Even including the self hosting setup, my all-in migration time was <30 minutes.
I looked through a ton of other options like keepass and the author's own PfP. But mobile, web, and yubikey support are all very important requirements for me.
Even including the self hosting setup, my all-in migration time was <30 minutes.
I looked through a ton of other options like keepass and the author's own PfP. But mobile, web, and yubikey support are all very important requirements for me.
[0]: https://cdn.bitwarden.net/misc/Bitwarden%20Security%20Assess... [1]: https://hackerone.com/bitwarden
The same could be said for proprietary applications, which may never see third party audits because 'meh, customers have no access to our source and IP protection or something'
Which is a shame, I have reported bugs to a lot of other password managers, but will not dedicate time to one that is not paying me for it.
Sure, you can't eat that, but man does not live on bread alone.
You'd tell a neighbour if they'd accidentally left their car door open, wouldn't you? Most people would even shut the door if they weren't around. Same principle.
This is a poor example because finding bugs requires a lot more effort than giving a door a push (which I find a little spurious - I wouldn't touch my neighbours' car).
There is in practice an almost infinite amount of things you can donate time to and all else being equal (for example, they're all password managers) I doubt you'll convince most people by telling them they should do it because "it makes things better for everyone", they could be making everything better for everyone and still getting paid - that's the superior option. Even if I think you are correct.
I think, for practically everyone, it is far more likely that shared infrastructure (like LP or hosted bitwarden) would be centrally compromised. For example, this post mentioned compromising a safety check for all lastpass users by finding a single vulnerability on a single lastpass domain.
Unless you go to extreme lengths with your personal opsec, a targeted attack by a skilled attacker is pretty much sure to be able to compromise you.
(In fairness, I don't actually know if self hosted bitwarden is enough for all classes of attacks or if I should also compile the clients myself in order to remove any references to the main bitwarden domain)
I believe the opposite to be true. Any use of Shodan or any vulnerability scan of the public internet provides strong evidence that centralized, funded and focused services do security better than 99% of orgs and individuals.
You can’t run infrastructure and app security better than a specialist SaaS company. You don’t have the same time and money.
Yes, the blast radius is smaller for self-hosting, but that’s small comfort when you are still inside the blast radius.
Combining a few of the shelf components (dropbox + keepass in my case) should be easy enough to not screw up so badly it isn't worth putting your eggs in a different basket as everyone else.
Link: https://joinup.ec.europa.eu/sites/default/files/ckeditor_fil...
For example, I chimed in on github semi recently about there being a lack of automated tests and within a week somebody claimed to have decided to prioritize it. With other companies, 1) we wouldn't have known, and 2) we wouldn't ever know if it was fixed
TLDR, long term looks great for bitwarden, short term makes me a tiny bit nervous though
Edit: looks like they added 3 test files that I could find, which isn't terribly comprehensive but I assume there are more I missed on the other repos...
Switched to it somewhat over a year ago from LastPass after I read up on LastPass’ ‘security’. The only thing I dislike about Bitwarden is that on their iOS app it sometimes takes a while (>30s) to load the search function. I love that their chrome extension has a dark mode!
Bitwarden is using Microsoft technologies. If running a MSSQL server is too much for you, you can use alternative servers which are fully compatible with the official clients:
- https://github.com/dani-garcia/bitwarden_rs - https://github.com/jcs/rubywarden
https://github.com/search?q=org%3Abitwarden+exceeds+the+maxi...
So the notes fields can't store more than 10k, which isn't going to work for me at all.
Update:
Found this python script and ran it. https://github.com/bitwarden/web/issues/194#issuecomment-464...
Only had two notes that were too long. Added them in by hand. Problem solved.
https://help.bitwarden.com/article/import-data/#troubleshoot...
Another reason, It has a polished app and works flawlessly on all the platforms and I can host it myself.