There's a nice migration guide here: https://support.1password.com/import-lastpass/
Which means you have to secure it. That's something a lot of people will not know how to do properly, and an insecure server with Bitwarden exposed to the public internet may turn out to be worse than trusting e.g. 1Password. Just something to keep in mind when making that decision.
https://bitwarden.com/blog/new-deployment-option-for-self-ho...
- Where do you host all that? If on your home network, then your availability is probably not going to be great. Sucks to be travelling and unable to get to anything because your Wireguard Raspberry Pi died, so you need to make sure you don't need that. If using a cloud or other IaaS you run similar risks to 1Password etc., same with "conventional" root server hosters. If they get owned, you may too.
- How secure is your domain name? DNS? Your app may not warn you if the server answering isn't the one that answered yesterday.
- Is your OS hardened? What else is running on your critical machines? How do you keep everything updated, OS and the actual applications?
- How do you keep abreast of zero days and critical issues in the exposed components?
- How do you know when automatic updates fail? How do you know you've been compromised?
- Do you keep all your machines on the same network? Can a smart lightbulb be an exploit vector?
- What about machines that access Bitwarden or whatever directly – how secure are those?
- What will the whole thing cost, both in terms of time and money? What about upskilling?
- If you manage this for others, which is something that cloud services excel at, with rights management and the like: Are you ready to admin this for the long run, do "customer" service, etc.?
Not saying everyone will need to have cover all those bases, or that you couldn't or wouldn't just take some risks, but if the aim is to get better security than e.g. 1Password with their security teams and posture, then it's worth to at least try to have a complete picture and make conscious decisions on them. What needs to be covered will depend on a lot of factors, including how exposed you think you are.
There may not have been any mass-takeovers of badly secured domains, but we've seen during the Log4J incident that a lot of people believe not being listed on Google means their services cannot be discovered only to find they're getting hammered with attacks, and that attackers have levelled up their capabilities a lot, with large-scale and surprisingly well-engineered attacks springing up pretty quickly. That trend will likely continue and that combination of very capable attackers perceived as incompetent and lots of false assumptions about the actual risks is pretty dangerous; a lot of people will not realize how exposed they are because HTTPS==secure, right?
That no one has targeted self-hosted Bitwarden instances on a large scale so far is no guarantee that no one ever will. People are presumably trying to breach 1Password all the time and so far they seem to hold up well, though LastPass hasn't. What risk is bigger? That a homebrew setup is falling to an untargeted mass exploit? That someone will target you with something more sophisticated? That 1Password is breached and keeping data they say they don't? That LastPass keeps data they everyone assumes they don't but never publicly said they don't, and get breached? If anyone knows, I'd like the details of their analysis, because to me it doesn't seem straightforward at all.
I really dig the 2FA auto-copy to clipboard feature in bitwarden.
Yet another fine reason to use 1Password, which puts a lot of time and attention into user experience stuff like this. I know Bitwarden is the Internet's darling, but holy hell the user experience is so aggressively bad
Bitwarden's previous(?) on-premises deployment script was a raging tire fire, which I openly admit is not exactly a _security_ issue, but it further lowers my lack of faith in them
With all that said, I think both Bitwarden and 1Password are miles and miles ahead of LastPass, so one will for sure be better off just picking one and trying it out. It seems to be a reversible decision, if you wanted to switch again
Thus the advantage goes to 1Password here, since Bitwarden does not require that "second factor" known only to the client (and I'm not talking about 2FA for logins, I mean for the vault)
is that if you're using bitwarden's 2FA authenticator instead of e.g. authy?
I've used various clients with the keepass db format for years now and have not yet been disappointed. Browser integration, Windows, Linux, Mac, and Android clients, open source, encryption I (naievely) trust... ticks all the boxes for me.
They also have incredible support (browsers, iOS, apps, etc...)
However there's an open source reverse engineered server, called vaultwarden (previously bitwarden-rs) that is indeed in Rust and quite slim.
Both can be used with the official clients (which are also open source).
Besides that, yes, Bitwarden is amazing.
Does it work if you have apple devices and also non-apple devices?