Live data from Hacker News

Bitwarden Acquires Passwordless.dev

bitwarden.com

91–100 of 399 posts

Re: Bitwarden Acquires Passwordless.dev

#91
post #79
post #53

Earlier quoted context omitted.

Ah for fuck's sake. It keeps happening to all the software I love. I guess I'll have to stop relying on convenience (I was a 1Password user years ago) and go 100% open-source. None of the libre offerings seem to be as convenient and polished, but at least they're not into some VC's pocket ready to squeeze as much profit as possible out of my paid membership. What's a good OSS alternative that works with iOS and Linux…

KeepassXC has served me well for many years, synced via my Nextcloud but could just as easily use dropbox or icloud, or even syncthing.

syncthing works really well imo, can also tell it to keep 3 versions as a backup

Re: Bitwarden Acquires Passwordless.dev

#92
post #68

I really dislike the idea of giving complete access to my digital life to any company, particularly one that needs to grow quickly. The tech for password vaults is so simple, I use keepass + icloud syncing and get free end-to-end encrypted password syncing, without sharing any data with anyone. Outlined in more detail here: https://magoop.substack.com/p/how-to-manage-500-passwords-se...

I do this, but have started using Syncthing [1] for sync instead of a cloud service.

[1] https://syncthing.net/

Re: Bitwarden Acquires Passwordless.dev

#93
post #39

Earlier quoted context omitted.

Also Bitwarden recently raised 100M from VC so yeah, the clock is ticking now.

I'm happy for the one dev who's been lone rangering as I hope it means he's finally getting paid, but the pressure is going to be on to get an ROI.

Insane radical idea: Businesses can actually make a profit by having income higher than expenses. You can pay yourself that way.

Re: Bitwarden Acquires Passwordless.dev

#94
post #48

As a recent convert to Bitwarden from LastPass, I start to get a bit nervous when I see acquisitions happening. LastPass getting acquired was the beginning of the end for it, IMO, before stagnating into criminal negligence. Granted this is Bitwarden acquiring rather than being acquired, but I still worry it leads to a trend of building "portfolio value" rather than focusing on the product. I sincerely hope I'm wrong.

A good note for bitwarden is that it has a self hosting open source version, vaultwarden that is easy to switch to: https://github.com/dani-garcia/vaultwarden I see this as downside protection, as I can quickly migrate if I disagree with bitwarden's direction with minimal changes to my clients. I do worry about VC pressure on Bitwarden for hypergrowth. However in my personal opinion, the benefits outweigh the cons (f…

Note that Vaultwarden is the unofficial server, there is also an official one, that you can self host.

Vaultwarden is much easier to set up and manage, I use it myself, and I heard that the official build is a little bit more tedious to go with.

Re: Bitwarden Acquires Passwordless.dev

#95
post #79
post #53

Earlier quoted context omitted.

Ah for fuck's sake. It keeps happening to all the software I love. I guess I'll have to stop relying on convenience (I was a 1Password user years ago) and go 100% open-source. None of the libre offerings seem to be as convenient and polished, but at least they're not into some VC's pocket ready to squeeze as much profit as possible out of my paid membership. What's a good OSS alternative that works with iOS and Linux…

KeepassXC has served me well for many years, synced via my Nextcloud but could just as easily use dropbox or icloud, or even syncthing.

Upvote for keepassxc. I've been using it and its predecessor with the same database file for something like 15 years and have seen many of these services come and go in the meantime. It will outlive Bitwarden for sure.

Re: Bitwarden Acquires Passwordless.dev

#96
post #72
post #68

I really dislike the idea of giving complete access to my digital life to any company, particularly one that needs to grow quickly. The tech for password vaults is so simple, I use keepass + icloud syncing and get free end-to-end encrypted password syncing, without sharing any data with anyone. Outlined in more detail here: https://magoop.substack.com/p/how-to-manage-500-passwords-se...

Agreed. I use keepass + dropbox secured with yubikey. You can even go a step further and configure yubikey with keepass as well.

Where about on mobile?

Re: Bitwarden Acquires Passwordless.dev

#97
post #87

Your passwords shouldn't leave your device. Chrome's password manager is pushing it. Everything else should be considered malware. I don't understand how such a 'techy' crowd here on HN can be so belligerent with this security vs convenience trade off. KeePass locally, gmail yourself an encrypted backup. That's it. FFS.

How is "gmail yourself an encrypted backup" fine but "store a copy of the encrypted vault in a cloud service designed for this purpose" not?

Re: Bitwarden Acquires Passwordless.dev

#98
post #35

Earlier quoted context omitted.

BitWarden is open source on both ends. So worst case one can self host then fork clients. (Server has already been reimplemented independently.)

This is true, but LastPass proved that by the time the worst case occurs it's already too late. A security breach means, at minimum, redoing all your passwords, and these sites are a very compelling target. OTOH I wouldn't want to self-host because I know I'm not going to spend the same amount of time and effort a full security staff would, even if my self-hosted box would make a much less attractive target. It's qui…

I self-host Vaultwarden. I'm sure someone will be happy to explain to me how foolish my implementation is, but I'm comfortable with it from a security perspective.

I run it as a Docker instance on my home Synology NAS. This turned out to be pretty easy to do. The only part that was a slight hassle was buying a cert, creating an FQDN and making the DNS entries to get an SSL connection to the NAS. Also, I wish updating to a new version of Vaultwarden was a little more straightforward.

When I am at home, my devices with Bitwarden all sync to the Vautwarden instance on the NAS without issue.

My router is a Ubiquiti UDMPro. I have an L2TP VPN configured with a shared-secret and user passwords that are ridiculously long and complex. When I'm out and about and need to sync with the NAS from my laptop or mobile device, I activate the VPN and do the sync.

My Ubiquiti account does have 2FA.

I implemented all this when 1Password informed me that in order to continue using their service, my vault would have to be hosted on their server and I would have to pay them every month for the privilege. That was a nonstarter.

I'm sure my router and NAS are not impenetrable, but I don't feel like I'm low-hanging fruit either. And if someone went to the trouble of breaking in, their reward would be one guy's vault and not the vaults of millions of customers. I'm hoping that makes me a less attractive target. Of course the vault itself has a very long and complex password as well.

This is working out quite well for me so far, knock on wood.

Re: Bitwarden Acquires Passwordless.dev

#99
post #87

Your passwords shouldn't leave your device. Chrome's password manager is pushing it. Everything else should be considered malware. I don't understand how such a 'techy' crowd here on HN can be so belligerent with this security vs convenience trade off. KeePass locally, gmail yourself an encrypted backup. That's it. FFS.

If the key to decrypt the vault never leaves your device, then the security implications are minimal. Well worth the convenience in my eyes, and many others apparently.

Re: Bitwarden Acquires Passwordless.dev

#100
post #87

Your passwords shouldn't leave your device. Chrome's password manager is pushing it. Everything else should be considered malware. I don't understand how such a 'techy' crowd here on HN can be so belligerent with this security vs convenience trade off. KeePass locally, gmail yourself an encrypted backup. That's it. FFS.

This push is because there's a lot of people using weak, reused passwords out there, who are not willing (or capable in cases) of a self-managing a password manager. For the people in my life in this position, I would much rather them use lastpass or bitwarden or anything over continuing their current practice. The risk of a lost password from one of those services is much lower than of them getting hit by password stuffing or getting a password brute-forced.

For a technical person I would advise a better solution, but the reason these solutions are being pushed is for widespread adoption of better password practices.

Post reply on HN