I Do Not Recommend Bitwarden
51–60 of 62 posts
Re: I Do Not Recommend Bitwarden
#52Probably my biggest tech hill-i'll-die-on is: Password management involving a 3rd party is dumb and should never ever have been a thing. Before two parties had the secret (or something related to it) and now three parties have it and that's objectively worse -- even taking into account "the lazy user" or whatever. I know we're past that in a lot of places for a lot of people, but nope, my dad and his printed out shee…
Until your house gets flooded or burns down or you hire a really curious janitor.
Re: I Do Not Recommend Bitwarden
#53I agree with the suggestion of using keepass/keepassxc/etc for personal passwords and other solutions for sharing with different partners. It was a good experience in general to use pass (or some alternative UI, like gopass) to use gpg+git to securely share passwords in an environment where that was possible. But sometimes you have to adapt to what already is being used or is accepted by the other players, and not always that is the safest in your opinion, in those cases limit your exposition.
Re: I Do Not Recommend Bitwarden
#54I don’t self-host, and I’m satisfied with the UX—it just does what it needs to.
One thing I’m not a fan of—-new features. Or the drive to add new features, without extraordinary care. I much rather use slow and boring for my password manager than deal with _woops, I did it again_ development.
Re: I Do Not Recommend Bitwarden
#55Nothing seems to draw out the ire more than pet peeves with your password manager. I still vividly recall the issue that made me leave 1Password in a huff to start using Bitwarden. I don’t self-host, and I’m satisfied with the UX—it just does what it needs to. One thing I’m not a fan of—-new features. Or the drive to add new features, without extraordinary care. I much rather use slow and boring for my password manag…
Re: I Do Not Recommend Bitwarden
#56Probably my biggest tech hill-i'll-die-on is: Password management involving a 3rd party is dumb and should never ever have been a thing. Before two parties had the secret (or something related to it) and now three parties have it and that's objectively worse -- even taking into account "the lazy user" or whatever. I know we're past that in a lot of places for a lot of people, but nope, my dad and his printed out shee…
>3rd party is dumb and should never ever have been a thing. Before two parties had the secret (or something related to it) and now three parties have it and that's objectively worse There seems to be a misunderstanding of how typical cloud password vaults work. The 3rd parties like Bitwarden, 1Password, Apple iCloud Keychain, etc don't have access to the users' passwords . The scheme is based on Zero-Knowledge End-2-…
You still have an extra party involved; and you can't fully guarantee that Apple et al is doing things perfectly, and again, in this scenario you've created a 3rd very juicy target.
Re: I Do Not Recommend Bitwarden
#57Probably my biggest tech hill-i'll-die-on is: Password management involving a 3rd party is dumb and should never ever have been a thing. Before two parties had the secret (or something related to it) and now three parties have it and that's objectively worse -- even taking into account "the lazy user" or whatever. I know we're past that in a lot of places for a lot of people, but nope, my dad and his printed out shee…
But it's not that though. They're hosting an encrypted version that they don't have the keys for. They are doing the backend sync for you, and writing the clients that YOU run, that sync yuur passwords everywhere. To suggest they have a copy of your passwords is to misunderstand what they're doing. It's the same as saying you host your Keypass on Dropbox so now Dropbox have a copy of your passwords/secrets. The value…
They have something that could end up being a juicy point-of-failure that does not need to exist.
Re: I Do Not Recommend Bitwarden
#58Probably my biggest tech hill-i'll-die-on is: Password management involving a 3rd party is dumb and should never ever have been a thing. Before two parties had the secret (or something related to it) and now three parties have it and that's objectively worse -- even taking into account "the lazy user" or whatever. I know we're past that in a lot of places for a lot of people, but nope, my dad and his printed out shee…
Are you aware that the goal of these password managers is that they do not ever have your decrypted vault?
That's why I said "something related to it."
As mullvad and others correctly note, however -- they can't leak something they never had in the first place.
Third parties make for juicy targets.