It's pretty good. There's also bitwarden_rs (a rust-based server component) if you fancy a simpler self-hosting stack that doesn't require SQL server.
The solution has been audited, I believe, but audits are only valid at individual points in time. The only downside for me is the use of electron and web technologies in many of the clients - that for me is a huge attack surface of complexity that few people can fully understand and manage.
If they would remove this step, or at the very least explain it, I'd be more likely to deploy and use it. Critical things like password managers should be self hosted where possible, IMO, and this is a blocker preventing trivial deployments.
So far so good, but how do they protect from hacking or from Bitwarden employees the shared secrets in an organization? I understand that each member of the organization team has their own master key.
This part makes electron apps even a bigger problem, because if hacker owns the app that's the point where they can grab the password before it's encrypted.
Depending on what remote sync and team permissions looks like at your end, you could perhaps get there with KeePassXC [0] (password manager) and a separate sync tool (that did your sync and, effectively, your permissions management) such as Keybase KBFS [1] or SyncThing [2].
I'm pretty sure you don't need to trust the syncing software, so anything should work. Someone please correct me if i'm wrong
Perhaps they could force you into a password reset for a specific site by corrupting the correct files. That might be an interesting first step for an account takeover.
These are highly complicated, active attacks. I wouldn't worry as long as your sync service isn't literally the Russian or Chinese government.
It would be interesting to see that accomplished without making it obvious (particularly: without corrupting large parts of or the entire database). KeePass encrypts the whole database.
http://users.ece.cmu.edu/~ganger/712.fall02/papers/p761-thom...
In the worst-case scenario, no, your seatbelt won't help. I'm still going to wear one.
its "just" a wrapper around gpg and git.
so add/crypt with the team and push. and you can do team shared keys if that's your thing.
oh, and passbolt is not terrible either.