▲ 334 ▼ Bitwarden Makes Change To Address Recent Open-Source Concerns (www.phoronix.com) submitted 2 years ago by moe90@feddit.nl to c/technology@lemmy.world 76 comments fedilink hide all child comments
[+] net00@lemm.ee -67 points 2 years ago* (last edited 1 year ago) (6 children) [deleted] permalink fedilink source hideshow 12 child comments replies: [+] Telodzrum@lemmy.world 70 points 2 years ago (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [+] net00@lemm.ee -22 points 2 years ago* (last edited 1 year ago) (4 children) [deleted] permalink fedilink source parent hideshow 8 child comments replies: [–] Lettuceeatlettuce@lemmy.ml 42 points 2 years ago (2 children) Lol, imagine ridiculing users for trusting an FOSS company to handle their password management, and then storing your encrypted password DB in Microsoft's OneDrive 😆 permalink fedilink source parent hideshow 4 child comments replies: [–] Llewellyn@lemm.ee -4 points 2 years ago encrypted is the key word permalink fedilink source parent [+] net00@lemm.ee -21 points 2 years ago* (last edited 1 year ago) (2 children) [deleted] permalink fedilink source parent hideshow 4 child comments replies: [–] Lettuceeatlettuce@lemmy.ml 37 points 2 years ago I don't think Microsoft can decrypt your DB file, neither do I think Bitwarden can. Encryption happens locally on their open source clients too. But I'm not the one disparaging trusting an open source program to securely encrypt passwords, you are. permalink fedilink source parent [–] Bezier@suppo.fi 14 points 2 years ago (1 child) Could you please show how bitwarden can decrypt a vault that's locally encrypted by a foss client? "Imagine trusting any company with your passwords" permalink fedilink source parent hideshow 2 child comments replies: [+] Llewellyn@lemm.ee -8 points 2 years ago* (1 child) They created the client. In theory, they can have some backdoors. And since you store your files on their side, risk is greater, imo permalink fedilink source parent hideshow 2 child comments replies: [–] soul@lemmy.world 4 points 2 years ago* (1 child) This is where your lack of understanding of the open source thing is readily apparent to everyone arguing with you. If it was backdoored, many people would be calling that out. In fact, this was one of the exact reasons at the heart of the original concerns leading to this story. The fact that the source is available means that we can see exactly how the data is encrypted, allowing assurances to be made independently. If nothing else, I trust Bitwarden MORE because of that and I'm happy to pay them for their services since it helps find further development. permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee -4 points 2 years ago (1 child) If it was backdoored, many people would be calling that out. In theory. And not necessarily soon. Don't forget the context of this thread: we compare bitwarden with keepass, which does not offer to you your password base on their server side. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 1 point 2 years ago (1 child) Trusting one FOSS client good. Trusting different FOSS client bad. Logic where? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago (1 child) That different FOSS client stores your data on their company's server. It's an important factor, IMO. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Dude, how is bitwarden hosting your own, locally encrypted (in FOSS client) password database any different than using keypass and syncing it however you want? I don't even use Bitwarden myself, I'm using keepass too, but this attitude is ... weird? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago* (1 child) I find risk slightly bigger when you encrypt your private data with the product of the company and store that encrypted data on servers of the same company. Why: because if they have some backdoor now or plans to introduce it in future, they have all the time in the world to apply that backdoor to your data. Without you knowing it. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent [–] Dark_Arc@social.packetloss.gg 29 points 2 years ago* I do not trust bitwarden to encrypt my data anymore than anyone trusts keypass to encrypt my data. They're both open source and they both do the encryption locally; you're plainly mistaken. permalink fedilink source parent [–] Appoxo@lemmy.dbzer0.com 7 points 2 years ago And you are aware that bitwarden knows nothing about the passwords inside the vault and the vault is encrypted in zero knowledge type of fashion? AND that Bitwarden does external audits? AND if you loose your master password you are out of luck as they can't support you helping crack the decryption? permalink fedilink source parent [–] cley_faye@lemmy.world 6 points 2 years ago Except for the part that it's not a question of trust (being open source), there's no third-party architecture to trust (it can and should be self-hosted), the data on the server are also encrypted client-side before leaving your device, sure. Oh, and you also get proper sync, no risk of desync if two devices gets a change while offline without having to go check your in-house sync solution, easy share between user (still with no trust needed in the server), all working perfectly with good user UI integration for almost every systems. Yeah, I wonder why people