Bitwarden: Free, open-source password manager
bitwarden.com
bitwarden.com
I tried teaching my father to use Bitwarden for the sole reason that it seemed to be translated into my native tongue. In his use, Bitwarden turned out to be completely unreliable. As techies, we stop noticing the little glitches, the times when Bitwarden is unable to auto-complete, or to detect a login that needs to be saved. Or the times Bitwarden logs you out of the account, or fails to use your biometrics in the browser because the app is no longer running in the background. Or the management UX of the app that's terrible. For us, these are little annoyances, but for my father it was the difference between usable and unusable.
The individual plan is very cheap, but the family plan is costly. And you can self-host, sure, but it's expensive to self-host.
When talking of self-hosting, people actually mean the alternative built from scratch in Rust (vaultwarden). Well, that project was never audited to my knowledge. Open source or not, it may have security vulnerabilities that could be exploited remotely, and I don't understand how people can trust it.
Bitwarden also took VC investments. Which is fine, I guess they need to grow, but I'm longing for projects that are owned by sustainable businesses that don't need to grow. Why does everything need freaking VC investments? The problem being that startups that took such investments are not trustworthy to be around in another year from now, sorry. Although this is true of 1Password as well.
Before, I used LastPass, and for me, the form field detection was miles ahead. Not a tiny bit, but _a lot_ better. And the UI built on the ephemeral pop-up was a very bad idea that after years and years they haven't decided to ditch and do it the proper way on a new tab, like LastPass, uBlock Origin, o TreeStyleTabs do.
I use both. It’s far from “miles ahead”
I use BW for my personal use with my SO and 1P at work. I hit some errors in 1P that were crypting, stuff like "Failed to add this record" with no details, no help button, I had to fire up the chrome console for the extension to find out it was a 401 to our 1P portal. Very poor experience, probably related to our SSO setup but still.
Never had any weird issue like this with BW and I love the autofill shortcut and the absence of a popup when I access a password field like 1P.
So yea, YMMV as usual but definitely not miles ahead.
FYI, 1password has taken almost 1 billion dollars in vc investment. They have an obscene amount of pressure to grow.
Cloud password manager functionality can be accomplished in 6U of server space. Vault files are measured in kilobytes or megabytes, millions of customers could be handled by a single SSD RAID and a fast Xeon. Infrastructure and software to make it secure, reliable, and user friendly, add expense but not 9 digits of it.
Your app, the detection of forms (when total idiots try to prevent password managers being used), the security audits, active intrusion detection, etc... those are yet to be handled by an AI, so these cost a lot.
There are small issues with autocomplete on mobile here and there, which I have never seen a password manager do a perfect job at. Otherwise I have never had any issues with BW and the 2fa on the paid tier is great.
My home server costs me about 3 euro per month in electricity (and it is quite beefy for a home server) and it runs many services, not just Vaultwarden. Add homeassistant for smart home, nextcloud for document cloud, jellyfin for media, immich for photo backups, etc. Maintenance using docker and compose is also trivial task.
On top of that, it runs in a private network and has limited exposure to the outside world though VPN in case you need to access it away from home.
Yes, hosting a single service is more expensive, but hosting a bunch is much much cheaper.
Infrastructure costs are not just AWS / DataDog / OpenAI bills.
I could barely understand it myself let alone explain it to our lowest understanding employees.
1Password last I used it, asked for a master, and a secret extra password. I still cannot explain why.
Granted my setup was for corporate but I am pretty sure it’s the same for everyone.
My best guess is that they are trying to cover for weak masters in the way that LastPass was enforcing but failing to update their PBKDF2 interations.
Which IMO is stupid and a failure to enforce best practices at the user’s first input.
Nope. With that, you've quite literally convinced me to not just avoid it forever, but to also recommend others do the same.
VC investments means "they're gonna want money back at some point," and the service they provide is too important to have that hanging in the air, especially given how badly MANY other VC backed things have screwed things up.
You've effectively told me, there's a serious, if not likely, chance that they will at some point screw me and my passwords over if I don't pay them ransom (or engage in some other similarly drastic behavior that I haven't even considered yet)
Kill this garbage now.
