Live data from Hacker News

Bitwarden: Avoid at all costs (outage issue)

news.ycombinator.com

51–60 of 137 posts

Re: Bitwarden: Avoid at all costs (outage issue)

#51

Earlier quoted context omitted.

Closed source I can deal with, as long as a strong audit has been performed. Found this: https://www.enpass.io/security-audit-report/ I'm not a security expert, so not sure if those audits are trustworthy.

That's the problem though isn't it? Unless you're an absolute expert in every aspect of a thing, you gotta trust someone who claims to be the expert, eventually. Or never trust it. When it comes to security audits of software I often prefer to see that software failed at this or that, and was corrected, with a reasonable explanation of both the problem and the applied solution. To me, this shows that 1) the audit was…

I appreciate this perspective.

Re: Bitwarden: Avoid at all costs (outage issue)

#53
post #23

Even Google and AWS have outages. Bitwarden has rarely had issues. And this is all free service. Customer expectations have skyrocketed.

Hello. I'm paying for the service. My expectation is as simple as being able to log into the password manager when the cloud has an outage and I don't experience any problems. When they did disable my log in attempts, they showed the centralized — we own your data type of an issue.

did you use 2fa?

Re: Bitwarden: Avoid at all costs (outage issue)

#55
post #20

No matter what password you use, I highly recommend regularly exporting a plaintext copy of it to somewhere safe like an encrypted volume on one or more of your devices. Just do it once a month - mount the volume, export the database in plaintext directly to the volume, then unmount it. If your password manager locks you out because of a bad software update, service outage, or you hold the wrong passport and got sanc…

I believe I will take this advice. Thanks for saying it.

Re: Bitwarden: Avoid at all costs (outage issue)

#56
post #47
post #20

No matter what password you use, I highly recommend regularly exporting a plaintext copy of it to somewhere safe like an encrypted volume on one or more of your devices. Just do it once a month - mount the volume, export the database in plaintext directly to the volume, then unmount it. If your password manager locks you out because of a bad software update, service outage, or you hold the wrong passport and got sanc…

Or just use KeePassXC+nextcloud/syncthing as others have suggested, it's just an encrypted database with no cloud bullshit.

Can you please explain why this is an improvement over the parent comment solution?

Re: Bitwarden: Avoid at all costs (outage issue)

#57

Earlier quoted context omitted.

Closed source I can deal with, as long as a strong audit has been performed. Found this: https://www.enpass.io/security-audit-report/ I'm not a security expert, so not sure if those audits are trustworthy.

That's the problem though isn't it? Unless you're an absolute expert in every aspect of a thing, you gotta trust someone who claims to be the expert, eventually. Or never trust it. When it comes to security audits of software I often prefer to see that software failed at this or that, and was corrected, with a reasonable explanation of both the problem and the applied solution. To me, this shows that 1) the audit was…

Well said, this is a reasonable way of looking at the situation.

Re: Bitwarden: Avoid at all costs (outage issue)

#58

Earlier quoted context omitted.

I sync my database to my Android phone with Nextcloud, works great with KeePassDX

Nextcloud is amazing, I just don't have the resources or time to self host right now so I'm currently not using it. Big problem for me is that most cloud providers don't actually support syncing to the filesystem through Android's Storage Access Framework and instead keep all of the data in the app data, requiring me to manually export from the cloud application, and re-import into the password manager.

KeePassAndroid (not KeePassDX) has integration with the major cloud providers, I used to use it with Dropbox before I switched to self-hosting

Re: Bitwarden: Avoid at all costs (outage issue)

#59
post #42

Earlier quoted context omitted.

Wow, okay, yeah, I'm actually sold. There's a CLI for desktop, and it's on both ios and android. Damn. Will gleefully fork over $80 for a lifetime license if it's as good as it seems. Why have I never heard of Enpass before? Anyone have any reason to not switch from Bitwarden to Enpass right now?

It depends if you feel happy entrusting your passwords to what is ultimately a closed source client. I do not. Moving to self hosted vaultwarden from keepassxc-in-syncthing was a big leap. A closed source client is a leap too far.

It's a closed-source UI on top of sqlite/SQLCipher. You'll be fine.
Post reply on HN