bother using that, instead of deploying clunky, single-user solution. permalink fedilink source parent [–] CarbonatedPastaSauce@lemmy.world 48 points 2 years ago Bitwarden can be fully self hosted, I'm doing it. My Bitwarden server doesn't (and can't) talk to them at all as it has no way to access the internet. They know nothing about my deployment except that I signed up for a free license key. permalink fedilink source parent [–] kameecoding@lemmy.world 35 points 2 years ago (1 child) Are you a software developer ? Because you are way out of touch with what users want. permalink fedilink source parent hideshow 2 child comments replies: [–] drspod@lemmy.ml 3 points 2 years ago (1 child) I get why you'd suggest the previous commenter is out of touch with what users want, but what does that have to do with being a software engineer? permalink fedilink source parent hideshow 2 child comments replies: [–] kameecoding@lemmy.world 4 points 2 years ago (1 child) A joke about shitty developers. permalink fedilink source parent hideshow 2 child comments replies: [–] drspod@lemmy.ml 11 points 2 years ago permalink fedilink source parent [–] Contravariant@lemmy.world 15 points 2 years ago Well, who did you trust to build your hardware? permalink fedilink source parent [–] mac@lemm.ee 13 points 2 years ago (1 child) I used to use Keepass and sync thing and would consistently run into conflicts between my desktop and mobile entries. Maybe there's a better way to do it that I'm missing, but that was very annoying permalink fedilink source parent hideshow 2 child comments replies: [–] cley_faye@lemmy.world 2 points 2 years ago I use this setup for my personal passwords, using nextcloud as the sync solution. A semi-fix for that was using Keepass2Android (on Android obviously). It integrates with nextcloud directly, keep a local DB of passwords, and would only load the remote one (and merge) on unlock and updates, not keeping it "constantly" sync on every remote change. It works well… most of the time… with only two devices that almost always have connection to the server… and for only one user. It's overly clunky though. It's the big advantage of "service based" password manager against "single file based" ones. They handle sync. We have plans to move to bitwarden at my workplace, and since the client supports multiple accounts on multiple servers, I'll probably move to that for personal stuff too. The convenience is just there, without downside. permalink fedilink source parent [–] noxy@yiffit.net 4 points 2 years ago cuz being able to log in is handy sometimes permalink fedilink source parent
[+] Telodzrum@lemmy.world 70 points 2 years ago (1 child) [deleted] permalink fedilink source parent hideshow 2 child comments replies: [+] net00@lemm.ee -22 points 2 years ago* (last edited 1 year ago) (4 children) [deleted] permalink fedilink source parent hideshow 8 child comments replies: [–] Lettuceeatlettuce@lemmy.ml 42 points 2 years ago (2 children) Lol, imagine ridiculing users for trusting an FOSS company to handle their password management, and then storing your encrypted password DB in Microsoft's OneDrive 😆 permalink fedilink source parent hideshow 4 child comments replies: [–] Llewellyn@lemm.ee -4 points 2 years ago encrypted is the key word permalink fedilink source parent [+] net00@lemm.ee -21 points 2 years ago* (last edited 1 year ago) (2 children) [deleted] permalink fedilink source parent hideshow 4 child comments replies: [–] Lettuceeatlettuce@lemmy.ml 37 points 2 years ago I don't think Microsoft can decrypt your DB file, neither do I think Bitwarden can. Encryption happens locally on their open source clients too. But I'm not the one disparaging trusting an open source program to securely encrypt passwords, you are. permalink fedilink source parent [–] Bezier@suppo.fi 14 points 2 years ago (1 child) Could you please show how bitwarden can decrypt a vault that's locally encrypted by a foss client? "Imagine trusting any company with your passwords" permalink fedilink source parent hideshow 2 child comments replies: [+] Llewellyn@lemm.ee -8 points 2 years ago* (1 child) They created the client. In theory, they can have some backdoors. And since you store your files on their side, risk is greater, imo permalink fedilink source parent hideshow 2 child comments replies: [–] soul@lemmy.world 4 points 2 years ago* (1 child) This is where your lack of understanding of the open source thing is readily apparent to everyone arguing with you. If it was backdoored, many people would be calling that out. In fact, this was one of the exact reasons at the heart of the original concerns leading to this story. The fact that the source is available means that we can see exactly how the data is encrypted, allowing assurances to be made independently. If nothing else, I trust Bitwarden MORE because of that and I'm happy to pay them for their services since it helps find further development. permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee -4 points 2 years ago (1 child) If it was backdoored, many people would be calling that out. In theory. And not necessarily soon. Don't forget the context of this thread: we compare bitwarden with keepass, which does not offer to you your password base on their server side. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 1 point 2 years ago (1 child) Trusting one FOSS client good. Trusting different FOSS client bad. Logic where? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago (1 child) That different FOSS client stores your data on their company's server. It's an important factor, IMO. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Dude, how is bitwarden hosting your own, locally encrypted (in FOSS client) password database any different than using keypass and syncing it however you want? I don't even use Bitwarden myself, I'm using keepass too, but this attitude is ... weird? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago* (1 child) I find risk slightly bigger when you encrypt your private data with the product of the company and store that encrypted data on servers of the same company. Why: because if they have some backdoor now or plans to introduce it in future, they have all the time in the world to apply that backdoor to your data. Without you knowing it. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent [–] Dark_Arc@social.packetloss.gg 29 points 2 years ago* I do not trust bitwarden to encrypt my data anymore than anyone trusts keypass to encrypt my data. They're both open source and they both do the encryption locally; you're plainly mistaken. permalink fedilink source parent [–] Appoxo@lemmy.dbzer0.com 7 points 2 years ago And you are aware that bitwarden knows nothing about the passwords inside the vault and the vault is encrypted in zero knowledge type of fashion? AND that Bitwarden does external audits? AND if you loose your master password you are out of luck as they can't support you helping crack the decryption? permalink fedilink source parent [–] cley_faye@lemmy.world 6 points 2 years ago Except for the part that it's not a question of trust (being open source), there's no third-party architecture to trust (it can and should be self-hosted), the data on the server are also encrypted client-side before leaving your device, sure. Oh, and you also get proper sync, no risk of desync if two devices gets a change while offline without having to go check your in-house sync solution, easy share between user (still with no trust needed in the server), all working perfectly with good user UI integration for almost every systems. Yeah, I wonder why people bother using that, instead of deploying clunky, single-user solution. permalink fedilink source parent
[+] net00@lemm.ee -22 points 2 years ago* (last edited 1 year ago) (4 children) [deleted] permalink fedilink source parent hideshow 8 child comments replies: [–] Lettuceeatlettuce@lemmy.ml 42 points 2 years ago (2 children) Lol, imagine ridiculing users for trusting an FOSS company to handle their password management, and then storing your encrypted password DB in Microsoft's OneDrive 😆 permalink fedilink source parent hideshow 4 child comments replies: [–] Llewellyn@lemm.ee -4 points 2 years ago encrypted is the key word permalink fedilink source parent [+] net00@lemm.ee -21 points 2 years ago* (last edited 1 year ago) (2 children) [deleted] permalink fedilink source parent hideshow 4 child comments replies: [–] Lettuceeatlettuce@lemmy.ml 37 points 2 years ago I don't think Microsoft can decrypt your DB file, neither do I think Bitwarden can. Encryption happens locally on their open source clients too. But I'm not the one disparaging trusting an open source program to securely encrypt passwords, you are. permalink fedilink source parent [–] Bezier@suppo.fi 14 points 2 years ago (1 child) Could you please show how bitwarden can decrypt a vault that's locally encrypted by a foss client? "Imagine trusting any company with your passwords" permalink fedilink source parent hideshow 2 child comments replies: [+] Llewellyn@lemm.ee -8 points 2 years ago* (1 child) They created the client. In theory, they can have some backdoors. And since you store your files on their side, risk is greater, imo permalink fedilink source parent hideshow 2 child comments replies: [–] soul@lemmy.world 4 points 2 years ago* (1 child) This is where your lack of understanding of the open source thing is readily apparent to everyone arguing with you. If it was backdoored, many people would be calling that out. In fact, this was one of the exact reasons at the heart of the original concerns leading to this story. The fact that the source is available means that we can see exactly how the data is encrypted, allowing assurances to be made independently. If nothing else, I trust Bitwarden MORE because of that and I'm happy to pay them for their services since it helps find further development. permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee -4 points 2 years ago (1 child) If it was backdoored, many people would be calling that out. In theory. And not necessarily soon. Don't forget the context of this thread: we compare bitwarden with keepass, which does not offer to you your password base on their server side. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 1 point 2 years ago (1 child) Trusting one FOSS client good. Trusting different FOSS client bad. Logic where? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago (1 child) That different FOSS client stores your data on their company's server. It's an important factor, IMO. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Dude, how is bitwarden hosting your own, locally encrypted (in FOSS client) password database any different than using keypass and syncing it however you want? I don't even use Bitwarden myself, I'm using keepass too, but this attitude is ... weird? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago* (1 child) I find risk slightly bigger when you encrypt your private data with the product of the company and store that encrypted data on servers of the same company. Why: because if they have some backdoor now or plans to introduce it in future, they have all the time in the world to apply that backdoor to your data. Without you knowing it. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent [–] Dark_Arc@social.packetloss.gg 29 points 2 years ago* I do not trust bitwarden to encrypt my data anymore than anyone trusts keypass to encrypt my data. They're both open source and they both do the encryption locally; you're plainly mistaken. permalink fedilink source parent [–] Appoxo@lemmy.dbzer0.com 7 points 2 years ago And you are aware that bitwarden knows nothing about the passwords inside the vault and the vault is encrypted in zero knowledge type of fashion? AND that Bitwarden does external audits? AND if you loose your master password you are out of luck as they can't support you helping crack the decryption? permalink fedilink source parent [–] cley_faye@lemmy.world 6 points 2 years ago Except for the part that it's not a question of trust (being open source), there's no third-party architecture to trust (it can and should be self-hosted), the data on the server are also encrypted client-side before leaving your device, sure. Oh, and you also get proper sync, no risk of desync if two devices gets a change while offline without having to go check your in-house sync solution, easy share between user (still with no trust needed in the server), all working perfectly with good user UI integration for almost every systems. Yeah, I wonder why people bother using that, instead of deploying clunky, single-user solution. permalink fedilink source parent
[–] Lettuceeatlettuce@lemmy.ml 42 points 2 years ago (2 children) Lol, imagine ridiculing users for trusting an FOSS company to handle their password management, and then storing your encrypted password DB in Microsoft's OneDrive 😆 permalink fedilink source parent hideshow 4 child comments replies: [–] Llewellyn@lemm.ee -4 points 2 years ago encrypted is the key word permalink fedilink source parent [+] net00@lemm.ee -21 points 2 years ago* (last edited 1 year ago) (2 children) [deleted] permalink fedilink source parent hideshow 4 child comments replies: [–] Lettuceeatlettuce@lemmy.ml 37 points 2 years ago I don't think Microsoft can decrypt your DB file, neither do I think Bitwarden can. Encryption happens locally on their open source clients too. But I'm not the one disparaging trusting an open source program to securely encrypt passwords, you are. permalink fedilink source parent [–] Bezier@suppo.fi 14 points 2 years ago (1 child) Could you please show how bitwarden can decrypt a vault that's locally encrypted by a foss client? "Imagine trusting any company with your passwords" permalink fedilink source parent hideshow 2 child comments replies: [+] Llewellyn@lemm.ee -8 points 2 years ago* (1 child) They created the client. In theory, they can have some backdoors. And since you store your files on their side, risk is greater, imo permalink fedilink source parent hideshow 2 child comments replies: [–] soul@lemmy.world 4 points 2 years ago* (1 child) This is where your lack of understanding of the open source thing is readily apparent to everyone arguing with you. If it was backdoored, many people would be calling that out. In fact, this was one of the exact reasons at the heart of the original concerns leading to this story. The fact that the source is available means that we can see exactly how the data is encrypted, allowing assurances to be made independently. If nothing else, I trust Bitwarden MORE because of that and I'm happy to pay them for their services since it helps find further development. permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee -4 points 2 years ago (1 child) If it was backdoored, many people would be calling that out. In theory. And not necessarily soon. Don't forget the context of this thread: we compare bitwarden with keepass, which does not offer to you your password base on their server side. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 1 point 2 years ago (1 child) Trusting one FOSS client good. Trusting different FOSS client bad. Logic where? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago (1 child) That different FOSS client stores your data on their company's server. It's an important factor, IMO. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Dude, how is bitwarden hosting your own, locally encrypted (in FOSS client) password database any different than using keypass and syncing it however you want? I don't even use Bitwarden myself, I'm using keepass too, but this attitude is ... weird? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago* (1 child) I find risk slightly bigger when you encrypt your private data with the product of the company and store that encrypted data on servers of the same company. Why: because if they have some backdoor now or plans to introduce it in future, they have all the time in the world to apply that backdoor to your data. Without you knowing it. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent
[–] Llewellyn@lemm.ee -4 points 2 years ago encrypted is the key word permalink fedilink source parent
[+] net00@lemm.ee -21 points 2 years ago* (last edited 1 year ago) (2 children) [deleted] permalink fedilink source parent hideshow 4 child comments replies: [–] Lettuceeatlettuce@lemmy.ml 37 points 2 years ago I don't think Microsoft can decrypt your DB file, neither do I think Bitwarden can. Encryption happens locally on their open source clients too. But I'm not the one disparaging trusting an open source program to securely encrypt passwords, you are. permalink fedilink source parent [–] Bezier@suppo.fi 14 points 2 years ago (1 child) Could you please show how bitwarden can decrypt a vault that's locally encrypted by a foss client? "Imagine trusting any company with your passwords" permalink fedilink source parent hideshow 2 child comments replies: [+] Llewellyn@lemm.ee -8 points 2 years ago* (1 child) They created the client. In theory, they can have some backdoors. And since you store your files on their side, risk is greater, imo permalink fedilink source parent hideshow 2 child comments replies: [–] soul@lemmy.world 4 points 2 years ago* (1 child) This is where your lack of understanding of the open source thing is readily apparent to everyone arguing with you. If it was backdoored, many people would be calling that out. In fact, this was one of the exact reasons at the heart of the original concerns leading to this story. The fact that the source is available means that we can see exactly how the data is encrypted, allowing assurances to be made independently. If nothing else, I trust Bitwarden MORE because of that and I'm happy to pay them for their services since it helps find further development. permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee -4 points 2 years ago (1 child) If it was backdoored, many people would be calling that out. In theory. And not necessarily soon. Don't forget the context of this thread: we compare bitwarden with keepass, which does not offer to you your password base on their server side. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 1 point 2 years ago (1 child) Trusting one FOSS client good. Trusting different FOSS client bad. Logic where? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago (1 child) That different FOSS client stores your data on their company's server. It's an important factor, IMO. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Dude, how is bitwarden hosting your own, locally encrypted (in FOSS client) password database any different than using keypass and syncing it however you want? I don't even use Bitwarden myself, I'm using keepass too, but this attitude is ... weird? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago* (1 child) I find risk slightly bigger when you encrypt your private data with the product of the company and store that encrypted data on servers of the same company. Why: because if they have some backdoor now or plans to introduce it in future, they have all the time in the world to apply that backdoor to your data. Without you knowing it. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent
[–] Lettuceeatlettuce@lemmy.ml 37 points 2 years ago I don't think Microsoft can decrypt your DB file, neither do I think Bitwarden can. Encryption happens locally on their open source clients too. But I'm not the one disparaging trusting an open source program to securely encrypt passwords, you are. permalink fedilink source parent
[–] Bezier@suppo.fi 14 points 2 years ago (1 child) Could you please show how bitwarden can decrypt a vault that's locally encrypted by a foss client? "Imagine trusting any company with your passwords" permalink fedilink source parent hideshow 2 child comments replies: [+] Llewellyn@lemm.ee -8 points 2 years ago* (1 child) They created the client. In theory, they can have some backdoors. And since you store your files on their side, risk is greater, imo permalink fedilink source parent hideshow 2 child comments replies: [–] soul@lemmy.world 4 points 2 years ago* (1 child) This is where your lack of understanding of the open source thing is readily apparent to everyone arguing with you. If it was backdoored, many people would be calling that out. In fact, this was one of the exact reasons at the heart of the original concerns leading to this story. The fact that the source is available means that we can see exactly how the data is encrypted, allowing assurances to be made independently. If nothing else, I trust Bitwarden MORE because of that and I'm happy to pay them for their services since it helps find further development. permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee -4 points 2 years ago (1 child) If it was backdoored, many people would be calling that out. In theory. And not necessarily soon. Don't forget the context of this thread: we compare bitwarden with keepass, which does not offer to you your password base on their server side. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 1 point 2 years ago (1 child) Trusting one FOSS client good. Trusting different FOSS client bad. Logic where? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago (1 child) That different FOSS client stores your data on their company's server. It's an important factor, IMO. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Dude, how is bitwarden hosting your own, locally encrypted (in FOSS client) password database any different than using keypass and syncing it however you want? I don't even use Bitwarden myself, I'm using keepass too, but this attitude is ... weird? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago* (1 child) I find risk slightly bigger when you encrypt your private data with the product of the company and store that encrypted data on servers of the same company. Why: because if they have some backdoor now or plans to introduce it in future, they have all the time in the world to apply that backdoor to your data. Without you knowing it. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent
[+] Llewellyn@lemm.ee -8 points 2 years ago* (1 child) They created the client. In theory, they can have some backdoors. And since you store your files on their side, risk is greater, imo permalink fedilink source parent hideshow 2 child comments replies: [–] soul@lemmy.world 4 points 2 years ago* (1 child) This is where your lack of understanding of the open source thing is readily apparent to everyone arguing with you. If it was backdoored, many people would be calling that out. In fact, this was one of the exact reasons at the heart of the original concerns leading to this story. The fact that the source is available means that we can see exactly how the data is encrypted, allowing assurances to be made independently. If nothing else, I trust Bitwarden MORE because of that and I'm happy to pay them for their services since it helps find further development. permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee -4 points 2 years ago (1 child) If it was backdoored, many people would be calling that out. In theory. And not necessarily soon. Don't forget the context of this thread: we compare bitwarden with keepass, which does not offer to you your password base on their server side. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 1 point 2 years ago (1 child) Trusting one FOSS client good. Trusting different FOSS client bad. Logic where? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago (1 child) That different FOSS client stores your data on their company's server. It's an important factor, IMO. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Dude, how is bitwarden hosting your own, locally encrypted (in FOSS client) password database any different than using keypass and syncing it however you want? I don't even use Bitwarden myself, I'm using keepass too, but this attitude is ... weird? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago* (1 child) I find risk slightly bigger when you encrypt your private data with the product of the company and store that encrypted data on servers of the same company. Why: because if they have some backdoor now or plans to introduce it in future, they have all the time in the world to apply that backdoor to your data. Without you knowing it. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent
[–] soul@lemmy.world 4 points 2 years ago* (1 child) This is where your lack of understanding of the open source thing is readily apparent to everyone arguing with you. If it was backdoored, many people would be calling that out. In fact, this was one of the exact reasons at the heart of the original concerns leading to this story. The fact that the source is available means that we can see exactly how the data is encrypted, allowing assurances to be made independently. If nothing else, I trust Bitwarden MORE because of that and I'm happy to pay them for their services since it helps find further development. permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee -4 points 2 years ago (1 child) If it was backdoored, many people would be calling that out. In theory. And not necessarily soon. Don't forget the context of this thread: we compare bitwarden with keepass, which does not offer to you your password base on their server side. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 1 point 2 years ago (1 child) Trusting one FOSS client good. Trusting different FOSS client bad. Logic where? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago (1 child) That different FOSS client stores your data on their company's server. It's an important factor, IMO. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Dude, how is bitwarden hosting your own, locally encrypted (in FOSS client) password database any different than using keypass and syncing it however you want? I don't even use Bitwarden myself, I'm using keepass too, but this attitude is ... weird? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago* (1 child) I find risk slightly bigger when you encrypt your private data with the product of the company and store that encrypted data on servers of the same company. Why: because if they have some backdoor now or plans to introduce it in future, they have all the time in the world to apply that backdoor to your data. Without you knowing it. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent
[–] Llewellyn@lemm.ee -4 points 2 years ago (1 child) If it was backdoored, many people would be calling that out. In theory. And not necessarily soon. Don't forget the context of this thread: we compare bitwarden with keepass, which does not offer to you your password base on their server side. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 1 point 2 years ago (1 child) Trusting one FOSS client good. Trusting different FOSS client bad. Logic where? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago (1 child) That different FOSS client stores your data on their company's server. It's an important factor, IMO. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Dude, how is bitwarden hosting your own, locally encrypted (in FOSS client) password database any different than using keypass and syncing it however you want? I don't even use Bitwarden myself, I'm using keepass too, but this attitude is ... weird? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago* (1 child) I find risk slightly bigger when you encrypt your private data with the product of the company and store that encrypted data on servers of the same company. Why: because if they have some backdoor now or plans to introduce it in future, they have all the time in the world to apply that backdoor to your data. Without you knowing it. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent
[–] kurcatovium@lemm.ee 1 point 2 years ago (1 child) Trusting one FOSS client good. Trusting different FOSS client bad. Logic where? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago (1 child) That different FOSS client stores your data on their company's server. It's an important factor, IMO. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Dude, how is bitwarden hosting your own, locally encrypted (in FOSS client) password database any different than using keypass and syncing it however you want? I don't even use Bitwarden myself, I'm using keepass too, but this attitude is ... weird? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago* (1 child) I find risk slightly bigger when you encrypt your private data with the product of the company and store that encrypted data on servers of the same company. Why: because if they have some backdoor now or plans to introduce it in future, they have all the time in the world to apply that backdoor to your data. Without you knowing it. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent
[–] Llewellyn@lemm.ee 0 points 2 years ago (1 child) That different FOSS client stores your data on their company's server. It's an important factor, IMO. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Dude, how is bitwarden hosting your own, locally encrypted (in FOSS client) password database any different than using keypass and syncing it however you want? I don't even use Bitwarden myself, I'm using keepass too, but this attitude is ... weird? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago* (1 child) I find risk slightly bigger when you encrypt your private data with the product of the company and store that encrypted data on servers of the same company. Why: because if they have some backdoor now or plans to introduce it in future, they have all the time in the world to apply that backdoor to your data. Without you knowing it. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent
[–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Dude, how is bitwarden hosting your own, locally encrypted (in FOSS client) password database any different than using keypass and syncing it however you want? I don't even use Bitwarden myself, I'm using keepass too, but this attitude is ... weird? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago* (1 child) I find risk slightly bigger when you encrypt your private data with the product of the company and store that encrypted data on servers of the same company. Why: because if they have some backdoor now or plans to introduce it in future, they have all the time in the world to apply that backdoor to your data. Without you knowing it. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent
[–] Llewellyn@lemm.ee 0 points 2 years ago* (1 child) I find risk slightly bigger when you encrypt your private data with the product of the company and store that encrypted data on servers of the same company. Why: because if they have some backdoor now or plans to introduce it in future, they have all the time in the world to apply that backdoor to your data. Without you knowing it. permalink fedilink source parent hideshow 2 child comments replies: [–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent
[–] kurcatovium@lemm.ee 0 points 2 years ago (1 child) Bitwarden client is FOSS same as Keepass, though. Why aren't you afraid of Keepass having backdoor by "insert whatever big corporation sponsoring FOSS" giving said companies free access to your passwords you happily store in their clouds? permalink fedilink source parent hideshow 2 child comments replies: [–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent
[–] Llewellyn@lemm.ee 0 points 2 years ago Keepass could have backdoors too. The difference is: authors of those backdoors are not from the same company, which I use as cloud storage. permalink fedilink source parent
[–] Dark_Arc@social.packetloss.gg 29 points 2 years ago* I do not trust bitwarden to encrypt my data anymore than anyone trusts keypass to encrypt my data. They're both open source and they both do the encryption locally; you're plainly mistaken. permalink fedilink source parent
