and 1password for my, and the 1password experience is night and day better. It's just so good, it always works. Bitwarden sometimes (especially on Android) will just not autofill. On my PC sometimes it won't recognise the domain correctly even though I've got an entry set for "base domain" etc. I am…

[dead]

Re: I Do Not Recommend Bitwarden

#36
post #19

Bitwarden have in my opinion is one of the BEST business models a user can ask for. It's open-source, and I can self-host (100% free) and the free version is really, really good too, and then a premium version is $20/year which is very reasonably priced. Also for cloud hosted password manager, you're always going to have attacks no matter what, but at least they are transparent about it .. (unlike say LastPass, Norto…

As a now almost 15 year long user (crazy to think about) of 1password I am unsure what attacks do you mean? Did passwords get lost and it was not disclosed or what did you mean by the lack of transparency?

Re: I Do Not Recommend Bitwarden

#37
post #19

Bitwarden have in my opinion is one of the BEST business models a user can ask for. It's open-source, and I can self-host (100% free) and the free version is really, really good too, and then a premium version is $20/year which is very reasonably priced. Also for cloud hosted password manager, you're always going to have attacks no matter what, but at least they are transparent about it .. (unlike say LastPass, Norto…

I also don't really expect the self-hosted version to be a small self-contained go binary or something, they have millions of users their tech stack is going to be more complicated necessarily. But then vaultwarden exists too and is well maintained but is then somehow also inadequate. Who could possibly live up these unreasonable standards?

Re: I Do Not Recommend Bitwarden

#38

As a tangent, this site will overwrite its and favicon if your browser changes tab to one of many random options, as well as showing an overlay highlighting the risk of keeping javascript enabled for once you're back. I dug around and found them listed within the `kill.js` file[0]. It uses the visibilitychange[1] API and swaps it to one of the following: Official Church of Scientology: Difficulties on the Job - Onlin…

I giggled but it’s dangerous as a prank (say if you were on that site during a break, then shared a screenshot of a design from your browser)

[deleted]

Re: I Do Not Recommend Bitwarden

#40

As a tangent, this site will overwrite its and favicon if your browser changes tab to one of many random options, as well as showing an overlay highlighting the risk of keeping javascript enabled for once you're back. I dug around and found them listed within the `kill.js` file[0]. It uses the visibilitychange[1] API and swaps it to one of the following: Official Church of Scientology: Difficulties on the Job - Onlin…

This is absolutely hilarious, and I am totally using this trick when I get to making my own porn video hosting platform (which I won't).
Post reply on HN