In the latest episode of "they will always sell you out" - they sold you out! Who would've thought.

Hoping for a good alternative client to appear, the writing is on the wall. Vaultwarden can't exist without "leeching" off of Bitwarden.

you are viewing a single comment's thread
view the rest of the comments
[–] 31 points 3 months ago (46 children)

KeePass isn't going anywhere. They're also dragging their feet on passkey support, so you might go with KeepassXC.

  • source
  • parent
  • hideshow 46 child comments
  • [–] 18 points 3 months ago (8 children)

    @slate

    Wasn't there some commotion a few weeks about KeepassXC and vibe coding?

    @RonnyZittledong

  • source
  • parent
  • hideshow 8 child comments
  • [–] 34 points 3 months ago* (last edited 3 months ago) (6 children)

    Yeah, there was. It was forked because of that, actually: https://codeberg.org/ChiPass

  • source
  • parent
  • hideshow 6 child comments
  • [–] 9 points 3 months ago (23 children)

    They also don't effectively allow collaboration though, which is my cheif reason for using a cloud hosted password manager.

  • source
  • parent
  • hideshow 23 child comments
  • [–] 5 points 3 months ago (13 children)

    What is "collaboration" in this context?

  • source
  • parent
  • hideshow 13 child comments
  • [–] 7 points 3 months ago (10 children)

    Sharing passwords between groups of people so everyone always has the up to date version. Not breaking the world if two people try to modify the same entry as some file syncing solutions do.

  • source
  • parent
  • hideshow 10 child comments
  • [–] -3 points 3 months ago (9 children)

    Hmm, interesting, though isn't that a fault of the organization not having an account-linking system so that each person could have their own credentials but can still access the unified content? This workaround seems... flimsy, unless I'm not picturing a legit scenario in which no other method is as good, or something.

  • source
  • parent
  • hideshow 9 child comments
  • [–] 3 points 3 months ago (2 children)

    It's the fault of my family organization or every company we use that my parent's bank, Google, phone, laptop, etc don't allow more than one set of credentials to access the same thing?
    It's not just that we need to be able to share credentials the once a blue moon I need to help them by logging into their account?

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 3 months ago* (1 child)

    Wait, I don't understand. Why do you need to do so much account-sharing? I never had half of that... and if connecting is just once in a blue moon, then it shouldn't need something like group creds anyway, right?

  • source
  • parent
  • hideshow 1 child comment
  • [–] 2 points 3 months ago

    I have credentials shared with my parents passwords managers (and others) so when they ask for help with a service I can do it remotely for the services they want help with, but not their whole password manager.

    I share company passwords in an organization so I can manage user accounts for things a user needs into but doesn't want to manage (I can change the Snowflake password but they can still login).

    I share common passwords with everyone in the house (gate codes, door codes, etc). Then when they need to change, no one is bothered or needs to take action. Also, then anyone can change it and everyone who should have the new one, does.

  • source
  • parent
  • [–] 2 points 3 months ago (3 children)

    You know why most cloud based services charge money? For stuff like this, because it’s not free to implement and maintain.

    Easy and fault-proof password sharing and syncing needs software and hardware to do. You either set it up and maintain it yourself, or pay for a product that does it - like Bitwarden.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 0 points 3 months ago* (2 children)

    But your argument falls apart against something like Syncthing's discovery networks combined with send-/receive-only folder types, which use no cloud yet allow the automatic, passive propagation of file updates to different users' devices... right? No cloud, no self-hosting, yet automatic syncing across multiple devices...

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 3 months ago (3 children)

    KeePass isn't meant to be used that way. It's a personal password manager. Always has been.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 4 points 3 months ago (2 children)

    Valid. But it's also valid that it now doesn't work for me or anyone who also helps manage other people's lives or works on a team ¯_(ツ)_/¯

  • source
  • parent
  • hideshow 2 child comments
  • [–] 0 points 3 months ago (4 children)

    Sure they do. Multiple people can have a file open at the same time. I use it for exactly this every day at work.

    With KeePassXC, that is. I don't know if other flavors have different support. I use XC primarily for the browser extension.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 3 points 3 months ago (3 children)

    And you can both modify the same things without causing horrible conflict issues? And you can share only parts of your vault with someone rather than having entirely different vaults you have to switch between? I'm assuming you mean putting the file somewhere like Google Drive, and you can access it offline even if you can't edit it offline? For feature parity with Bitwarden, obviously ideally one could edit any time and it would resolve problems when it came back online if there were any but Bitwarden doesn't allow this.