[–] Appoxo@lemmy.dbzer0.com 7 points 2 years ago And you are aware that bitwarden knows nothing about the passwords inside the vault and the vault is encrypted in zero knowledge type of fashion? AND that Bitwarden does external audits? AND if you loose your master password you are out of luck as they can't support you helping crack the decryption? permalink fedilink source parent
[–] cley_faye@lemmy.world 6 points 2 years ago Except for the part that it's not a question of trust (being open source), there's no third-party architecture to trust (it can and should be self-hosted), the data on the server are also encrypted client-side before leaving your device, sure. Oh, and you also get proper sync, no risk of desync if two devices gets a change while offline without having to go check your in-house sync solution, easy share between user (still with no trust needed in the server), all working perfectly with good user UI integration for almost every systems. Yeah, I wonder why people bother using that, instead of deploying clunky, single-user solution. permalink fedilink source parent
[–] CarbonatedPastaSauce@lemmy.world 48 points 2 years ago Bitwarden can be fully self hosted, I'm doing it. My Bitwarden server doesn't (and can't) talk to them at all as it has no way to access the internet. They know nothing about my deployment except that I signed up for a free license key. permalink fedilink source parent
[–] kameecoding@lemmy.world 35 points 2 years ago (1 child) Are you a software developer ? Because you are way out of touch with what users want. permalink fedilink source parent hideshow 2 child comments replies: [–] drspod@lemmy.ml 3 points 2 years ago (1 child) I get why you'd suggest the previous commenter is out of touch with what users want, but what does that have to do with being a software engineer? permalink fedilink source parent hideshow 2 child comments replies: [–] kameecoding@lemmy.world 4 points 2 years ago (1 child) A joke about shitty developers. permalink fedilink source parent hideshow 2 child comments replies: [–] drspod@lemmy.ml 11 points 2 years ago permalink fedilink source parent
[–] drspod@lemmy.ml 3 points 2 years ago (1 child) I get why you'd suggest the previous commenter is out of touch with what users want, but what does that have to do with being a software engineer? permalink fedilink source parent hideshow 2 child comments replies: [–] kameecoding@lemmy.world 4 points 2 years ago (1 child) A joke about shitty developers. permalink fedilink source parent hideshow 2 child comments replies: [–] drspod@lemmy.ml 11 points 2 years ago permalink fedilink source parent
[–] kameecoding@lemmy.world 4 points 2 years ago (1 child) A joke about shitty developers. permalink fedilink source parent hideshow 2 child comments replies: [–] drspod@lemmy.ml 11 points 2 years ago permalink fedilink source parent
[–] Contravariant@lemmy.world 15 points 2 years ago Well, who did you trust to build your hardware? permalink fedilink source parent
[–] mac@lemm.ee 13 points 2 years ago (1 child) I used to use Keepass and sync thing and would consistently run into conflicts between my desktop and mobile entries. Maybe there's a better way to do it that I'm missing, but that was very annoying permalink fedilink source parent hideshow 2 child comments replies: [–] cley_faye@lemmy.world 2 points 2 years ago I use this setup for my personal passwords, using nextcloud as the sync solution. A semi-fix for that was using Keepass2Android (on Android obviously). It integrates with nextcloud directly, keep a local DB of passwords, and would only load the remote one (and merge) on unlock and updates, not keeping it "constantly" sync on every remote change. It works well… most of the time… with only two devices that almost always have connection to the server… and for only one user. It's overly clunky though. It's the big advantage of "service based" password manager against "single file based" ones. They handle sync. We have plans to move to bitwarden at my workplace, and since the client supports multiple accounts on multiple servers, I'll probably move to that for personal stuff too. The convenience is just there, without downside. permalink fedilink source parent
[–] cley_faye@lemmy.world 2 points 2 years ago I use this setup for my personal passwords, using nextcloud as the sync solution. A semi-fix for that was using Keepass2Android (on Android obviously). It integrates with nextcloud directly, keep a local DB of passwords, and would only load the remote one (and merge) on unlock and updates, not keeping it "constantly" sync on every remote change. It works well… most of the time… with only two devices that almost always have connection to the server… and for only one user. It's overly clunky though. It's the big advantage of "service based" password manager against "single file based" ones. They handle sync. We have plans to move to bitwarden at my workplace, and since the client supports multiple accounts on multiple servers, I'll probably move to that for personal stuff too. The convenience is just there, without downside. permalink fedilink source parent
[–] noxy@yiffit.net 4 points 2 years ago cuz being able to log in is handy sometimes permalink fedilink source parent