Bitwarden: Free, open-source password manager
bitwarden.com
bitwarden.com
I expected a blog article with actual feedbacks from companies and data, but ended up on bitwarden.com main page.
Baseless claims can be quite common when it comes to marketing, but I'm genuinely curious: which password manager is used in your workplace, if any?
I've personally never seen in my (for now short) career anything else than Keepass.
I like Bitwarden and the work they do and I'm sure they're trustworthy seeing as they've been audited and such but the android app and some of the UI is clunky to say the least. I tried switching from LastPass (which is awful) and ended up going to 1Password
OP here; this hype bothered me, but to avoid being accused of editorialising the target link, I try to include any strap line in full in the HN link description field.
I like them both - 1password has better UX but I prefer supporting open source for personal use.
Same here. Opensource also adds to security in this case.
Also BitWarden's server has no knowledge of your phrase, and hence cannot, never ever, read your data. Forgetting your phrase means you lose your wallet. 1Pass and competitors do not have such guarantee, and allow one to retrieve access to the wallet by other means.
And how does this work when I share passwords with my colleagues in a vault? They dont have my "client generated secret key", so how can they read my passwords?
I know companies write stuff to sell their products, but I dont trust that, I prefer open source and the laws of logic over marketing.
For the record, Bitwarden's white paper is a good read as well. Available at https://bitwarden.com/help/article/bitwarden-security-white-....
(edit: fixed typos)
That whitepaper is a piece of marketing text. Not saying their audit did not take place. But they are soooooo powerful in their own system that they basically have access to everything.
BitWarden: not so much.
Alice is the one that initiates the request. She owns the vault being shared and encrypts it with Bob's pre-shared public key.
1Password says explicitly that you're not sharing the actual item in your vault and that it's creating a copy of it. It's probably generated client side and pushed to an external sharing service
I mean, I understand trusting open source but your statements seem like non-sequiturs. 1Password has been audited and has been an industry standard for a while. They seem to know security so at some level I don't find it difficult to trust them. Of course, I don't deny trusting open source and that's completely valid but not with these specific points
They cannot. That's closely related to why it is so secure, and why they can never see you data. That's why I use it.
It's sometimes called "zero knowledge".
> 1Password has been audited and has been an industry standard for a while.
MSFT products were also audited, and much used, and very insecure. Also 1Pass may be subpoena'd into sharing your data. I do not trust 1Pass, but you do you and feel free to do trust them :)
[0]: https://psono.com/
Note for context - we are in a company that for obvious and less obvious reasons has a detailed list and tiering of allowed open source software for various purposes; while we have more control over our laptop than most companies such size, policies are fairly firm on what we are and aren't actually supposed to install.
KeePass (https://keepass.info/) is excellent for personal usage or for infrequently changing credentials in a team setting, which is why i've also had a good run with it!
That said, for something a bit more centralized and more easily manageable, i've seen solutions like TeamPass be used: https://teampass.net/
Well, TeamPass in particular has a pretty horrible UI (not respecting what i click with my mouse and janky dragging of items around, as well as weird display rules), but in general i feel like many companies out there might want a web app of sorts, even if only available in the internal network and self hosted.
(Not for most of us here, but for most people out there.)
(This could be a limitation of the browser)
When I have to enter my master password into the browser, I'm left with the Lastpass tab focused instead of the site that I'm trying to log into. Although this is annoying for me, it's probably a major obstacle for people who aren't very good at computers.
It does the job, but very poorly. Same as LastPass.
I use 1Password now. If I didn't want to pay for it I'd use KeePass.
Also, we use Passbolt.
But we do use Bitwarden where I work (large enterprise software vendor). Adoption is not consistent, but it's the IT supported solution here.
Also, I'm a happy and paying user personally.
The only thing I miss is an "add to bitwarden?" dialog when I sign up somewhere. Their docs say it exists but I've never managed to get it to appear :-)
I have seen this occasionally but it is fairly random and unreliable. And then sometimes it pops up for stuff I clearly don't want to save, like OTP.
