you are viewing a single comment's thread
view the rest of the comments
[+] -67 points 2 years ago* (last edited 1 year ago) (6 children)
  • [+] 70 points 2 years ago (1 child)
  • [+] -22 points 2 years ago* (last edited 1 year ago) (4 children)
  • [–] 42 points 2 years ago (2 children)

    Lol, imagine ridiculing users for trusting an FOSS company to handle their password management, and then storing your encrypted password DB in Microsoft's OneDrive 😆

  • source
  • parent
  • hideshow 4 child comments
  • [+] -21 points 2 years ago* (last edited 1 year ago) (2 children)
  • [–] 37 points 2 years ago

    I don't think Microsoft can decrypt your DB file, neither do I think Bitwarden can. Encryption happens locally on their open source clients too.

    But I'm not the one disparaging trusting an open source program to securely encrypt passwords, you are.

  • source
  • parent
  • [–] 14 points 2 years ago (1 child)

    Could you please show how bitwarden can decrypt a vault that's locally encrypted by a foss client?

    "Imagine trusting any company with your passwords"

  • source
  • parent
  • hideshow 2 child comments
  • [+] -8 points 2 years ago* (1 child)

    They created the client. In theory, they can have some backdoors. And since you store your files on their side, risk is greater, imo

  • source
  • parent
  • hideshow 2 child comments
  • [–] 4 points 2 years ago* (1 child)

    This is where your lack of understanding of the open source thing is readily apparent to everyone arguing with you. If it was backdoored, many people would be calling that out. In fact, this was one of the exact reasons at the heart of the original concerns leading to this story.

    The fact that the source is available means that we can see exactly how the data is encrypted, allowing assurances to be made independently.

    If nothing else, I trust Bitwarden MORE because of that and I'm happy to pay them for their services since it helps find further development.

  • source
  • parent
  • hideshow 2 child comments
  • [–] -4 points 2 years ago (1 child)

    If it was backdoored, many people would be calling that out.

    In theory. And not necessarily soon. Don't forget the context of this thread: we compare bitwarden with keepass, which does not offer to you your password base on their server side.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 2 years ago (1 child)

    Trusting one FOSS client good. Trusting different FOSS client bad. Logic where?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 2 years ago (1 child)

    That different FOSS client stores your data on their company's server. It's an important factor, IMO.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 2 years ago (1 child)

    Dude, how is bitwarden hosting your own, locally encrypted (in FOSS client) password database any different than using keypass and syncing it however you want?

    I don't even use Bitwarden myself, I'm using keepass too, but this attitude is ... weird?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 2 years ago* (1 child)

    I find risk slightly bigger when you encrypt your private data with the product of the company and store that encrypted data on servers of the same company.

    Why: because if they have some backdoor now or plans to introduce it in future, they have all the time in the world to apply that backdoor to your data. Without you knowing it.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 2 years ago (1 child)

    Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 7 points 2 years ago

    And you are aware that bitwarden knows nothing about the passwords inside the vault and the vault is encrypted in zero knowledge type of fashion?
    AND that Bitwarden does external audits?
    AND if you loose your master password you are out of luck as they can't support you helping crack the decryption?

  • source
  • parent
  • [–] 6 points 2 years ago

    Except for the part that it's not a question of trust (being open source), there's no third-party architecture to trust (it can and should be self-hosted), the data on the server are also encrypted client-side before leaving your device, sure.

    Oh, and you also get proper sync, no risk of desync if two devices gets a change while offline without having to go check your in-house sync solution, easy share between user (still with no trust needed in the server), all working perfectly with good user UI integration for almost every systems.

    Yeah, I wonder why people bother using that, instead of deploying clunky, single-user solution.

  • source
  • parent
  • [–] 48 points 2 years ago

    Bitwarden can be fully self hosted, I'm doing it. My Bitwarden server doesn't (and can't) talk to them at all as it has no way to access the internet. They know nothing about my deployment except that I signed up for a free license key.

  • source
  • parent
  • [–] 35 points 2 years ago (1 child)

    Are you a software developer ? Because you are way out of touch with what users want.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 2 years ago (1 child)

    I get why you'd suggest the previous commenter is out of touch with what users want, but what does that have to do with being a software engineer?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 13 points 2 years ago (1 child)

    I used to use Keepass and sync thing and would consistently run into conflicts between my desktop and mobile entries. Maybe there's a better way to do it that I'm missing, but that was very annoying

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 years ago

    I use this setup for my personal passwords, using nextcloud as the sync solution. A semi-fix for that was using Keepass2Android (on Android obviously). It integrates with nextcloud directly, keep a local DB of passwords, and would only load the remote one (and merge) on unlock and updates, not keeping it "constantly" sync on every remote change. It works well… most of the time… with only two devices that almost always have connection to the server… and for only one user.

    It's overly clunky though. It's the big advantage of "service based" password manager against "single file based" ones. They handle sync. We have plans to move to bitwarden at my workplace, and since the client supports multiple accounts on multiple servers, I'll probably move to that for personal stuff too. The convenience is just there, without downside.

  • source
  • parent