My biggest complaint about the 1Password8 situation is that i've been "self hosting" version 7 for years using iCloud sync, and it has worked perfectly. I have my 1Password vault on every device for "free". With family sharing in iTunes, i had it for every family member for "free" as well.
With version 8 they're taking that away, and instead trying to push me to a $5/month subscription that essentially does the same thing.
I have faithfully purchased every version up until now, and had they kept local vaults/iCloud sync i would have purchased the next one as well. As it is now, self-hosted or not, i will be looking for something else. Afterall, all i really need is an encrypted file on a cloud share.
Unix Pass would be great if it didn't leak information about which sites you have logins for. "Easily" fixable by using Pass Tomb, but sadly that's not available on iOS.
Having said, I'm all for self-hosting and I hope it continues to become prevalent.
Most people have no clue about the amount of work required to runs things in a secure, redundant and resilient way. And no, a RaspberryPi in the corner, running on your LAN probably won't cut it. At least not for me.
I moved from 1Password, and my main gripe with Bitwarden are the apps aren't as polished. If it's not too expensive I'd consider switching back (1Password family is $60 per year, so I assume this will be less).
I'm just really grateful this project exists. I've tried most of the major password managers out there and I feel like BW/VW is the clear winner, especially if you're willing to host your own server. If not, their pricing for an annual personal account is incredibly reasonable.
- Firefox Extension doesn't work fully in a private window in Firefox.
- Extension loses data when you click away from it.
- Extension is hard to navigate using keyboard - e.g. there is no way to copy specific username/password/otp code.
There is lots more issues.
The one killer feature which is preventing me from switching is the ability to use multiple self-hosted servers at once (so I can separate family vaults from business) [1], but "client profiles" are likely to be implemented some time soon [2].
Now that I've learnt that local vaults are going away in 1Password 8 [3], I'll probably make a move to Bitwarden sooner rather than later.
[1] https://community.bitwarden.com/t/log-in-with-multiple-bitwa...
[2] https://community.bitwarden.com/uploads/default/original/2X/...
The most glaring issue (for me, anyway; I fully understand I'm just a sample size of 1!) they have is relying on the pop-up UI of the browser, which I guess is stateless (state is lost when the popup closes, it seems?). The decision of using this UI was already wrong from its inception, IMHO, not sure why they thought it would be a good idea. But more surprising is that they haven't yet moved to the much more reliable and user friendly method of opening their UI on a new tab, which was a no brainer when using LastPass. Oh well. They said to have this in the backlog, so hopefully it gets some attention sooner than later... but in the meantime the end users are faced with silly issues like this, software that loses user data should not be a concern in the first place, and for sure they won't care about some technical explanation about how the browser handles pop-up windows.
(for anyone interested: https://community.bitwarden.com/t/persist-bitwarden-ui-and-m...)
(he recommends using your browser's built-in password manager, which isn't as convenient but is much more secure)
But this whole proposition totally breaks if I store my Amazon password in Chrome at work, and then later I cannot access it in Firefox at home, or the native app in my Android phone.
Basically, I want the browsers to implement something close to what Apple has for password management on iOS. Ideally go a bit further and expose hooks for creating/saving a new login, too.
Unless they already do this, and nobody has actually taken them up on using it?