With bitwarden I never missed the "add to bitwarden" dialog. As a paying user. I love that they offer Android app. It has its moments like the integration with keyboard does not always work, but I can use it from the shot it's drawer.
If you generate passwords (or passphrases!) they are stores 8n history, so there's always a backup :)
I've found keyboard integration really hit or miss on Android. On iOS it does quite a bit better.
It's pretty business unfriendly IMO, as most users simply cannot pick up a new, rarely used flow.
I switched away from 1P after they dropped the perpetual license option. They failed me by taking VC money and then chasing growth at users' expense. Not that the other PWM vendors aren't worse -- some of them much worse.
So I went on to add a new entry manually. Oh my, the UX to do so is quite bad. There is such low hanging fruit here for improvement, like copying the "UI on a new tab" style that LastPass does... meanwhile Bitwarden insists on doing everything on a stateless pop-up window [0]. LastPass UI might be worse for some (that's debatable), but the UX of opening it on a new tab is simply superior, just for the fact of it being stateful. I don't get why Bitwarden doesn't adopt it.
I'm happily paying for Bitwarden to support its development, but would never consider suggesting it to my grandpa or to serious business. The flow and experience is just far away from what is expected; a very good software, but with still too many rough edges.
[0]: https://community.bitwarden.com/t/persist-bitwarden-ui-and-m...
It doesn't work very well in Firefox's private browsing. Only thing you can do is autofill by right clicking a text field and autofill from there, or the keyboard shortcut. But you cannot unlock it in private browsing.
Stateless UI is annoying at best. There's a few times where this has slipped my mind, so I paste a generated password in a new item, and then go to copy the email, and the new item is gone. If I didn't use a clipboard manager, this would have meant losing the generated password.
The browser addon is completely separate from the desktop app. It's annoying as it means you have unlock them separately when you need them. I used to be a 1Password customer, and I absolutely adored the seamless experience of the browser extension utilising the desktop app when it's installed.
[1] https://support.mozilla.org/en-US/kb/extensions-private-brow...
https://github.com/bitwarden/browser/pull/2121#issuecomment-...
[0] https://github.com/bitwarden/browser/pull/2121/commits/9d81b...
[1] https://github.com/bitwarden/browser/issues/136#issuecomment...
>Stateless UI is annoying at best...
Agreed. I've been using Bitwarden for ages now and this drives me insane.If you open the popup menu and need to copy/paste/refer to more than one piece of info from it [because autofill doesn't always work or for example, you need more info to login than just username & password] you have to go back each time and re-open the menu, then the sub-menu [if you have more than one account info saved for a domain], to re-find the saved info and copy the next item.
It's made doubly annoying by the fact that there's a button to open the popup in its own mini-window, which allows you to go back and forward to that window, copy/pasting all the 'stuff' you need. However, when you click this button, the new window which opens doesn't retain whatever was in it in its popup version. So you still have to drill down through menus to find the appropriate info again.
I reported this as a bug several years ago on their Github and got a ridiculous reply from the developers, saying that behaviour was deliberate and wouldn't be changed. Apparently they couldn't envisage a situation whereby a user converting the popup menu into a separate mini window would actually want to retain the info therein, rather than having to search it out again.
When faced with total pig-headedness like that from developers, my natural support for their open source efforts evaporates pretty quickly.
The search function is also piss-poor. I've got several Gmail accounts and quite often a site will allow me to login using my Google account. Obviously that won't show up in Bitwarden's popup, as I'm not on a Google domain. So I type 'gmail' into the searchbox and it returns every single one of the 100s of websites where I've got an '...@gmail.com' username, rather than prioritising the Gmail logins which I've actually saved titled 'Gmail <account name>'.
So yes, it's great that it's open source and free [for private use]. But the usability is pretty poor and the developers unresponsive to feedback.
Oh. And incidentally, it barely ever works properly on Android --even with all the required settings and permissions allowed. I might as well keep all my passwords in a text document on my phone. It'd be quicker than waiting in vain for Bitwarden to offer to fill in a login, then opening the app itself to copy/paste the required info and waiting the several seconds while it creaks into action, decrypting my vault.
