Live data from Hacker News

I Do Not Recommend Bitwarden

xn--gckvb8fzb.com

51–60 of 62 posts

Re: I Do Not Recommend Bitwarden

#52
post #8

Probably my biggest tech hill-i'll-die-on is: Password management involving a 3rd party is dumb and should never ever have been a thing. Before two parties had the secret (or something related to it) and now three parties have it and that's objectively worse -- even taking into account "the lazy user" or whatever. I know we're past that in a lot of places for a lot of people, but nope, my dad and his printed out shee…

> my dad and his printed out sheet of password next to his desk is still beating every company out there.

Until your house gets flooded or burns down or you hire a really curious janitor.

Re: I Do Not Recommend Bitwarden

#53
There are not obvious solutions for all use cases, because some of those use cases implies sharing with others under different conditions (because they are role passwords, device/software passwords and other ways to be unique even if multiple people can use and update them), while others are personal (and may or not be used from different devices). Using the same password repository for all, specially if it depends on a single player the access of the repository or the client application could be risky. Having an open format for the database, if self hosted/replicated is something good to have

I agree with the suggestion of using keepass/keepassxc/etc for personal passwords and other solutions for sharing with different partners. It was a good experience in general to use pass (or some alternative UI, like gopass) to use gpg+git to securely share passwords in an environment where that was possible. But sometimes you have to adapt to what already is being used or is accepted by the other players, and not always that is the safest in your opinion, in those cases limit your exposition.

Re: I Do Not Recommend Bitwarden

#54
Nothing seems to draw out the ire more than pet peeves with your password manager. I still vividly recall the issue that made me leave 1Password in a huff to start using Bitwarden.

I don’t self-host, and I’m satisfied with the UX—it just does what it needs to.

One thing I’m not a fan of—-new features. Or the drive to add new features, without extraordinary care. I much rather use slow and boring for my password manager than deal with _woops, I did it again_ development.

Re: I Do Not Recommend Bitwarden

#55

Nothing seems to draw out the ire more than pet peeves with your password manager. I still vividly recall the issue that made me leave 1Password in a huff to start using Bitwarden. I don’t self-host, and I’m satisfied with the UX—it just does what it needs to. One thing I’m not a fan of—-new features. Or the drive to add new features, without extraordinary care. I much rather use slow and boring for my password manag…

I have used 1pw since fleeing lastpass many years ago. It seems to be just what you want, functional and boring. I never had issues with the version 7 to 8 upgrade, that pissed off so many people.

Re: I Do Not Recommend Bitwarden

#56
post #31
post #8

Probably my biggest tech hill-i'll-die-on is: Password management involving a 3rd party is dumb and should never ever have been a thing. Before two parties had the secret (or something related to it) and now three parties have it and that's objectively worse -- even taking into account "the lazy user" or whatever. I know we're past that in a lot of places for a lot of people, but nope, my dad and his printed out shee…

>3rd party is dumb and should never ever have been a thing. Before two parties had the secret (or something related to it) and now three parties have it and that's objectively worse There seems to be a misunderstanding of how typical cloud password vaults work. The 3rd parties like Bitwarden, 1Password, Apple iCloud Keychain, etc don't have access to the users' passwords . The scheme is based on Zero-Knowledge End-2-…

I absolutely understand how it works, which is why I said something like it.

You still have an extra party involved; and you can't fully guarantee that Apple et al is doing things perfectly, and again, in this scenario you've created a 3rd very juicy target.

Re: I Do Not Recommend Bitwarden

#57
post #8

Probably my biggest tech hill-i'll-die-on is: Password management involving a 3rd party is dumb and should never ever have been a thing. Before two parties had the secret (or something related to it) and now three parties have it and that's objectively worse -- even taking into account "the lazy user" or whatever. I know we're past that in a lot of places for a lot of people, but nope, my dad and his printed out shee…

But it's not that though. They're hosting an encrypted version that they don't have the keys for. They are doing the backend sync for you, and writing the clients that YOU run, that sync yuur passwords everywhere. To suggest they have a copy of your passwords is to misunderstand what they're doing. It's the same as saying you host your Keypass on Dropbox so now Dropbox have a copy of your passwords/secrets. The value…

All of you keep missing the "something related to it."

They have something that could end up being a juicy point-of-failure that does not need to exist.

Re: I Do Not Recommend Bitwarden

#58
post #8

Probably my biggest tech hill-i'll-die-on is: Password management involving a 3rd party is dumb and should never ever have been a thing. Before two parties had the secret (or something related to it) and now three parties have it and that's objectively worse -- even taking into account "the lazy user" or whatever. I know we're past that in a lot of places for a lot of people, but nope, my dad and his printed out shee…

Are you aware that the goal of these password managers is that they do not ever have your decrypted vault?

I am. I'm also aware that *they don't always meet that goal".

That's why I said "something related to it."

As mullvad and others correctly note, however -- they can't leak something they never had in the first place.

Third parties make for juicy targets.

Re: I Do Not Recommend Bitwarden

#59
You should keep regular backups of your BW vault as a plain JSON file. KeepassXC can now import BW vaults natively (passkeys included). If anything were to happen to Bitwarden you can migrate to KeepassXC as a stop-gap measure.

Re: I Do Not Recommend Bitwarden

#60
This is such a HN blog post it's almost funny. You wanted to selfhost and you can but it wasn't easy or particularly Linux friendly, so you got a Rust server from the community, but you wanted something officially supported, so they made a specifically lightweight self-hostable version but it's in a programming language you don't like. :( Those bastards!
Post reply on HN