Meanwhile everyone stopped wearing wristwatches except as a fashion statement. The original company would have survived this easily but the VCs wanted the next Apple or bust.
Exactly my experience. When 1Password announced the shift to a crummy Electron app, I evaluated all of the major password managers, plus some less major ones, such as Strongbox. Even with the UX degradation of 1PW 8, it's still clearly superior to the others, to the point it's really not a contest.
I stuck with V7 until just a few weeks ago, when other circumstances necessitated an "upgrade". I once again evaluated the others, including Bitwarden, to see if they were "good enough". Bitwarden's UX hasn't improved as far as I can tell; more importantly, it refused to import my secrets because I had a secure note that was too big for it. Not "refused to import that note"; refused to import anything—there's no skip option. I had to do a bunch of manual nonsense, which still left me in an incomplete state because I both need that note and want it in my vault (splitting it into multiple notes is an option but also an ugly kludge).
If I selfhost i want to not have to manage all my services with individual logins. Selfhosting with e.g. Authentik to provide SSO and identity management is really a perfect solution, but alas so many projects lock SSO away in their enterprise edition (good on psono to not make it ridiculously expensive like often is the case).
I share this frustration. Putting aside the ambitions of founders and initial investors in order to address your question about "everything"...
I think it comes down to tech being perennially talent constrained. It might not feel like that right now after a year or two of big layoffs, but every time that has happened, another long hiring boom has started within a couple of years.
If there were enough competent engineers (in this case, ones that aren't going to get the company in the news for things like cryptography mistakes or sloppy data handling), then that would change all of this. But there aren't, so these companies are left competing for the scarce talent.
You need a large pool of resources for that competition. VC money (eventually replaced by liquid stock grants) is often the easiest source of that. So, VCs can help a company keep and add talent, but in return they want hypergrowth.
But Google is so much more convenient.
I still wonder why there's no completely P2P password manager using SyncThing plus a layer of encryption. We have this near perfect tool for making multidevice apps but we don't use it for much!
https://www.passwordstore.org/
KeePassX works fairly well with syncthing as well, if I remember.
I've heard KeePassX can have sync conflicts if you edit on multiple devices with the wrong timing.
I think for a real conflict-free experience you'd need to put each password in its own file, or give each device a logfile to publish CRDT updates with cr-sqlite(Looking into adding that to a baserow style app).
This happened to me too. Moved to KepassXC with syncthing and I haven't looked back
So many comments are of the generic nature, "<COMPETING PRODUCT> is miles ahead", without any specifics on what that's supposed to mean. My last few employers have used LastPass and 1Password, while I use Bitwarden for my personal stuff, and I prefer the latter by far.
The browser plugin is more reliable about recognizing when I'm entering or updating a password, and offering to store or update it. The iOS version has smoother integration with password autocomplete in other native apps. It MAY be that Bitwarden lags behind in "team" sharing features, I don't know. For personal use, that class of use cases is irrelevant to me.
As near as I can tell, there seems to be a lot of HN rage that "most" of Bitwarden is open source, but there are still some proprietary bits that keep it from 100%. I never understand this mentality, that software should fall from the sky like manna from heaven and not support a business. I also don't understand why these resentments never seem to stick to products like VS Code, that are the exact same way. Maybe Bitwarden should just try a sexier-looking dark mode UI?
I just have a rule that if I can get 80% of the same features with an open source solution I'll use it, even if it's not "the best."
At some point, the pressure to aggressively monetize will unfortunately happen.
https://techcrunch.com/2022/09/06/open-source-password-manag...
That's not the type of service I thought I was using.
I looked up their headquarters in Santa Barbara and it's a co-working space. That doesn't sound very secure. Though that could be their corp address and they're hiding where they work.
This sounds like ageism to me. I don't know if this guy is any good or not, but calling out someone as a 'concern' just because they were successful in the past isn't a good look. Is there anything more substantive behind your concern?
Kyle Spearrin is still at BitWarden and is listed as the Founder & CTO: https://bitwarden.com/about/ It looks like he lives in Jacksonville, FL and has a lot of hobbies.