I switched from Lastpass when they started demanding more money - and whilst not perfect, am very happy with Bitwarden. Functionality is all there, just a bit clunky in places - but you get used to it.
It's not that hard even; we did that for our login form. Works great with Bitwarden. And on mobile too. But you have to know how to name things so that password managers can do their magic.
Frequent mistakes caused by essentially ignorance on this front:
- Splitting the email and password form across two screens. That somehow became fashionable. There are ways to do this and not break password managers. But why do this at all? Having to click the fill button twice is ugly and should be flagged as a bug if you ever see that. There's no need for that regardless of the UX.
- Having a login form but then not using field names like "email" and "password" that a password manager would recognize as such. There are a few more things you need to think about: https://hiddedevries.nl/en/blog/2018-01-13-making-password-m.... Just do it right.
- Not having password managers on the radar as a thing that the UX MUST support (not optional). Non technical people like designers and product owners tend to be a bit sloppy with their own security and they won't necessarily even be aware this is a thing that they need to worry about. So, they don't notice when it doesn't work. They probably don't even use a password manager themselves. And they certainly won't test it.
- Developers not caring enough to do anything about this unprompted; by e.g. just raising the topic with their PMs or just implementing things correctly to begin with. I've actually brought up this topic and usually this is not controversial at all and simple to resolve.
And it's hard to figure out why it doesn't work when it doesn't. The feedback cycle is nonexistent.
Just wanted to note that Google handles this right, which I've always appreciated.
They have two-screen login, and if you use a password manager, the password is prefilled when the second screen loads.
I assume the two-screen login is to ensure the name is valid before asking for a password. Without the clunkiness of doing it "onBlur".
This is done because it's an easier way to support both local login and SSO(like oauth or saml). By taking the username first you can determine whether to ask them for a password or send them to a sso provider.
It doesn't have to be implemented this way but it is seen as easier.
Also, a typical opendid flow or SSO would not actually require an email field at all. So splitting the screens is kind of redundant in that case. E.g. a Github signin would be done with a button click and a few redirects.
It is truly excellent, especially the fact that you can "move" an entry to an organization, where everyone has the same ownership and rights (and not merely "share" it). Plus a ton of wonderful things.
There are two minor points I am missing:
- the ability to control someone's passwords. Typical usage: the 24/7/365 support for my parents, where I would like to be able to access their passwords (they also would like that, obviously). There would be a simple solution: the ability to force someone to file entries only in an organization. But it is not possible (and new entries will go to the personal vault by default).
- the ability to discard the Android pop-up, sometimes it completely blocks the ability to manually fill in something. An "escape" kind of gesture.
[1] https://github.com/dani-garcia/vaultwarden/wiki/Using-Docker...
Now - I used traefik and caddy extensively (and everything I do is in docker these days) and caddy is so much, much better than traefik.
I used traefik v1 and v2 and struggled with having an optimal configuration. With caddy it just works.
The main difference is that with traefik you usually try to squeeze your configuration in the docker-compose.yaml, but end up with a traefik configuration as well.
With caddy you have everything in a caddy file - in my case adding a service with plenty of things set up (filtering for networks etc. is a matter of adding
https://my-new-service.com { import lan container-name:PORT }
On top of that, the caddy community is great - some questions may seem simple for the ones who are used to proxies etc. but are very hard to understand for the newcomers. There are always kind guidance for these people in the forum.
We fake users inputing text to input boxes and spend crazy time figuring out how to do that and how to get around various sites trying to block that, so the site can still pretend it’s actual user inputting the password. Plus the manager needs to work around arbitrary password rules. Plus they usually don’t work at OS level; so you still need to remember that stupid iTunes password, that stupid Windows password, that stupid Google password on Android login. Plus you still need random PINs in random banks and other systems.
It’s better than memorizing, of course, and slightly better than writing it on paper somewhere (although that’s actually not that horrible honestly).
