But honestly with all the updates I'm putting off I'm probably actually more at risk, and a good password manager implementation will encrypt all passwords client-side so you're not actually uploading your passwords to anyone's computer.
To access your account you need to type your master password, the same password that is used decrypt your vault. If a competent hacker gains access to the Bitwarden servers they could install a compromised login page that logs master passwords and with that gain access to password vaults.
Sounds far-fetched maybe, but your password security depends completely on the ability of Bitwarden to protect their servers. The encryption is just a minor hurdle once the servers are compromised.
Note that 2FA doesn’t help since it is not used for vault encryption.
First-party end-to-end encryption is broken by design, especially in the presence of auto-updating.
The caveat being: you have to manually copy over any credentials from Bitwarden to Keepass, which is time consuming but one day maybe worth it.
pass-import works pretty well; create an initial empty KeePass DBX file first and keep a copy to re-use, then one can re-run pass-import to import BW to a fresh KDBX on a recurring basis with a simple script.
There's a self-hosted alternative, but even so, I'd trust them to handle server security better since, since it's their speciality.
I'd suggest adding Yubikey as 2-factor, then anyone would need that physical key to login.
Personally, I've used it since lastpass made people pay for multi-device access. You can treat it like a git repo that's encrypted at rest. Client implementations are pretty quality in my window of experience (on linux+ff, mac osx+ff, iOS+safari).
The security problem reduces to "how do I securely store a private key that I use every day", which is a well-understood problem with a well-documented set of solutions.
There's no desktop autofill or autotype and no SSH key management.
That said, I use KeePass on Windows and Android, sync my safes once a month/as needed, and call it a day.