Maybe this is some internalization, but thinking about another engineer referring to me, pejoratively, as a "web 1.0 engineer" would probably leave me confused. Am I supposed to be ashamed I played in the early days of the web?
A strong negative signal as far as I am concerned.
For a consumer-oriented software startup, an “exit” is most of the time a polite euphemism for selling the userbase to a juicing machine of some sort; the second place is taken by selling the product to an enterprise-oriented business which doesn’t want the userbase and eventually will, with more or less grace, show them the door.
Therefore, when I see a consumer-oriented, VC-funded startup, I don’t see why I should consider trusting them for even a second. Dine on the free lunch while it lasts, yes; squirrel away every bit of software they’re willing to release, yes; trust, depend on, or invest even a tiniest bit of my time, no.
Based on the interview I linked BitWarden is going down a venture of trying to offer vault-like enterprise secrets management on top of BitWardens tech, which could mean they're trying to monetize the more enterprise side of their business.
Web 2.0 replaced Web 1.0, right? Is that because Web 1.0 was better or just as good? Or was that because Web 2.0 was an improvement? And we're a good decade or so beyond Web 2.0 now. Surely you're familiar with the term dinosaur in this context. Web 1.0 are the dinosaurs.
If you still think web 1.0 doesn't have any negative connotations there is nothing I can say to change your mind. But I strongly disagree.
Tim Berners-Lee invented the web 1.0 when he was in his thirties in 1989.
Tim O'Reilly and Dale Doughterty, both in their 40s, coined the concept of Web 2.0 in 2004.
Tim Berners-Lee, then in his 50s, coined the semantic or executable web aka Web 3.0 in 2006.
Web 4.0 has no known origin, but the chase for artificial intelligence and machine learning was led by many of the same people from Web 1.0 from engineers to thought leaders. Many of the people who were building back then are only now beginning to peak in their careers. Not to mention, the guy you're talking about would be "Web 3.0" because the company he founded was in 2007 - pretty much the year cloud computing started.
I think, sadly, you're incredibly far down the rabbit hole of ageism.
Ref: https://ijcsit.com/docs/Volume%205/vol5issue06/ijcsit2014050...
That doesn't make me wrong.
Is it ageism to say I'd rather have a 23 year old baseball player than a 60 year old one? What about a 23 year old model instead of a 60 year old model? Ageism? Ok. Then I'm an ageist. I'll take the 23 year olds.
'But being a model or a baseball player and working at a tech company are not the same thing'
Ya, I know. But the point stands. Crying ageism doesn't make you right or the person appealing to age wrong.
Yeah, it does. Just like racism and sexism, being ageist is wrong. You should really re-asses how you look at the world, because your current view stinks.
> Is it ageism to say I'd rather have a 23 year old baseball player than a 60 year old one? What about a 23 year old model instead of a 60 year old model? Ageism? Ok. Then I'm an ageist. I'll take the 23 year olds.
There are 60 year old models, what is wrong with that? Only somebody who is ageist thinks somebody can't be model at 60. As for the baseball player, they are not discriminated by age, but by physical condition. If a 60 year old player could have the same physical impact as a 23 year old, then why not?
When it comes to the industry we're in, physical condition is not a discriminator. We are knowledge workers. Older workers tend to (not always) have much more knowledge and experience. Which is why they are paid more and end up in leadership positions (as in this case).
Your comments assume that the guy stopped learning in 1989. How do you know that he's not keeping up with the times? How do you know that he can't understand the modern world, as you imply? And do you even know what it means to be an executive? It doesn't mean knowing all the latest features of the React. It means setting a strategy (with fellow executives) for successful growth of the business. These things are as old as time (well, as old as capitalism). Having a talented CTO paired with a shrewd/experienced CEO is a good setup. It doesn't guarantee success, but it's more likely to succeed than with inexperienced executives.
Here's another way of looking at it. Replace "old" in your original sentence with "black", "woman", or "gay":
- Now it's some black Web 1.0 guy who was the CEO of eFax in the 90's.
- Now it's some Web 1.0 woman who was the CEO of eFax in the 90's.
- Now it's some gay Web 1.0 guy who was the CEO of eFax in the 90's.
How do those sentences make you feel?