It’s just, they feel like a patch-fix from 1990s to a problem from 1990s.
I don’t want password manager. I wish I didn’t need password manager.
Say, given a site, create a password as:
HardcodedChars+siteName+len(siteName)+symbolInKeyboardOf(lenSiteName)+len(TLD)*N+hardcodedChars
So gmail.com would be something like
Chad1Gmail5%9Foo@
And then use that algorithm for generating all passwords.
You lost 99% of people here.
Wait was it "TransferWise" or "Transferwise" or "Wise" or "wise" or "transferwise"?
I don't hate the idea, but what happens when you stumble upon a website that does not accept % in passwords, or needs less then 8 characters or one of the other random things that do exist? Then you have an algo for this, and a algo for that, you end up back at the same place.
What happens if you lose your KeePass file?
What happens if your password manager service goes out surprisingly, or gets hacked and someone deletes their DB?
What if, what if...!
Password managers are stupid because the problem they solve is dumb. They act like fake users inputting passwords into little boxes.
I don't know how to solve that issue though. Some single-sign-on? Client certificates? Biometrics? I don't know.
Probably client certificates would be the best option.
But something I've seen is that is making mainstream using private and public keys. We have Client certificates but those are hard to create and use, and not really compatible with mobile.
I think a good workflow will be something similar to connecting to SSH, instead of a static password you sign a challenge with your key pair.
I have a few weeks thinking of replacing the social login (FB, Twt, OAuth) with wallet login https://github.com/amaurym/login-with-metamask-demo
Designate the first to "heads" and the second to "tails". Every time you're prompted to login with a password, flip a coin and enter that designated password. If it fails, then enter the second password.
For those interested in basic cryptography, feel free to point out the major and obvious flaw in this approach.
1. If any of that site is compromised, 50% of your sites will be quickly owned due to password reuse with same username.
2. If someone will get hold of two of your unencrypted strings, they own 100% of your accounts.
- You may solve #1 by creating new password for each site.
- You may solve #2 by encrypting the file.
Voila, you just created your own password manager.
* Things you have (physically)
* Things you are
We have abstracted a thing we know, passwords, to be managed. The alternative could be multiple things we have and things we are.
So a combination of:
* physical objects, such as keys, smart phones, smart cards, USB drives, and token devices.
* fingerprint scanning, palm scanning, facial recognition, retina scans, iris scans, and voice verification, etc.
Remembering this is a chore leading to one of two things - the user tends to create short passwords or mneonics that only change a few letters/numbers per password - the user will use a password manager, completely giving up control in case of a disastrous failure (e.g. data deletion) and having potentially finicky setups.
There should be better options for the broad usership than passwords, but password managers are imho a good solution for today.
- "It just works" for me and my non-tech-family
- It's only $50/year
Maybe BitWarden is just as good or better. But why take the gamble and migrate everything and everyone, when I have multiple happy 1P users for a low yearly cost?
The paying part is when you want to sync key-chain between device and require an iCloud subscription which start at $0,99 and bundle other features.
While I would never trust a "free service" (fremium backed with pro account/bundling is still ok AFAIC), it's still hard to consider $4/month for a syncing service cheap. It's literally the price of a cheap VPS service!
PS: From another angle if security is really your priority maybe $4 is not expensive enough. Password manager don't protect you from an hostile OS vendor and on top of that you now have to trust another entity. High levels of security require a global approach and paying more for a Password manager might provide a false sense of security.
1PW has so many more features on top of Apple’s native PW stuff it is only comparable If the basics are needed.
Not paying for something because it's not free is being penny wise, pound foolish.
For a program I use every day, which is well made and has pretty good UX, the price is in line with other utilities I pay for.
I've tried Bitwarden for a few days with their Firefox plug-in. During those few days there were multiple occasions were it would create a password for me, but wouldn't save the login.
I switched to 1password and it is way better in letting you know if it saved a password or not. I also ran in to some other small issues with the Bitwarden ux that made it less than ideal to use.
I want to like Bitwarden, but 1password just seems to be better at managing passwords.
