Earlier quoted context omitted.
Closed source I can deal with, as long as a strong audit has been performed. Found this: https://www.enpass.io/security-audit-report/ I'm not a security expert, so not sure if those audits are trustworthy.
That's the problem though isn't it? Unless you're an absolute expert in every aspect of a thing, you gotta trust someone who claims to be the expert, eventually. Or never trust it. When it comes to security audits of software I often prefer to see that software failed at this or that, and was corrected, with a reasonable explanation of both the problem and the applied solution. To me, this shows that 1) the audit was…
Bitwarden: Avoid at all costs (outage issue)
51–60 of 137 posts
Re: Bitwarden: Avoid at all costs (outage issue)
#52Censoring the forum comments is definitely a very different kind of secret management!
Re: Bitwarden: Avoid at all costs (outage issue)
#53Even Google and AWS have outages. Bitwarden has rarely had issues. And this is all free service. Customer expectations have skyrocketed.
Hello. I'm paying for the service. My expectation is as simple as being able to log into the password manager when the cloud has an outage and I don't experience any problems. When they did disable my log in attempts, they showed the centralized — we own your data type of an issue.
Re: Bitwarden: Avoid at all costs (outage issue)
#54Re: Bitwarden: Avoid at all costs (outage issue)
#55No matter what password you use, I highly recommend regularly exporting a plaintext copy of it to somewhere safe like an encrypted volume on one or more of your devices. Just do it once a month - mount the volume, export the database in plaintext directly to the volume, then unmount it. If your password manager locks you out because of a bad software update, service outage, or you hold the wrong passport and got sanc…
Re: Bitwarden: Avoid at all costs (outage issue)
#56No matter what password you use, I highly recommend regularly exporting a plaintext copy of it to somewhere safe like an encrypted volume on one or more of your devices. Just do it once a month - mount the volume, export the database in plaintext directly to the volume, then unmount it. If your password manager locks you out because of a bad software update, service outage, or you hold the wrong passport and got sanc…
Or just use KeePassXC+nextcloud/syncthing as others have suggested, it's just an encrypted database with no cloud bullshit.
Re: Bitwarden: Avoid at all costs (outage issue)
#57Earlier quoted context omitted.
Closed source I can deal with, as long as a strong audit has been performed. Found this: https://www.enpass.io/security-audit-report/ I'm not a security expert, so not sure if those audits are trustworthy.
That's the problem though isn't it? Unless you're an absolute expert in every aspect of a thing, you gotta trust someone who claims to be the expert, eventually. Or never trust it. When it comes to security audits of software I often prefer to see that software failed at this or that, and was corrected, with a reasonable explanation of both the problem and the applied solution. To me, this shows that 1) the audit was…
Re: Bitwarden: Avoid at all costs (outage issue)
#58Earlier quoted context omitted.
I sync my database to my Android phone with Nextcloud, works great with KeePassDX
Nextcloud is amazing, I just don't have the resources or time to self host right now so I'm currently not using it. Big problem for me is that most cloud providers don't actually support syncing to the filesystem through Android's Storage Access Framework and instead keep all of the data in the app data, requiring me to manually export from the cloud application, and re-import into the password manager.
Re: Bitwarden: Avoid at all costs (outage issue)
#59Earlier quoted context omitted.
Wow, okay, yeah, I'm actually sold. There's a CLI for desktop, and it's on both ios and android. Damn. Will gleefully fork over $80 for a lifetime license if it's as good as it seems. Why have I never heard of Enpass before? Anyone have any reason to not switch from Bitwarden to Enpass right now?
It depends if you feel happy entrusting your passwords to what is ultimately a closed source client. I do not. Moving to self hosted vaultwarden from keepassxc-in-syncthing was a big leap. A closed source client is a leap too far.