Live data from Hacker News

Concerns raised over Bitwarden moving further away from open source

phoronix.com

41–50 of 61 posts

Re: Concerns raised over Bitwarden moving further away from open source

#41

Earlier quoted context omitted.

I think the thing we need to learn about security is that usability matters. I think this is easy for pretty much anyone that's an active HN user, but is it for your parents or grandparents? It's they who matter a lot. It's why WhatsApp was so successful, it passed the Grandma check. Signal might, but onboarding is "hard" (and the nerds argue and that's all others hear and then do what... Use telegram? Lol). But it's…

> Signal might, but onboarding is "hard" (and the nerds argue and that's all others hear and then do what... Use telegram? Lol). I refuse to use Signal because their message history functionality is too restrictive for me. Telegram strikes a good balance, and wins at the UI/UX game.

  > message history functionality is too restrictive for me.
At least a way you can get around this is to do the backing up by desktop. I'm assuming you're on an iPhone because Android supports backup.

If you are Android, see Molly: https://github.com/mollyim/mollyim-android

  > Telegram strikes a good balance, and wins at the UI/UX game.
Telegram gets the "lol" because it's not default E2EE. They advertise themselves as E2EE but most people are not using this feature because it's opt in. If you're going to seriously position yourself as a security app, the defaults have to be secure. It's the bare minimum.

And E2EE isn't even available for group chats... WhatsApp is more secure (telegram also gathers metadata)...

I do think signal has stagnated while there are many things that could really be improved, including low hanging fruit like just being able to search for stickers (people do in fact care). But for the most part, I'm not sure there's anything major missing. It seems like we're willing to pay high costs to avoid small thorns. But I guess it's better to have a rock on your shoulders than a needle in your finger.

Re: Concerns raised over Bitwarden moving further away from open source

#42
post #20

Earlier quoted context omitted.

KeepassXC. https://keepassxc.org/ Recently switched over from a premium Bitwarden account to it. Import from Bitwarden was a breeze. Note that KeepassXC only writes to a local encrypted db file. Syncing that across devices is left to you. I used Syncthing for that.

Bad news there. https://forum.syncthing.net/t/discontinuing-syncthing-androi...

I've used this long-running fork and been pleased, and it's on F-Droid. https://github.com/Catfriend1/syncthing-android

Re: Concerns raised over Bitwarden moving further away from open source

#43

Earlier quoted context omitted.

I think the thing we need to learn about security is that usability matters. I think this is easy for pretty much anyone that's an active HN user, but is it for your parents or grandparents? It's they who matter a lot. It's why WhatsApp was so successful, it passed the Grandma check. Signal might, but onboarding is "hard" (and the nerds argue and that's all others hear and then do what... Use telegram? Lol). But it's…

This is fair, though in my answer, I wasn't answering the question from the perspective of applicability for a general audience. For a general audience, even Bitwarden doesn't pass the "grandma check". If you've used Bitwarden for a while you have probably been met with a stern warning about "KDF Iterations too low". So I pitched the answer assuming "able to use Bitwarden" as a base level of tech savvy. Also, seeing…

That's totally fair and I actually do agree.

I'm willing to give up convenience for security. But I do like to stress that we should try to have both as much as possible. It's a thing that is often forgotten and many times matters.

I'd definitely agree that it's not a big issue here, as password managers are more personal, though my general frustration is with things like communication where I need the other person to also be willing to make the same compromises. Though back with password managers, I do need things that at least pass the parent test (retiree but not old folks home) because their information leakage leads to my leakage regardless of my actions. So I still do think it's worth turning up the heat to push things this way.

As a different point (which I'm not trying to argue but point out) is that we also need to recognize momentum and the challenges it brings, especially to the less tech savvy. We can jump ship easily when tides change because we know how to sail on our own, but what about those that don't? I am sympathetic to those who think we just jump ship to ship because even when they follow when they look back it looks like everyone is fine. I think it's a really unfortunate issue and I think a much more difficult challenge to solve. I'm not sure if anyone has any ideas. OSS only makes it easy to jump ship, but it doesn't reduce the need to jump in the first place

Re: Concerns raised over Bitwarden moving further away from open source

#44

Earlier quoted context omitted.

> Signal might, but onboarding is "hard" (and the nerds argue and that's all others hear and then do what... Use telegram? Lol). I refuse to use Signal because their message history functionality is too restrictive for me. Telegram strikes a good balance, and wins at the UI/UX game.

> message history functionality is too restrictive for me. At least a way you can get around this is to do the backing up by desktop. I'm assuming you're on an iPhone because Android supports backup. If you are Android, see Molly: https://github.com/mollyim/mollyim-android > Telegram strikes a good balance, and wins at the UI/UX game. Telegram gets the "lol" because it's not default E2EE. They advertise themselves as…

> Telegram gets the "lol" because it's not default E2EE.