Your comments are ageist and you should realise that discrimination is unacceptable. It would be wise to stop digging.
You can try to poke holes in that with whatever isms you want, it's still true. And I'm not alone.
We don't really have a HQ since we are a 100% remote company.
Source: I am the Bitwarden founder.
I'm just a normal tech-lover guy who works in the marketing field. I have made my family & 2 agencies switch to Bitwarden and they all love it.
I have stored more than 400 passwords and more than 30 debit + credit cards in it. Though I don't need a paid plan but I'm paying $10 per year just to support the developers.
As a long time user, I'm a bit concerned as well.
Bitwarden is and has been monetized since the beginning. There are no plans to change how we monetize our products. It's working well for us.
You know, how you don't just save all of your life for a house - but get a mortgage and enjoy a house now, not in 50 years.
Until 2 years later there is a license and pricing change. One that will make it 10 times more expensive - or the free/open-source version will be crippled.
FWIW: I've been using this application for the past years. I pay 12 USD or so a year, though I self-host. I just pay as a thank you since I still use the FOSS client, and the price is very reasonable.
1Password is hardly even a competitor as it is a completely different price range, and different product. It isn't FOSS at all, there's a vendor lock-in (in contrast to Bitwarden), and it is 3x as expensive at the very least. They're miles apart.
:)
Nothing. Nothing of consequence; either way. You know, maybe that’s why?
That’s a bit worrying.
The $10/year individual plan wouldn't warrant $100M investment. But going after big companies who are going to commit to $X/year/employee or similar kinds of pricing packages might, especially if Bitwarden integrates with existing corporate directory systems and such for delegating and managing accounts.
Surely this is the inherent benefit of using open source?
I even pay for Bitwarden and it's been great with its back-to-basics UI that just works, and not crushing page load performance with the Chrome plugin.. But 100M is a huge sum and we saw how this turns out.
If you had a growing popular product like this, why on earth would you raise that amount of money? This isn't a rhetorical question btw! I would honestly like to know the rationale here?!
Another concerning realization is how sparingly encryption is used in (many) modern password managers. Sure, it makes search easier but it also leaks secrets stored in metadata fields without any disclosure to the user. And this is in the single-user setting! There are vastly more security considerations as soon as a common "workspace" is involved.
All that to say, every time you hear someone talking about this, it's not because they want to talk crap about Bitwarden, it's because they are afraid of getting too sucked into yet another product that works well, only to have to leave when the company's leadership loses focus. Largely because they received pressure from investors trying to 10x their investment in the short term when they could have received sustainable dividends over time.
https://techcrunch.com/2022/01/19/1password-series-c-funding...
At a certain point, you just have to live your life. To accept that products you use might change in the future, and you might need to migrate to something else down the road.
The alternative is just keep something like KeePass around on a thumb drive, and forgo all the cloud sync, and browser and native app autocomplete integration. But those things are really the main point to all these products. Without that, I would argue that you're better off with a pad of paper in your desk drawer.
Bitwarden server is dual-licensed [1]
- part of it is licensed with AGPL (Open Source)
- some features are licensed with a source available Bitwarden license
Now, even the Open Source core requires you to register if you want to self host. This is to provide you with complementary services like security updates, push relay servers (?), and licensing checks. [2] Although not stated in the docs, I guess this also improves their telemetry data, as they suggest to never share the license keys between installations.
I completely understand the need to use source available licenses instead of open source. What I don't understand is why to even license parts of your app as Open Source? The resulting product is not free. Neither as in beer, nor as in speech. Does anyone know good reasons for doing that? I'm asking seriously. I'd like to better understand how companies benefit by marketing their products as Open Source, even if they are barely open source.
[1]: https://github.com/bitwarden/server/blob/master/LICENSE_FAQ....
[2]: https://bitwarden.com/help/hosting-faqs/#q-what-are-my-insta...
The rest of Bitwarden is free both as in beer and as in speech. Dunno why you think otherwise. Vaultwarden exists, and Bitwarden clients are compatible with it.
Bitwarden is not free as in speech, as it requires me to register with Bitwarden, Inc and get a license key to be able to self host. Also, then it uses some closed cloud services.
