The only thing I miss is an "add to bitwarden?" dialog when I sign up somewhere. Their docs say it exists but I've never managed to get it to appear :-)
I have seen this occasionally but it is fairly random and unreliable. And then sometimes it pops up for stuff I clearly don't want to save, like OTP.
With bitwarden I never missed the "add to bitwarden" dialog. As a paying user. I love that they offer Android app. It has its moments like the integration with keyboard does not always work, but I can use it from the shot it's drawer.
If you generate passwords (or passphrases!) they are stores 8n history, so there's always a backup :)
I've found keyboard integration really hit or miss on Android. On iOS it does quite a bit better.
It's pretty business unfriendly IMO, as most users simply cannot pick up a new, rarely used flow.
I switched away from 1P after they dropped the perpetual license option. They failed me by taking VC money and then chasing growth at users' expense. Not that the other PWM vendors aren't worse -- some of them much worse.
So I went on to add a new entry manually. Oh my, the UX to do so is quite bad. There is such low hanging fruit here for improvement, like copying the "UI on a new tab" style that LastPass does... meanwhile Bitwarden insists on doing everything on a stateless pop-up window [0]. LastPass UI might be worse for some (that's debatable), but the UX of opening it on a new tab is simply superior, just for the fact of it being stateful. I don't get why Bitwarden doesn't adopt it.
I'm happily paying for Bitwarden to support its development, but would never consider suggesting it to my grandpa or to serious business. The flow and experience is just far away from what is expected; a very good software, but with still too many rough edges.
[0]: https://community.bitwarden.com/t/persist-bitwarden-ui-and-m...
It doesn't work very well in Firefox's private browsing. Only thing you can do is autofill by right clicking a text field and autofill from there, or the keyboard shortcut. But you cannot unlock it in private browsing.
Stateless UI is annoying at best. There's a few times where this has slipped my mind, so I paste a generated password in a new item, and then go to copy the email, and the new item is gone. If I didn't use a clipboard manager, this would have meant losing the generated password.
The browser addon is completely separate from the desktop app. It's annoying as it means you have unlock them separately when you need them. I used to be a 1Password customer, and I absolutely adored the seamless experience of the browser extension utilising the desktop app when it's installed.
[1] https://support.mozilla.org/en-US/kb/extensions-private-brow...
https://github.com/bitwarden/browser/pull/2121#issuecomment-...
[0] https://github.com/bitwarden/browser/pull/2121/commits/9d81b...
[1] https://github.com/bitwarden/browser/issues/136#issuecomment...
>Stateless UI is annoying at best...
Agreed. I've been using Bitwarden for ages now and this drives me insane.If you open the popup menu and need to copy/paste/refer to more than one piece of info from it [because autofill doesn't always work or for example, you need more info to login than just username & password] you have to go back each time and re-open the menu, then the sub-menu [if you have more than one account info saved for a domain], to re-find the saved info and copy the next item.
It's made doubly annoying by the fact that there's a button to open the popup in its own mini-window, which allows you to go back and forward to that window, copy/pasting all the 'stuff' you need. However, when you click this button, the new window which opens doesn't retain whatever was in it in its popup version. So you still have to drill down through menus to find the appropriate info again.
I reported this as a bug several years ago on their Github and got a ridiculous reply from the developers, saying that behaviour was deliberate and wouldn't be changed. Apparently they couldn't envisage a situation whereby a user converting the popup menu into a separate mini window would actually want to retain the info therein, rather than having to search it out again.
When faced with total pig-headedness like that from developers, my natural support for their open source efforts evaporates pretty quickly.
The search function is also piss-poor. I've got several Gmail accounts and quite often a site will allow me to login using my Google account. Obviously that won't show up in Bitwarden's popup, as I'm not on a Google domain. So I type 'gmail' into the searchbox and it returns every single one of the 100s of websites where I've got an '...@gmail.com' username, rather than prioritising the Gmail logins which I've actually saved titled 'Gmail <account name>'.
So yes, it's great that it's open source and free [for private use]. But the usability is pretty poor and the developers unresponsive to feedback.
Oh. And incidentally, it barely ever works properly on Android --even with all the required settings and permissions allowed. I might as well keep all my passwords in a text document on my phone. It'd be quicker than waiting in vain for Bitwarden to offer to fill in a login, then opening the app itself to copy/paste the required info and waiting the several seconds while it creaks into action, decrypting my vault.
I switched from Lastpass when they started demanding more money - and whilst not perfect, am very happy with Bitwarden. Functionality is all there, just a bit clunky in places - but you get used to it.
It's not that hard even; we did that for our login form. Works great with Bitwarden. And on mobile too. But you have to know how to name things so that password managers can do their magic.
Frequent mistakes caused by essentially ignorance on this front:
- Splitting the email and password form across two screens. That somehow became fashionable. There are ways to do this and not break password managers. But why do this at all? Having to click the fill button twice is ugly and should be flagged as a bug if you ever see that. There's no need for that regardless of the UX.
- Having a login form but then not using field names like "email" and "password" that a password manager would recognize as such. There are a few more things you need to think about: https://hiddedevries.nl/en/blog/2018-01-13-making-password-m.... Just do it right.
- Not having password managers on the radar as a thing that the UX MUST support (not optional). Non technical people like designers and product owners tend to be a bit sloppy with their own security and they won't necessarily even be aware this is a thing that they need to worry about. So, they don't notice when it doesn't work. They probably don't even use a password manager themselves. And they certainly won't test it.
- Developers not caring enough to do anything about this unprompted; by e.g. just raising the topic with their PMs or just implementing things correctly to begin with. I've actually brought up this topic and usually this is not controversial at all and simple to resolve.
And it's hard to figure out why it doesn't work when it doesn't. The feedback cycle is nonexistent.
Just wanted to note that Google handles this right, which I've always appreciated.
They have two-screen login, and if you use a password manager, the password is prefilled when the second screen loads.
I assume the two-screen login is to ensure the name is valid before asking for a password. Without the clunkiness of doing it "onBlur".
This is done because it's an easier way to support both local login and SSO(like oauth or saml). By taking the username first you can determine whether to ask them for a password or send them to a sso provider.
It doesn't have to be implemented this way but it is seen as easier.
Also, a typical opendid flow or SSO would not actually require an email field at all. So splitting the screens is kind of redundant in that case. E.g. a Github signin would be done with a button click and a few redirects.