I use Telegram mostly for group chats, pretty much as an IRC replacement. I think that's where it really shines. :)

Agreed that even WhatsApp is more secure, but if I remember correctly, they do not promise that metadata is E2EE (if that's even possible), and Meta harvests that.

Re: Concerns raised over Bitwarden moving further away from open source

#45
post #16

Earlier quoted context omitted.

No support for passkeys, either.

I wouldn't trust passkey myself [0] [0]: https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shatt...

I'm using passkeys in BitWarden, and they so far work everywhere, except for the Apple Developer website. That doesn't _have_ a passkey enrollment option, and instead automagically creates it in the keychain somehow.

I checked the way they are implemented in BitWarden, and it's straightforward.

BTW, the blog is disingenuous. The removal of device attestation from PassKeys was a great boon for compatibility. And the experience with resetting key storages or not having enough slots are simply bugs and/or limitations of hardware. Which was to be expected from a new technology.

Re: Concerns raised over Bitwarden moving further away from open source

#48

Earlier quoted context omitted.

> message history functionality is too restrictive for me. At least a way you can get around this is to do the backing up by desktop. I'm assuming you're on an iPhone because Android supports backup. If you are Android, see Molly: https://github.com/mollyim/mollyim-android > Telegram strikes a good balance, and wins at the UI/UX game. Telegram gets the "lol" because it's not default E2EE. They advertise themselves as…

> Telegram gets the "lol" because it's not default E2EE. I use Telegram mostly for group chats, pretty much as an IRC replacement. I think that's where it really shines. :) Agreed that even WhatsApp is more secure, but if I remember correctly, they do not promise that metadata is E2EE (if that's even possible), and Meta harvests that.

But just to be clear, telegram is not a privacy nor security app. It's just a communication app. It's fine that you use it, but just making sure you aren't calling an orange an apple (eat whatever fruit you want, I'm not a cop).

  > they do not promise that metadata is E2EE (if that's even possible), 
Sure it's possible. Signal does do this as well as many VPNs, things like encrypted DNS, tailscale and so on.

It's important to remember that it's also not binary. There's a whole range of metadata is. You can leave a footprint that's a very clear image of your shoe or you can leave a footprint that's a smudge that's only approximately in the size of your shoe. If you're concerned then the difference matters a lot.

While you won't leave zero trace the aforementioned apps (like signal and mullvad) do minimize the collection to the point where it isn't very useful. I mean it's metadata that you're a person, but that's not going to be helpful to identify you. Even knowing your gender probably won't but metadata's power is in it's accumulation.

Re: Concerns raised over Bitwarden moving further away from open source

#49
post #9

Earlier quoted context omitted.

Yes, via the KeePassium client: https://github.com/keepassium/KeePassium As with all iOS apps, there’s no guarantee that the open source app code on GitHub corresponds to what you install from the App Store. I have been very satisfied with KeePassium, it integrates with all the cloud storage providers I’d want and the app itself works well.

Notably though, Keepassium from the App Store is licensed differently than the version on GitHub. Only the Keepassium team can ever actually submit to the App Store as GPL software is banned, and so they do not accept contributions so that they have the ability to submit under a proprietary license.

My reading from the License section[1] of the Keepasium README and this Stack Exchange post[2] is that the author of KeePassium wishes to license KeePassium under GPLv3. Accepting applications licensed under GPLv3 would require that Apple provide certain forms of source code alongside App Store downloads which they are unwilling to do. As such the App Store terms of service has terminology stating that you give Apple the right to not do that, which is something that only the copyright holder(s) of a work can do. The simplest way to have clarity over who holds the copyright is to have a single author. So long as the KeePassium author is willing to assign Apple the permission implicit in submitting to the App Store, that’s fine. It just means that all other uses of KeePassium must follow the GPLv3 license.

I am not a lawyer, nor really even well-versed in IP law, and you should not take this as legal advice.

[1] https://github.com/keepassium/KeePassium?tab=readme-ov-file#...

[2] https://opensource.stackexchange.com/questions/9500/is-apple...

Re: Concerns raised over Bitwarden moving further away from open source

#50
post #31
post #21

I'm paying for BitWarden because I want to support them. But it's pretty clear that they're backsliding. This is understandable, the password manager market is saturated and implementing new features like Passkeys is far from trivial. Still, they are the only real option for a one-click mostly open source password manager that works across all the major platforms and that supports modern features.

Isn't passkey support already in? I am using that in day-to-day basis. Bugs exists, but it is not that far.

I mean that implementing things like passkeys required a lot of front-loaded work from them, without getting any compensation. So it's understandable that they're trying to push people to get subscriptions.
Post reply on HN