(That said, I am also concerned about the direction Bitwarden is taking. I just think this shows that even OSS projects can have direction/rugpull issues.)
(That said, I am also concerned about the direction Bitwarden is taking. I just think this shows that even OSS projects can have direction/rugpull issues.)
Whats to say this will still be true if the company gets sold?
If they went this path I think I would jump ship to a paid service.
Apple and Google being the gatekeepers for all mobile app distribution is a real pain point. Without the clout of a big brand name the risk of being unable to distribute apps goes up.
Then you could say well Vaultwarden will work with these forked clients, but then you are placing your security into the hands of multiple different open source maintainers and vaultwarden then has nothing to do with Bitwarden and becomes some random back end + some random 3rds party clients.
IMO that fact that the existing Vaultwarden system relies on Bitwarden clients and therefore caries Bitwardens secure reputation is its main selling point. Take that away and Vaultwarden is nothing more than some random back end software that can not really be trusted.
I hope that this could be a starting point and not an end-point of Vaultwarden. It has gotten far on the shoulders of the Bitwarden giant. If it forked, would it have a large enough community to continue to carry that trust forward (including building new clients)? How much financial support would they need? Could they find a sponsor? It's a European project -- would the EU help fund it as a data sovereignty push?
Why not? The most important security bits are implemented client-side which is developed by Bitwarden. If the clients are secure then my database is safe even if Vaultwarden turns out to be evil.
Switching from Bitwarden Client to Vaultwarden Client would require about 3 orders of magnitude more trust than switching the server which primarily deals with encrypted blobs. If the client turns out to be malicious then it's game over.
I pay for a service for my family because I need reliable and easy for my wife and daughter to use it.
- KeePass files synced between laptop and phone on OneDrive, DropBox, etc
- KeePassXC on Windows and Mac
- Keepass2Android mobile client
- Browser integration on mobile.
- On laptop, I prefer no browser integration; Copy username and password with Ctrl+B and Ctrl+CUnhackable. Yours forever.
Use words based passwords to make entry easier.
Suffers from physical presence security hacks. I argue those are far less frequent than online hacks.
Wouldn’t recommend for people who are comfortable with Password managers.
It is super easy to explain to people how to use it. And some security is better than none.
And wow… just even the cops.
I am more worried about “lawful” “government” “agencies” stealing my crap than actual criminals. And that makes me sad.
What I stopped doing so frequently could be described as "evangelizing" or "endorsing". I no longer actively tell people that I think they should use X, instead, if someone asks, I say "I use X, and it's worked for me so far".