I've been a BW user for years (relatively early adopter), and they are improving. At the moment I wouldn't consider anything else, for the simple reason that I could host it myself tomorrow if they went closed-source or shut down. For something like secret management, continuity planning is a must IMHO. I think they have been very good at doing things The Right Way since early days. Also 1Password always looked very Apple-focused and I'm trying to move away from that.
So, as I said, I’ve considered Bitwarden for being open source and cheap and for simplicity but despite reading the implementation they do and knowing they have had successful audits the paranoid in my cannot stop thinking on the “what ifs”. I have all my life on Keepass: from access to the bank, to government taxes stuff, to the pi-hole web ui etc etc. I feel I have more control now with my clunky approach. If I migrate to a managed solution and for any reason my data gets compromised on their side I would be utterly fucked.
Probably it’s just me being irrational.
Even if KeePass turned out to have some expoloitable vulnerabilities, it's still running solely on my machine, and I don't allow it to connect to the internet at all. I suppose yes, if someone breaks into my computer I could be in trouble, but if they can do that, they can just steal my session cookies anyway, password manager or not.
I've been looking for an alternative to Enpass, which:
1) Supports using WebDAV as a backend (or an "app" exists for Nextcloud, if one exists).
2) Supports biometric authentication on Windows and Android.
3) Has a client which unlocks off the system keyring on Linux (Enpass doesn't do this).
4) Uses in-line autofill (through the Keyboard) on Android. Enpass said they'd add this month's back... but never did.
5) Has a not-ugly UI which at least partially matches GTK/Qt on Linux, Fluent on Windows, and MD2/Material You on Android.
6) Has Chrome and Firefox extensions that "take over" as Autofill like the Enpass extensions do (you can see it in Chrome Settings -> Autofill, if an extension does).
I don't mind if it's paid, as long as it isn't relatively expensive (i.e. no more than Enpass because I got that on discount).
I'd highly recommend it in case anyone here's looking to switch to Bitwarden.
I've used LastPass previously, but that was so long ago that it'd hardly be a fair comparison to Bitwarden now - but I remember not being satisfied with LastPass enough to export my data and switch.
I tried to use Vaultwarden implementation with one caveat: I don't need to use any plug-ins - my everyday passwords are at my fingertips anyway, for anything else I'm fine with logging in and copy-pasting the login and password.
And here comes the thing which makes VW (and a couple of other password managers I tried in the last couple of years) usage abysmal: the web-interface just sucks.
First of all - the process of adding a new login-password info requires too many clicks to set something more than just a login, password, (web-site) address. You want to add some tag? Click 'add', click 'type', click to the value field, type in. Want more than one tag? Repeat for each one. Okay, that would be tolerable if this was just once in a while task, but here comes the next one:
Second and more important - awful search. VW just doesn't have the search functionality. It just loads ALL your accounts and filters them in the UI.. and sometimes even fails to do that. Like I see '$something' in the account description, type it in the 'search' field.. and have an empty result.
For me personally the lack of useful search (including server-side search) makes the thing unusable.
Are my requirements (sane web-gui, working search, usable without browser/apps addons) unreasonable?
> It just loads ALL your accounts and filters them in the UI
Server-side search would only work if you decrypt the data on the server, which is explicitly not wanted.
Or do not store it encrypted (aside from passwords) in the first place, or have a separate server-side encryption for non secrets, so it would be still encrypted at rest.
It is all understandable, yet I don't have an option (except using almost a decade old RatticDB).
To auto-fill login information, use the following default shortcuts. If there are multiple Login items with the detected URI, the last-used login will be used for the auto-fill operation. You can cycle through multiple Logins by repeatedly using the keyboard shortcut:
On Windows: Ctrl + Shift + L
On macOS: Cmd + Shift + L
On Linux: Ctrl + Shift + LIt doesn't need to be automated, if I can tell it which HTML element to read and parse as an index and which text elements to fill in, then that's good enough for me.
Generally, I would really like a hardware password manager. Maybe in a chip that you can have in your body. With some MFA so no one can use it when you are dead or passed out.
