https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden
Previously discussed: https://news.ycombinator.com/item?id=48163389
https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden
Previously discussed: https://news.ycombinator.com/item?id=48163389
If you believe that the technology works, that encryption is happening and that the decryption is only happening on your local machine then why in the fuck would I host this myself?
You need to believe that it does not work when they do it, but does work when you do it.
I have not seen any evidence of that.
I'm curious why other self hosters think it's a bad idea.
Thanks for sharing.
So probably its RSS usage is just mostly its own executable code?
What will you use when this stops working in the near future?
I'll just export my vault and move to KeepPass or something else?
I've been self hosting Vaultwarden for me and my wife for years without issue. People like to tell others what they should and shouldn't do because they want to feel superior to others, I suppose.
It's especially strange since self hosting is, aside from the 'fun' aspect of it, about personal control. So this tsk tsk'ing from others about self hosting a password manager is especially ridiculous.
mostly i was missing power user features and especially ux for the browser plugin, namely you can't operate it fully with the keyboard, with keepassxc you can
No reason to use anything more complicated.
https://www.glassdoor.com/Reviews/Bitwarden-Reviews-E4337610...
Guess I'll never be visiting Glass Door again then.
Not sure if still the case but normally you have to not only 'sign in' but also feed them information (e.x. salary at a position, write a review, etc.) in order to be able to view much of anything.
They also do not give a shit about obvious 'juicing' (i.e. when it is obvious that upper management and/or HR is adding reviews where the 'con' reads like one of those softball warning phrases in a job description.)
The most egregious example I've found was that the Danish postal service had something like a 4,8/5,0 rating on Trustpilot. You'll be hard pressed to find a more inept, corrupt and universally hated company. So in an attempt to improve their public image, they decided to game the ratings, instead of actually delivering mail properly.
However they may have proved that they are indeed.. trash. Maybe even a few times.
One such case was https://www.forrester.com/blogs/glassdoors-mishandling-of-cu...
In my eyes they are in the same class of Facebook, uservoice, Pinterest, Quora etc.
Fundamentally it's all a game of whack-a-mole for admins unless some kind of microtransaction system is invented. Then a DDOS scraping event is just extra revenue.
or pooling together tokens and asking Claude nicely to make a mobile app
What's happening with Namecheap? I've been a user for a long time and haven't noticed anything.. Maybe I'm one of the frogs being boiled!
[2] https://discuss.privacyguides.net/t/privacy-concerns-regardi...
Bought out by private equity. I've moved my domains to Hover when I found out from that Hacker news thread before any of the enshittification affects me.
[2] https://discuss.privacyguides.net/t/privacy-concerns-regardi...
Bought out by private equity. I've moved my domains to Hover when I found out from that Hacker news thread before any of the enshittification affects me.
The switch to Vaultwarden was insanely easy.
But auto renewals not working at times for some reason, credit cards not being saved, prices rising vs competitors.
Just switched everything to CloudFlare since I'm always pointing to it anyways and use a lot of their services.
Fuck bitwardens creators for selling out. I want them to know they fucking suck.
I don't even mind paying a reasonable amount for Bidwarden (as I do) or other things I find valuable, but it's the unlimited growth of profit that disgusts me. My Grand Father, Father, and myself were/are all business people (in very different industries) and we'd all be ashamed to double the price of something simply for more profit.
Usually this was never an issue when becoming the one at the driving wheel, was due scaling up the ladder all the way from the bottom, or having the luck of being in the owners' family already.
Disgustes me as well, above all the layoffs only to give the money to the "poor" shareholders.
I think we need to be a bit more aware of our expectations from free products. By the end of the day on the free tier, and as long as you're not paying, you are a cost to the company. I think most of these problems go away if we don't rely or expect that much from free products. If we pay a little bit, even if it's just for the compute when self-hosting, it creates much healthier relationship.
The post also mentions GitHub. Let's be honest, they created a lot of value with the free tier, but we also can't have high expectations for a service we're not paying
> The price is updating to $1.65/month, billed annually.
Followed by a 25% discount for this reveal only.
Have to go back to my old invoice to see it was $10/y and now the new one $19.80/y
I never liked that I needed to pay premium just for 2FA but this abuse of trust is definitely the end of it.
Too bad I won't get a refund for my Oct 1st renewal but I'll happily cancel as soon as I get vaultwarden hosted.