As for the free as in beer - this is more nuanced, but I still think it is far from free. For individuals - hosting something that requires 2-4 GB of RAM [1] is definitely not free. For companies - hosting something that doesn’t include SSO is pointless. The Bitwarden source available license, that includes SSO, does not allow production use [2], and requires a paid subscription instead.
BTW I completely understand the reasons to not open source everything. What I don’t understand is: why not use the source available Bitwarden license for the entire server codebase?
[1]: https://bitwarden.com/help/install-on-premise-linux/
[2]: https://github.com/bitwarden/server/blob/master/LICENSE_FAQ....
That is not the right understanding of the term "free" because the code is completely open-source and you can remove the parts that have to do with registration and enterprise features yourself without breaking the license agreement. You would have to maintain such a fork on your own though. It would be easier if Bitwarden Inc. themselves would maintain a completely open-sourced version and an open core version with non-free parts and registration, but they are not obligated to do so.
I did, however, assume the Open Source <=> OSI approved license. How else to define Open Source?
Transparency alone could be achieved with their own Source Available license, so it doesn't seem like a reason for double licensing.
So, the argument is simply that Open Source is a branding that attracts developers as a target group.
I wonder when will we start seeing commercial, source available projects posted to GitHub with a single file like stringutils.[ts|go|java|etc] MIT-licensed for a single purpose of calling the entire project "Open Source"
[1]: https://redmonk.com/sogrady/2023/08/03/why-opensource-matter...
> ... api includes... Commercial Core which is under the Bitwarden License, however this can be disabled by using /p:DefineConstants="OSS" as an argument to dotnet while building the module.
There's even a Tauri-based desktop app!
Full disclosure: I have "contributing power" but do not make money from its sales or anything like it.
[1]: https://padloc.app
—Google Play on an Android 13 Pixel 7. That and the star rating are not confidence inspiring.
Not exactly the impression I’d like to see when using a password manager. And I’m a UI/UX designer in case you wonder…
That said, I do share in the concern about the funding and exec changes.
On the other hand keeping everything in sync manually seems a hassle and in the end you just encrypt on your machine and the syncing goes through the cloud anyway, so where's the difference? I'd be happy to hear thoughts on this.
My relevant data is synced regularly to my nas (running a raid-1) and I weekly back the whole thing up to an offsite disk at my parents house.
Can someone who really really want it, get to it? Sure, how big of a target am I against a cloud provider?
For extra security I use a key file in addition to a password which I manually transfer between devices.
I'm sure I forgo some convenience by not having field auto-populate all of the time (Keepass can do some of this, but I haven't had it work reliably), but I relax knowing I need not worry about a third-party service being hacked or my credentials being behind a paywall.
If you're worried about using Bitwarden's cloud vault, you can always spin up an instance of vaultwarden (FOSS server impl in Rust) and point your clients to it. I haven't done it myself yet (though I will likely do it) but I've heard it works really well.
I’m not too worried about the eggs in one basket. My digital national ID and my email credentials aren’t saved on my Bitwarden, so while I obviously don’t want to lose it, it also wouldn’t be the end of the world for me.
Also, there is a chance of data breach. The 2FA and hardware keys are bypassed in this case. It’s all your master password.
Not sure I follow. When my master password is breached, attackers would still need to have my hardware key (which I obviously don't keep in the cloud), right?
For the average user, it is infinitely better to use a password manager than to use hunter42 on all their accounts.
I keep super important 2FA codes (email, github etc) elsewhere, and for less important services, I store the OTP in my password manager.
On the topic of phishing and OTPs, storing the OTP in your password manager could actually help with phishing (opposed to storing it in an authenticator), because it will only autofill on the correct domain. This can be the difference between compromising a password or the whole account.
From here, we can have a discussion about broad behavior and individual behavior. We observe that at scale people reuse passwords if they are not using a password manager. End of story. Getting people to use a password manager at scale is the single largest practical improvement in account security for the general population that we have available to us right now. This is even true with the risk of a vault being stolen and unlocked. I've never seen any data that even remotely challenges this point.