I liked Bitwarden so much I asked them if I can pay for it several years in advance. No dice there.
My recommendation is to pair Bitwarden with Yubikey.
Another few comments have said BW sometimes loses track of a pw or login. Maybe when created?
Not sure. Is this stuff not true? I’m on a family plan for 1PW and it has been mostly flawless for me. However if that family plan ever breaks up, i would love to BW
- history
It’s saved me enough times that I can’t move to a manager that doesn’t record history.
I see it doesn't have history anywhere else, such as secure notes, which 1password does have.
Might still be too tough to give up the extra types and tags, but having history on the passwords is a great step. Quite tempting indeed.
> Q: I need an old password! Can I view the history of a password that I changed in Bitwarden?
> A: Yes! You can view the last 5 passwords for any Login Item. Open the item in question and select the “1” next to Password History near the bottom of the window.
Updated: 18 May 2020, 16:22:44 Password updated: 18 May 2020, 16:22:44 Password history: 1
I was using KeepassXC, but I liked the the TOTP backup/share with partner functionality and iOS strongbox app.
I attempted to set her up with her own database but it's difficult to manage accounts that we both share in two separate databases.
Most people do not add passwords often, so that works just fine.
You also can have multiple database file, one for the common shared password which is always read only synced from a single source. And one for local passwords which are not yet, or should not, go into the shared database.
bitwarden:
container_name: bitwarden
networks:
- bitwarden
image: vaultwarden/server:latest
restart: always
environment:
SIGNUPS_ALLOWED: "false" # Set to true when making your accounts
DOMAIN: "https://bw.domain.nl"
WEBSOCKET_ENABLED: "true"
# ADMIN_TOKEN: "SomeTokenForResetPurposes"
volumes:
- ./bw-data:/data
labels:
- traefik.enable=true
- traefik.http.middlewares.redirect-https.redirectScheme.scheme=https
- traefik.http.middlewares.redirect-https.redirectScheme.permanent=true
- traefik.http.routers.bitwarden-ui-https.rule=Host(`bw.domain.nl`)
- traefik.http.routers.bitwarden-ui-https.entrypoints=websecure
- traefik.http.routers.bitwarden-ui-https.tls=true
- traefik.http.routers.bitwarden-ui-https.service=bitwarden-ui
- traefik.http.routers.bitwarden-ui-http.rule=Host(`bw.domain.nl`)
- traefik.http.routers.bitwarden-ui-http.entrypoints=web
- traefik.http.routers.bitwarden-ui-http.middlewares=redirect-https
- traefik.http.routers.bitwarden-ui-http.service=bitwarden-ui
- traefik.http.services.bitwarden-ui.loadbalancer.server.port=80
- traefik.http.routers.bitwarden-websocket-https.rule=Host(`bw.domain.nl`) && Path(`/notifications/hub`)
- traefik.http.routers.bitwarden-websocket-https.entrypoints=websecure
- traefik.http.routers.bitwarden-websocket-https.tls=true
- traefik.http.routers.bitwarden-websocket-https.service=bitwarden-websocket
- traefik.http.routers.bitwarden-websocket-http.rule=Host(`bw.domain.nl`) && Path(`/notifications/hub`)
- traefik.http.routers.bitwarden-websocket-http.entrypoints=web
- traefik.http.routers.bitwarden-websocket-http.middlewares=redirect-https
- traefik.http.routers.bitwarden-websocket-http.service=bitwarden-websocket
- traefik.http.services.bitwarden-websocket.loadbalancer.server.port=3012
- traefik.http.routers.bitwarden-ui-https.tls.certresolver=mytlschallengeOn the other hand, Bitwarden lets you self-host a complete server that handles everything. If you want something less resources intensive you can take a look at Vaultwarden which is a re-implementation of the server in Rust instead of C#. The main advantage is that it uses MySQL or Postgres instead of the heavy MS SQL Server.
I personally don't.
