Live data from Hacker News

Bitwarden: Free, open-source password manager

bitwarden.com

81–90 of 306 posts

Re: Bitwarden: Free, open-source password manager

#81

Earlier quoted context omitted.

Hopefully VC never ever touch Hackernews... :)

Oh sure yes they are indeed here.

Fairly sure that was meant tongue in cheek, as HN is literally run by a VC firm for all intents and purposes. Moderators seems to do a pretty well done making it impartial, but worth keeping in mind that Y Combinator ultimately run this website.

Re: Bitwarden: Free, open-source password manager

#82

I try to use open-source wherever I can, but Bitwarden's UX just can't compete with 1Password or even LastPass. The Firefox extension in particular is pretty wonky.

Agree. MacOS app is bad. Chrome extension bad. I use it at work and for that it's fine, I barely have to use it.

Re: Bitwarden: Free, open-source password manager

#83
I’ve been using Bitwarden more as a backup since it lags in more ways than one. With iOS 17 bringing password sharing, I may be able to rely on that and switch to KeePass (and its derivatives) as a cross platform backup where needed.

Products like 1Password and Dropbox first made a good consumer product before pivoting to enterprise and making the products worse. Even before the VC funding of $100 million, Bitwarden started pivoting to cater to enterprise features and neglected the consumer side. This has resulted in Bitwarden doing a minimum set of things in a very mediocre way.

Its desktop clients are based on Electron and suffer with the common issues related to that (don’t behave like native apps for keyboard shortcuts or navigation, sluggish, etc.). Its mobile app, at least on iOS, is also sluggish and has poor UX.

People have asked for additional predefined item types (like WiFi passwords, software licenses, etc.) and that’s been on the roadmap for more than five and a half years [1] with no timeframe for release in sight. It just recently changed the timeframe for this from the first half of 2023 back to “Under Research”. [2] In all likelihood, it’ll be six and a half to seven years by the time that’s done, if at all.

One positive about Bitwarden is that its free tier offers something that’s somewhat good (ProtonPass is nowhere close to this as of yet). But I don’t see anything in the password management market that’s cheap enough (like Bitwarden’s personal plan), has good features (including browser extensions) and stability, and is managed by courteous and helpful people (1Password fails on some of these).

[1]: https://community.bitwarden.com/t/additional-item-types-pre-...

[2]: https://community.bitwarden.com/t/bitwarden-roadmap/12865

Re: Bitwarden: Free, open-source password manager

#84

I am a KeepassXC user, yet this sounds interesting. What does Bitwarden offer to make me want to switch?

I also use KeePassXC and commit my DB to git. On PCs I just clone the repo and am ready to go. On mobile I download the DB via a web interface. No fancy automatic sync, but my DB doesn't change that often, so the manual effort is still small.

Re: Bitwarden: Free, open-source password manager

#85

Earlier quoted context omitted.

My take in life: whenever VC or PE investors take over, start moving away from that product and pronto .

Hopefully VC never ever touch Hackernews... :)

Hacker News is essentially a marketing and legitimization arm of a VC firm. The community around it is the value. They know what happens if they try to change it.

Re: Bitwarden: Free, open-source password manager

#86

FYI - Bitwarden took $100M in VC money last year. At some point, the pressure to aggressively monetize will unfortunately happen. https://techcrunch.com/2022/09/06/open-source-password-manag...

You are right, but I think it is relatively easy to just export Bitwarden data and import it to KeePassXC if it will be necessary.

Re: Bitwarden: Free, open-source password manager

#88
post #79

I have no passwords. Don't get me wrong, I don't use a password manager either. Not a single one of them is truly portable, safe or secure. What if you lose all your electronics? All your belongings? Your house burns down in a fire? The cloud gets hacked? You have conflicting interests with US government and they kindly request your passwords from Apple? You have conflicting interests with any other country and they…

Interesting. If say 3 passwords using that algorithm leaked, would it be possible to deduce the algorithm itself? Edit: what about digit-only password?

No. Not without a proper examination by someone who knows historical cryptography techniques, those used before computers. I'd expect the only real threat to be an automated transformer AI solution actively looking for these types of algorithmic passwords, and one which already has access to a few of my passwords. Which is extremely unlikely given that no one uses algorithmic passwords. I was using a separate algorithm for more critical things, like my Google account but I deemed it unnecessary after some time because there is virtually no chance someone will crack it.

Though I should admit I still didn't migrate all my passwords to the latest and safest specification of the algorithm.

Only using digits limits the probabilities space drastically.

Re: Bitwarden: Free, open-source password manager

#89
post #7

I am a happy user and find it very convenient but how safe is it really to have all your jewels centralized in the cloud, including 2FA. It seems such a worthwhile target. On the other hand keeping everything in sync manually seems a hassle and in the end you just encrypt on your machine and the syncing goes through the cloud anyway, so where's the difference? I'd be happy to hear thoughts on this.

I'm using keepass, and the sync does not seem to be hassle - my file lives in dropbox, and it's always been synced before I open the app on another device. Bonus - backing up the database is as easy as copy-pasting a file.

For anyone who wants to avoid storing the Keepass database in the cloud store I can recommend Syncthing.

For extra security I use a key file in addition to a password which I manually transfer between devices.

Re: Bitwarden: Free, open-source password manager

#90
post #54

Earlier quoted context omitted.

My take in life: whenever VC or PE investors take over, start moving away from that product and pronto .

The new CEO concerns me. I didn't know who the founder was but I always had the impression it was a lone hacker. They passed the baton. Now it's some old Web 1.0 guy who was the CEO of eFax in the 90's. That's not the type of service I thought I was using. I looked up their headquarters in Santa Barbara and it's a co-working space. That doesn't sound very secure. Though that could be their corp address and they're hi…

> The new CEO concerns me. I didn't know who the founder was but I always had the impression it was a lone hacker. They passed the baton. Now it's some old Web 1.0 guy who was the CEO of eFax in the 90's.

This sounds like ageism to me. I don't know if this guy is any good or not, but calling out someone as a 'concern' just because they were successful in the past isn't a good look. Is there anything more substantive behind your concern?

Post reply on HN