Cloud management of passwords is basically non-negotiable for most people. "Oh fuck, my vault was on my computer and I dropped it on the floor and the disk broke" will be a constant occurrence. Getting everybody to properly back up their vaults is not feasible at scale.
You can separately talk about specific people if you want. If you are capable of creating unique and sufficiently strong passwords for all of your accounts, then go ahead and avoid a password manager. This will mitigate a marginal risk for you.
It is compatible with pass and uses the very same store.
It sounds like a good idea, but I'm worried that a client could be at risk of a software supply chain attack - I don't think I will have the expertise to evaluate each new version.
Products like 1Password and Dropbox first made a good consumer product before pivoting to enterprise and making the products worse. Even before the VC funding of $100 million, Bitwarden started pivoting to cater to enterprise features and neglected the consumer side. This has resulted in Bitwarden doing a minimum set of things in a very mediocre way.
Its desktop clients are based on Electron and suffer with the common issues related to that (don’t behave like native apps for keyboard shortcuts or navigation, sluggish, etc.). Its mobile app, at least on iOS, is also sluggish and has poor UX.
People have asked for additional predefined item types (like WiFi passwords, software licenses, etc.) and that’s been on the roadmap for more than five and a half years [1] with no timeframe for release in sight. It just recently changed the timeframe for this from the first half of 2023 back to “Under Research”. [2] In all likelihood, it’ll be six and a half to seven years by the time that’s done, if at all.
One positive about Bitwarden is that its free tier offers something that’s somewhat good (ProtonPass is nowhere close to this as of yet). But I don’t see anything in the password management market that’s cheap enough (like Bitwarden’s personal plan), has good features (including browser extensions) and stability, and is managed by courteous and helpful people (1Password fails on some of these).
[1]: https://community.bitwarden.com/t/additional-item-types-pre-...
[2]: https://community.bitwarden.com/t/bitwarden-roadmap/12865
EDIT: I have just noticed this. Everyone whos interest should submit!
What are you talking about?
Passkeys aren’t supported in 1Password on Android because Google has not released APIs to allow that. Not because Android support is an afterthought. Which you would know if you had researched this: https://blog.1password.com/save-use-passkeys-web-ios/
Your comments on this topic are woefully out of date and wrong.
For families who are hooked into Apple's ecosystem, this can provide a much better password management than third party tools.
Especially ones better than MacOS.
Also you can’t edit while offline.
And as an admin it's much easier to maintain.
If you don't want to pay $10/year for Premium, you can still host Vaultwarden instead and get the features for free.
> self-hosting is deliberately difficult so you'll be using the cloud
[citation needed] in my opinion. Yes, the current self-hosting method is rather complex, but still not that difficult to set up. Just follow their guide.
They are even working on a new "unified" deployment method [1] where you can choose your own DB and all the Bitwarden containers are merged into one. The resulting docker-compose.yml looks as simple as any other service I self-host. Why would they do this if what you said were true?
[1] https://bitwarden.com/help/install-and-deploy-unified-beta/
Whereas in the case of KeepassXC, you have to have your own place where to store the password database and set it up on you different devices. So Bitwarden offers more convenience.
On the KeepassXC side of things I’ve had zero issues with the app itself (using it on Linux, OSX and Windows) and I use Strongbox on iOS which is one of the very few apps I’m happy to pay for to support the developer, it’s so much more polished than Bitwarden.
I can imagine how the password sharing would be a problem tho.
The reasons for me for switching specifically to Bitwarden were:
- Price.
- Open source.
- Multiplatform client.
- Simple and straightforward to import stuff from KeepassXC.
- MFA.
- Possibility of self hosting. (Although I'm using the saas version for now)
- Fewer people to trust. You have to be a little more careful with KeePass clients:
https://news.ycombinator.com/item?id=36020196
- Templates. Bitwarden's implementation is pretty basic but the KeePass ecosystem is still sorting it out:
Also, while I trust Bitwarden sync, I'm not quite as sure of the various apps that implement the KeePassXC on iOS. I'm still not aware that any have been audited, so to my mind Bitwarden is more secure.
