Live data from Hacker News

Bitwarden Completes Third-Party Security Audit

blog.bitwarden.com

41–50 of 148 posts

Re: Bitwarden Completes Third-Party Security Audit

#41

Can I get a quick vote on keepass2 vs bitwarden, and a feature comparison?

The fact that I can't easily use a Yubikey for 2FA with KeePass has always made it a nonstarter for me. After experiencing the comfort and peace of mind I get with "master password PLUS Yubikey" in Bitwarden and LastPass, I could never go back to just having a master password that could be keylogged.

Yes, you can have a static "keyfile" on a USB stick that you use for 2FA, but that could be easily copied. "But if they have physical access it's already game over!" The scenario I am concerned about is unlocking my master database on a computer I don't own, like at work. I can do that with Bitwarden.

Re: Bitwarden Completes Third-Party Security Audit

#42

Can I get a quick vote on keepass2 vs bitwarden, and a feature comparison?

The fact that I can't easily use a Yubikey for 2FA with KeePass has always made it a nonstarter for me. After experiencing the comfort and peace of mind I get with "master password PLUS Yubikey" in Bitwarden and LastPass, I could never go back to just having a master password that could be keylogged. Yes, you can have a static "keyfile" on a USB stick that you use for 2FA, but that could be easily copied. "But if the…

Doesn't KeepassXC support 2FA?

Re: Bitwarden Completes Third-Party Security Audit

#43

We used LastPass for several years in our home, mostly because it was able to fill Firefox http basic auth dialogs. When Firefox switched to the webextension format, LastPass started using the Chrome version as the foundation for Firefox. This was a huge step backwards and my wife HATED it. The biggest problem she had was that it was that the standard workflow of it capturing generated passwords became unreliable and…

Yes, I use KeePass and Kee for Firefox. Before WebExtensions it was perfect. Now, it has a dialog that tries to intercept basic/negotiate auth, but it never works.

Luckily, keepass has a very nice auto-type functionality that works perfectly with basic auth dialogs. Now if I could just disable the Kee dialog that doesn't actually do anything...

Re: Bitwarden Completes Third-Party Security Audit

#44

We used LastPass for several years in our home, mostly because it was able to fill Firefox http basic auth dialogs. When Firefox switched to the webextension format, LastPass started using the Chrome version as the foundation for Firefox. This was a huge step backwards and my wife HATED it. The biggest problem she had was that it was that the standard workflow of it capturing generated passwords became unreliable and…

Very similar for me but with 1Password instead of LastPass.

My only complaint about Bitwarden is that the desktop app on macOS does not have support for Touch ID which is a shame. It has been a requested feature for a long time but no progress seems to have been made.

The desktop Bitwarden app is Electron based so I don't know if that is an issue or not.

Overall for £10/year for Premium or legitimately free if you don't need the Premium features you are a fool to not use it imho.

Re: Bitwarden Completes Third-Party Security Audit

#45

We used LastPass for several years in our home, mostly because it was able to fill Firefox http basic auth dialogs. When Firefox switched to the webextension format, LastPass started using the Chrome version as the foundation for Firefox. This was a huge step backwards and my wife HATED it. The biggest problem she had was that it was that the standard workflow of it capturing generated passwords became unreliable and…

Yeah, I noticed the change in LastPass' behavior. It turns out that it actually DOES save the random passwords it generates... it's just very well hidden. If you generate a random password for a site, register your account, and LastPass does not catch it and doesn't prompt you to save the account info, it's not lost. If you open the 'Generate secure password' page by itself from the context menu extension, you'll get a new random password. BUT, if you click the down arrow to the right of it, it will drop down a list of the prior generated random passwords for at least that browser session.

Utter madness, but it saved me a couple times.

Re: Bitwarden Completes Third-Party Security Audit

#46
post #7

Since Bitwarden added sub-domain support and fixed the speed-issues on large key-bases, I absolutely cannot live without Bitwarden it's been absolutely flawless. Previously used Lastpass for 8 years. So glad to see that it's security taken seriously by the developers!

How is the form fill for information besides username and password (e.g. credit cards, personal contact info) compared to LastPass?

I only use it for autofilling my CC and it works fine. A couple of sites don't play well with setting the expiry month via dropdown menus but otherwise it is solid.

Re: Bitwarden Completes Third-Party Security Audit

#47

There's a Rust implementation of the BitWarden server which is compatible with the open source clients, that you can run really easily in Docker: https://github.com/mprasil/bitwarden_rs Im running it via Dokku and it has been rock solid. It's way lighter than running their reference server implementation.

I look forward to testing it.

I was using the ruby version, but I didn't know a rust one existed as well.

https://github.com/jcs/rubywarden

Re: Bitwarden Completes Third-Party Security Audit

#48

We used LastPass for several years in our home, mostly because it was able to fill Firefox http basic auth dialogs. When Firefox switched to the webextension format, LastPass started using the Chrome version as the foundation for Firefox. This was a huge step backwards and my wife HATED it. The biggest problem she had was that it was that the standard workflow of it capturing generated passwords became unreliable and…

Switched to Lastpass half a year ago and it's been a rocky move (I didn't have a password manager before). It's consistently been painful to use. For example, my work email transfers between different domains for log in versus viewing and I think even a third. Lastpass never manages to suggest the password at the right time because of this and I always forget where to find it. The mobile app routinely makes me type my long passphrase in twice in a row which is painful because it's easy to typo it. I also don't trust it saving randomized passwords it generates so I always have to copy them to clipboard and confirm that the account was added properly. I have had problems where data did not sync; I could see it in Mobile but not desktop or vice versa. It had been in my account for weeks at that point. Maybe I should try bitwarden.

Re: Bitwarden Completes Third-Party Security Audit

#49
post #7

Since Bitwarden added sub-domain support and fixed the speed-issues on large key-bases, I absolutely cannot live without Bitwarden it's been absolutely flawless. Previously used Lastpass for 8 years. So glad to see that it's security taken seriously by the developers!

>Previously used Lastpass for 8 years. As a longtime Lastpass user, this is the comment that made me go check it out. Are there any big pros or cons you have run in to compared to Lastpass (aside from the ones you listed)? I'm asking about actual functionality, not about the it being open source and such.

I've been a paying LastPass user for over 8 years. I switched to Bitwarden a few months ago. It's so much nicer to use than LP.

LP's extensions and mobile app have gotten slow and clunky. Bitwarden's software is fast. Unlocking LP in Firefox would take me 10+ sec. Bitwarden takes about a second.

The only downside I've found so far is that Bitwarden doesn't have an inactivity logout, only timeout. This makes me log in more frequently than I'd prefer.

Re: Bitwarden Completes Third-Party Security Audit

#50
I use and like Bitwarden but their iOS app feels a bit slow especially when I need to search the Vault. After tapping the search icon it takes somewhere around five seconds (sometimes even longer) of loading time until I can enter my query. Has anyone else experienced this or is it just me?
Post reply on HN