The argument here is always why would people spend all this time and money to build custom software when they can just pay a company $20-100 bucks a month? Because that product will become enshittified. It's not a question of if, its a question of when. I thought open-source SaaS would be immune, but clearly not.
If you excuse a Warcraft-y metaphor.
But it is worrying that they might intentionally break vaultwarden in the future.
Also protonpass.
Bitwarden was the no nonsense choice because it just worked.
How does this work with keepassxc? Does it depend on your file syncing primitive?
I already have "Proton Unlimited" as a subscription but until now I never used Proton Pass. I thought about giving up on Bitwarden for some time and probably will try it now. AFAIK you can even import your Bitwarden logins.
For me, Pass works much better, especially passkeys on Android. Bitwarden was very flaky in that regard, Proton Pass "just works".
I use Pass for personal logins and sharing family-related accounts with my wife.
Proton ticks all good-company boxes. E2ee, majority owned by the Proton foundation, all client-side code is OSS, and some other structures in place to protect themselves from corp greed. Best I could find.
Seriously. About as secure, if you're honest about the actual threat model (vs one security aficionados would like you to assume), and paper can't be enshittified.
[1]: https://en.wikipedia.org/wiki/Bruce_Schneier
[2]: https://www.schneier.com/blog/archives/2005/06/write_down_yo...
Current offerings are ok. But they had a pay once model before which they grandfathered in. I got lucky. It's amazing and no bullshit software.
Has apps from everything including browsers. Can use any cloud storage as vault. Supports un Pass passkey totp pin and everything you can think of.
It's somewhat concerning to me that none of the security conscious people in this thread seem to notice that they are changing their privacy practices based on the advice of a language model pretending to be a person.
https://docs.ipfs.tech/concepts/persistence/#pinning-service...
Maybe someone could write a provably private client-based browser decryption script, hosted on various websites. We might need a new browser spec that sandboxes pages until they're unsandboxed, allowing them no egress/ingress or even local storage or cookies.
Or better yet, take that choice away from browser vendors, and create a runtime in the browser that simply can't be observed, perhaps by using zero-knowledge proofs.
Writing this out, I wonder if the issue is due to longstanding incomplete browser architecture, going back to when the web went mainstream in the mid-1990s. Or maybe it's still just an open problem.
Solve private distributed durable storage, along with a base level of secret computation eventually running about the speed of a 6502, 286 or 68000, and we wouldn't need free services that inevitably get privatized and ensh!ttified.
I have no idea if something like this already exists, I'm just speculating as to what base functionality it might need from first principles.
Also I wonder if similar techniques could be recruited to build an OS around cryptocurrency. That way a meta economy could run alongside the corrupt economy, and shield users from currency devaluation and other wealth inequality drivers used by the ultra-wealthy to increase the value of the means of production that they own relatively, so that they can buy more.
Arguably the process of wealth concentration is so fundamental that it puts a countdown on capitalism, driving it towards the late-stage capitalism that we've had since about 1970 when productivity diverged from wages, and eventually revolution which results in socialism/communism or even permanent authoritarian dystopia like on Star Wars. In a way, it's in the best interests of the ultra-wealthy to build meta economies, which of course makes those economies suspect and probably vulnerable to exploits, especially in the AI age. We've seen how crypto has created black markets capable of capturing governments, so maybe we should be careful what we wish for.
But really I just don't want to type my password anymore.
Or is it just software that has zero value to you because it’s intangible and you intentionally ignore the time and effort other people spend on it?
Someone has to pay for ongoing maintenance.
I don't think you understand what capitalism is, or you've spent no time at all looking into how many hundreds of millions have been killed under socialism, fascism, crony-capitalism, or any of the other means of exchange that involve force.
The federal government printing infinite money is the reason that companies need to constantly keep increasing profits, otherwise they will just ground down by the annual 15% inflation rate.
Everything else is just a nonsense, watermark and fluff, scamming from time and attention - there's NO value in the filler.
To reiterate: there's no value in this sort of the LLM garbage. There's value in the information, especially when formatted and provided in the humane format.
I don't understand why some people feel the need to turn a few hundred words if concise description into thousands via LLM.
> And it never comes in a single dramatic announcement. It comes in layers. A feature post with a price change inside it. A LinkedIn update nobody made a press release about. A values page that says something slightly different than it did last week. If you’re still on Bitwarden cloud and this is giving you pause — it should. [...] Whether self-hosting stays viable long-term is the real question worth sitting with.