Still, the possibility of a change of management philosophy at Bitwarden also wore on me, so not wishing to be solely dependent on an app that I might no longer trust, I continued to maintain my KeePassXC vault, duplicating any new Bitwarden entries. It's a simple way to backup Bitwarden, though a bit time-consuming.
Syncing KeePassXC is simpler now than before I migrated; sneakernet is no longer required, having been replaced by Signal and "Note to Self." It's still not as simple as Bitwarden's sync, so I'll maintain that unless I have a trust reason to change. FWIW
* Desktop app not focusing correctly when opening it
* Browser extension asking to save password even if it's already there
* Log-In suggestions not showing
* Slow and laggy on iOS
* Biometrics log-in breaks half of the times I try to use it
I like the fact it's open-source, although that doesn't make it more secure, and I don't think I would like to self-host.
I mean, being a MSSQL + .NET app it's quite an exotic beast in my self-hosting garden, but it definitely does its job without skipping a beat.
I'm also happy to support them with a modest $10/month contribution - for that price you get a few extra perks on your instance, but most importantly for me you get to store OTP codes / support for MFA, so I don't have to use a separate app for that.
I feel like it's important to keep financially supporting projects like these, even if we host them ourselves, even if we only get one or two extra perks for the extra bucks.
External pressures towards enshittification are inversely proportional to profitability.
If a company can make money out of a business model where 80% is free to self-host and 20% is additional subscribe-only stuff, then things can remain like they are. If it doesn't, then we're all going to lose also the remaining 80%.
It is portable and easy to access from anywhere ( don't need to VPN to your local network). Not a fan of the self hosted server password management model. Doesn't make any sense unless managing multiple users.
Don't get me wrong, I don't use a password manager either. Not a single one of them is truly portable, safe or secure. What if you lose all your electronics? All your belongings? Your house burns down in a fire? The cloud gets hacked? You have conflicting interests with US government and they kindly request your passwords from Apple? You have conflicting interests with any other country and they find and use the backdoors installed in US companies by US agencies?
I use an algorithmic password which is:
* Trivial to run in my head (I got used to it)
* Compliant with all silly password character requirements
* Has password rotation built in for apps/websites which require you to change your password every X monts
* Has a shorter version for apps/websites which have a password length limit of 20 chars
* Has a third easier-to-spell version for passwords I need to share with family and friends
* Completely ASCII
* Impossible to tell with bare eyes it's the password for amazon.com from the resulting password. It looks like randomly generated gibberish.
* Leaves the Caps Lock off (so that you won't try again and fail again when you fail once and the Caps Lock is on)
I only have an algorithm in my head. The downsides? It's a bit more slower to enter a password if I haven't entered it in a while. Still doesn't take more than 30 secs. And it can only be brute forced in a million years instead of a billion.
And yes, you need these features in your algorithmic password. It took me about a year of trial and error to get to this point.
Edit: what about digit-only password?
Though I should admit I still didn't migrate all my passwords to the latest and safest specification of the algorithm.
Only using digits limits the probabilities space drastically.
For digit-only, I meant platforms that forces you that requirement - my bank does.
What about MFA?
Take a look for the algorithms: https://www.google.com/search?q=historical+cryptography+tech... Choose one which you can run in your head, don't use it as-is, insert random chars at certain places, substitute some letters in the app name for others, make sure it looks like randomly generated, and you will be fine.
I still use 2FA with Authenticator (on iPhone), fallback set as SMS. Only thing I need is my government issued ID to get a new SIM card if the current one burns.
Still, the algorithm method requires 3 services to be breached. Those services must be storing the passwords in plaintext or an otherwise retrievable method. The bad actor must put together the fact that your account is the same across all 3 services. Then they must analyze your password and reverse engineer your algorithm.
That seems a lot less likely than your master password getting nabbed.
The attack vector for a PW manager is a lot easier. They're obvious targets for both breaches and social hacks. One person looking over your shoulder at the coffee shop is as or more likely than anything else. They can even swipe your phone in that scenario to beat MFA.
I'm not advocating an algorithmic approach. The average person isn't going to understand this (heck, they don't understand PW managers either). And if they did, most algos would be something like ServiceName! anyway.
On the whole a password manager is a better solution, but it's not without its own trade offs, which don't get nearly enough discussion.