Sure I have a password manager on my phone, but it only gets a small subset of my passwords anyway. Similar any password I add on my phone is very likely to be somewhat irrelevant mostly throwaway.
{Bit,Vault}warden} both now support emergency access which will be useful if it's ever needed
Apart from that bitwarden is just wayyy easier, you simply tell the (official) app the URL to your vault and it's basically good to go. You don't have to worry about synchronization one bit. The app is also fairly nice and has all the features you need. Bitwarden also does the browser integration well, unlike keepass where it's a major pia.
Isn't the self-host server (Vaultwarden) also 3rd party?
You are implying that this is a problem, but KeePass actually explicitly supports this and merges your changes. I've been using KeePass like this for many years and never had a problem editing the database from multiple devices.
I had that problem on iOS, and it disappeared since I moved to Android. There is probably an issue in what they are (not) allowed to do in background on iOS.
Could it be that you weren't using it correctly? KeePass database files aren't supposed to remain open (for security of course) and it has quite a number of options to automatically close it after certain amount of time or when the window isn't focus, computer is locked, etc. This would trigger a sync with the (NC) server and assuming that all your clients follow the same usage pattern and close the DB after a small window of time, there shouldn't be any conflict.
> NextCloud to be always up of course, also self-hosted
You could use NextCloud's own hosting. But then Bitwarden's server needs to always be up too, and optionally self-hosted.
> Bitwarden just works
A low bar to recommend a password manager, don't you think so?
For me BW has always just worked, meanwhile I have several KeePassXC dbs with a date in their name because of conflicts. Which arguably is because of NextCloud issues, which are my own "fault" (issues include, on work PC file sync services are not allowed, on Server somehow NC disconnects after every container update, since it is "headless" I often notice this very late, the shitty state of NC client packaging on Ubuntu will let you install very old clients that may stop syncing, you need to be aware of this... etc). Perhaps KeePass(XC) just works if you outsource syncing, but then still, it is easier to have sync conflicts than with BW.
And then there is the ability to share PWs with relatives with a BW account on the same server, KeePass does not have this concept as far as I am aware.
KeepassXC on the desktop 'Keepass2Android Offline' on android Keep my database in dropbox. Keep things synced on Android via Dropsync.
I know it's not a self-hosted solution, but I think dropbox as a sync solution in this particular case is a pretty good solution for personal use.
There's an alternative implementation of the server API called Vaultwarden that works nicely with all the frontends but is unofficial.
If Keepass works for you, you're likely not gaining much from switching. They're both just password managers at heart.
Features I need:
* Cross-platform (iOS, macOS, Windows)
* Easy to use browser plugins (the LastPass safari plugin is awful and non-discoverable via Safari plugin search)
* Autofill in browsers (Safari and Firefox) and mobile (iOS)
* Internet-based sync (I don't really want to manage my own backend)
Nice to haves:
* Account creation detection
* TOTP
* Yubikey support
* XKCD-style password generation for passwords I want a shot at remembering
I am not sure about all the nice-to-haves you have listed but it definitely supports your last point.
The combination has all of the features you mentioned including xkcd password generation & Yubikey.
Only downside is that the desktop extension requires the app to be open in the background. For that, I have the app minimize to system tray so it isn’t in the task bar.
Strongbox settings menus are an absolute disaster to learn, but it has extensive customization. Make sure you only give the app 32mb of memory or autofill will crash.
I read a few comments from people that this was a classic LogMeIn move where they buy a service, hike the price and squeeze out everything they can before slowly letting the service die off.
I'm happy to pay a reasonable price for services and bitwarden's $10 price (the old LastPass price) shows that's the reasonable price.
Thanks to the Bitwarden-Team.
Bitwarden sucks, but sucks the least. Make sure you self-host using vaultwarden, the people at the Bitwarden company are clueless about security.
Maybe a misunderstanding on my side on why they differ. Can someone care enough to explain this to me?
That's what LastPass is, which is why they were holed multiple times. Turns out it's quite hard to implement a secure key-value store.
Hacker news was about cool hacker or personal project. This is a company advertisement.