We used LastPass for several years in our home, mostly because it was able to fill Firefox http basic auth dialogs. When Firefox switched to the webextension format, LastPass started using the Chrome version as the foundation for Firefox. This was a huge step backwards and my wife HATED it. The biggest problem she had was that it was that the standard workflow of it capturing generated passwords became unreliable and…
I moved from Lastpass to 1Password recently. Neither fill basic auth dialogs, and both companies state this is a feature not a bug. It still pisses me off.
Bitwarden Completes Third-Party Security Audit
81–90 of 148 posts
Re: Bitwarden Completes Third-Party Security Audit
#82We used LastPass for several years in our home, mostly because it was able to fill Firefox http basic auth dialogs. When Firefox switched to the webextension format, LastPass started using the Chrome version as the foundation for Firefox. This was a huge step backwards and my wife HATED it. The biggest problem she had was that it was that the standard workflow of it capturing generated passwords became unreliable and…
Each generated password is visible in the triangle drop-down to the right of the generated password. This list resets on restarts
Re: Bitwarden Completes Third-Party Security Audit
#83I used Lastpass for about 5 years and moved to bitwarden a couple of years back. I never had to turn back again. The browser addons are great, but the mobile app is fantastic, simple, usable and lightweight. It's great to hear that it's pretty secure too.
Great browser addon? The one I'm using (the official one) could definitely use some improvements in UX and security - when I open it my master password is prefilled and you can just unmask it - either don't prefill it and have me enter it or log me in immediately - when creating new credentials it defaults to master password again that you can just unmask. And the URL is empty instead of the current URL - everytime:…
You don't happen to have that password set up in your browsers own password management tool do you?
Url for new credentials is always the current one as well.
Re: Bitwarden Completes Third-Party Security Audit
#84Currently using Bitwarden right now. Really good to see that the security assessment is relatively positive: > All in all, while the client and backend code are vulnerable to some issues, all of the problems can be easily fixed without a lot of effort. In that sense, Cure53 believes these items of the Bitwarden scope to be fully capable of reaching the desired standards of security in a rather short time. To reiterat…
> Wondering how they will address the current cryptographic scheme though. The only cryptographic weakness Cure53 identified was that a malicious API server could exfiltrate encryption keys. Cure53 deemed it a hard problem to solve. I wrote a proposed strategy for mitigating it: https://github.com/bitwarden/core/issues/392 Regarding Bitwarden's cryptographic security, a cursory read through their code yields the foll…
I don't know the details of the security proof for RSA-PKCS though, just that there is one.
Re: Bitwarden Completes Third-Party Security Audit
#85Earlier quoted context omitted.
Not sure I understand you correctly, but Bitwarden can do this (it's the 'passphrase' option).
They recently added that: "Oct 9 - This is in the next release for various apps." [1] the PR is from Oct 6 [2]. It is a very basic implementation as of now. The wordlist is English-only, and it doesn't have a minimum character account so it contains 'words' such as 'aa' and 'aaa'. [1] https://community.bitwarden.com/t/add-an-ability-to-generate... [2] https://github.com/bitwarden/jslib/pull/12
The PR discusses how the original word list that was referenced was changed out to the better long word list from https://www.eff.org/dice .
Re: Bitwarden Completes Third-Party Security Audit
#86We used LastPass for several years in our home, mostly because it was able to fill Firefox http basic auth dialogs. When Firefox switched to the webextension format, LastPass started using the Chrome version as the foundation for Firefox. This was a huge step backwards and my wife HATED it. The biggest problem she had was that it was that the standard workflow of it capturing generated passwords became unreliable and…
Still less buggy than Lastpass's Safari extension though...
Re: Bitwarden Completes Third-Party Security Audit
#87Earlier quoted context omitted.
>Previously used Lastpass for 8 years. As a longtime Lastpass user, this is the comment that made me go check it out. Are there any big pros or cons you have run in to compared to Lastpass (aside from the ones you listed)? I'm asking about actual functionality, not about the it being open source and such.
I used LastPass for roughly a year before making the switch. I also switched from Chrome to Firefox at the same time, on Windows and Android. Desktop - no issues! Android is evolving, and their changes seem to have put Firefox in a slightly behind position, which I think they're almost caught up on. Basically, there's legacy and modern autofill capabilities in Android, and Firefox is working on closing the gap. In th…
Re: Bitwarden Completes Third-Party Security Audit
#88We used LastPass for several years in our home, mostly because it was able to fill Firefox http basic auth dialogs. When Firefox switched to the webextension format, LastPass started using the Chrome version as the foundation for Firefox. This was a huge step backwards and my wife HATED it. The biggest problem she had was that it was that the standard workflow of it capturing generated passwords became unreliable and…
Re: Bitwarden Completes Third-Party Security Audit
#89Earlier quoted context omitted.
From your experiences is there any downside or drawbacks with switching? I've been considering it, particularly as Lastpass's Firefox app has been flakey and unreliable. In general Lastpass has become less reliable since the LogMeIn take-over, and they've now added ads to the vault which bug me from a security perspective (even if I happily pay $2/month, it is the principle of putting profits over security).
I'm a former last pass user as well. I made the switch about a year ago, and haven't really looked back. That being said, there are a few things that annoy me about bitwarden. For some sites or apps in iOS, you can launch a password manager to retrieve your credentials. This sometimes but does not always have bitwarden available. Sometimes when launching bitwarden from an app, it will only show you the logins associa…
As a very happy BW user, this is probably its weakest point at the moment. It improves a bit if you click the "do you want Bitwarden to save these credentials" banner, but still suboptimal (the captured URL is unnecessarily precise).
I don't think they can solve this problem though, unless they get a sidebar - which may not be possible with WebExtensions (I honestly can't recall).
Re: Bitwarden Completes Third-Party Security Audit
#90I have been using Keepass2, then KeepassXC for 5 years, with Dropbox to sync the db between my devices. Since Dropbox recently stopped to support ecryptfs, I started looking for alternatives (KeepassXC + Google Drive/SpiderOak, Lastpass were some candidates). Looks like Bitwarden is worth testing too :-)
KeePass would be perfect if I had an easy platform to share the file on. A VPS isn't reliable enough for me, and Dropbox 's proprietary Linux client did suspicious stuff.