I know it's controversial, it's a risk I'm willing to take.
I'm using it (FIDO2/webauthn)
I tried this years ago and didn't like it. Not only because Electron, but I thought it was missing a lot of basic features (folders/organizing passwords was sorely lacking).
I'm not looking to try it again, to be clear, just curious. KeepassXC won my heart.
Got any insight there?
For Android there is https://github.com/android-password-store/Android-Password-S....
The only Windows client listed at https://www.passwordstore.org/#other is unmaintained.
We tried using Keepass but people were resistant to using it. The UI is not very user-friendly for non-technical people.
Keepass also lacks some of the features we would like to have, for example: We would like to push a new user/password to a person's vault (for example let's say IT creates a printer account for a person, we would like to put the account information to the relevant person's vault), or we would like to share a common password among a group of people.
But I am not sure if Bitwarden is a good choice in practice for this kind of things.
If I could figure out how to sign and ship Mac and iOS apps, I'd ship a fork that continually pulled from upstream, with just the two `variables.scss` files patched.
There's only one thing I wanna hear from Bitwarden: What do you do that KeePassXC doesn't, and what are the trade-offs?
Bitwarden offers free hosting for personal use. Also, consistently named apps (even for mobile).
Not open source but very good and very convenient.
(I see they changed. There may not be a free version anymore, not sure)
Dashlane, it’s well worth the price for my piece of mind and the security of my passwords.
Unfortunately, Bitwarden fails at both.
1. Security.
Bitwarden's documentation on its security model is quite thin.
1password has a great write-up about how it works in detail: https://1passwordstatic.com/files/security/1password-white-p.... Corresponding doc for Bitwarden is much lighter on detail: https://bitwarden.com/help/bitwarden-security-white-paper/.
The security audits they list of https://bitwarden.com/help/is-bitwarden-audited/ are focused on the client software implementation bits, and make no judgement on the overall security model.
My main concern is that the password is the only key that is needed to both log into the server and to decrypt the vault. There is no additional key that is completely offline, like 1password Secret Key (that is presumably stored in Keychain / Secure Enclave at rest). A password seems somewhat more easily stealable (with keyloggers or clipboard loggers etc).
I am not a security expert, but I know enough to be concerned :). I wish there was more discussion on the implications of this difference on security models.
2. Offline access.
Bitwarden does not like to work offline.
You can unlock and view the vault, but you cannot make any changes without active connection to the internet! And Bitwarden will show you a very generic error ("failed to fetch") if you try editing while offline, it won't give you any suggestion on what to do.
Moreover, apparently they will delete the local copy of the vault if internet connection is missing for 30 days: https://www.reddit.com/r/Bitwarden/comments/vtaqi0/comment/i.... That's just nuts if true. I should not rely on the Cloud to have access to the vault as stored locally as long as I have the password.
While there is a general fear about trusting The Cloud as the source of truth for accessing the passwords, this caused very tangible practical issues. I have actually run into needing Bitwarden while on the go. Also the CloudFlare IP that Bitwarden uses was somehow blocked by my provider for some time, and that broke Bitwarden completely (both the provider and Bitwarden neglected to do anything about the problem when contacted).
3. UX.
You get used to it, but it's simply not great.
Worst of all, the UI of the browser extension is prone to data loss. The Bitwarden popup resets the state every time it is unfocused. So imagine the scenario:
* I start creating a new entry and generate a password. * I briefly dismiss the Bitwarden popup to paste the password into the website. * I open Bitward popup again hoping to finish entering the data and save. But the entry is gone. I just need to hope that the generated password is still on the clipboard.
1password in contrast keeps full UI state and partially entered data even if the vault is locked in the interim.
Doesn't always work reliably with Bitwarden ;)
Also that one time when they randomly blocked my IP and wont do anything about it, wtf?! From then on I've started occasionally exporting the JSON file and keeping it somewhere safe, just in case. Like... I'm the person behind this account, I own the email.. I don't even ask you for a password or whatever! I'm asking you to unblock my IP. This shouldn't take more than 5 minutes!
I also want BitWarden to succeed, but does it want itself to succeed?