  • source
  • parent
  • hideshow 3 child comments
  • [–] -1 points 3 months ago (2 children)

    Yes, no conflicts. I don't know if you can only share part of vault; I just created a separate one for a separate team.

    I wouldn't put it in Google Drive or anything like that. The separate sync logic will definitely cause conflicts.

    I'm not worried about having access if I'm offline, because if I'm offline I'm not going to be able to log into anything anyway.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 3 months ago* (1 child)

    I guess a laptop, server, IoT device, or WiFi connection when your main device doesn't have internet is out of scope for you?
    Like fixing my laptop and not wanting to type the new password into my phone instead of copy/paste, sync when online?
    And how are you sharing a file, to multiple people anywhere in the world realtime ish, without a cloud service you or someone else hosts? Doesn't that necessitate some syncronization logic?

  • source
  • parent
  • hideshow 1 child comment
  • [–] -5 points 3 months ago* (12 children)

    They’re also dragging their feet on passkey support

    As... they... should, forever.

  • source
  • parent
  • hideshow 12 child comments
  • [–] 20 points 3 months ago (11 children)

    Two articles behind a paywall, one that won’t load, and another article that says the big problem with passkeys is…people are unfamiliar with them.

    If anyone tells you that Passkeys are bad, they’re a liar. Way more safe than passwords, full stop.

    Just don’t let Microsoft or Apple tie them to your device. You don’t have to do that.

  • source
  • parent
  • hideshow 11 child comments
  • [–] 6 points 3 months ago (6 children)

    Are you calling me a liar? That's pretty weird; it's not like I'm telling you to stick to passwords while I move to passkeys. With that said, though, get Bypass Paywalls Clean (Mozilla-only, as far as I know) and you'll never see another paywall again. I forgot about having that.

    Just don’t let Microsoft or Apple tie them to your device. You don’t have to do that.

    The problem is that this is where it's eventually going to lead to.

  • source
  • parent
  • hideshow 6 child comments
  • [–] 3 points 3 months ago (3 children)

    Not really, Vaultwarden/bitwa4den offer passkey support. When I log into a service a popup shows on my extension, I click it and I'm in. It's not gonna lead to device locking if you don't want to...

  • source
  • parent
  • hideshow 3 child comments
  • [–] 2 points 3 months ago (2 children)

    except when the wide populace starts accepting it being device locked, and your opinion does not matter anymore to those making the decisions

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 3 months ago* (1 child)

    No one of the people I know that use passkeys use it from the phone, either they use a password manager, they have passwords on a physical note, on an excel file in the desktop, a physical yubikey, or bitwarden like me. That's everyone I physically know including every family member, friends and work people.

    I know it's anecdotal, but you present your "wide populace" fact without giving sources too, and since I know no one that uses phone based passkeys, even if my experience is anecdotal, I say sus. Check your bias.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 3 months ago

    but you present your "wide populace" fact without giving sources too

    my statement is not that many people are using passkeys today. but that if there comes a time when many people will use passkeys, they will be as careless and convenient as they are with everything else today, accepting any restrictions, because "why would anyone not use Google Passkeys? It's the most convenient thing!".

    and not only that. I was talking about device locking but that's only part of the problem. isn't it that passkey receiving services can identify the client software, and decide they will only accept passkeys from x and y clients?

  • source
  • parent
  • [–] 3 points 3 months ago (1 child)

    At the very least you're misguided or don't know what you're talking about. Passkeys are not vendor locked in and of themselves.

    You can make the same argument against password managers because most iPhone users that use them, use Apple's one.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 6 points 3 months ago* (last edited 3 months ago)

    They will almost certainly lead to vendor lock in. Why do you think they won't? Apple's password manager is definitely an example of vendor lock in. Many others have a simple to use export feature to CSV or something that others can understand

    Edit: it could be that you don't know what the WebAuthn/FIDO2 specification says or we understand it differently? Do you know how the attestation mechanism works? That ties the key to a device or software authenticator (the software authenticator is likely going to tie it to the device somehow, possibly even via a TEE).

  • source
  • parent
  • [–] 3 points 3 months ago (3 children)

    There is no full stop there... A password that is sufficiently long will never be cracked no matter the hashing algorithm in use. Passwords are easily transferrable and can be communicated to a third party in the event of an emergency. They also provide tunable security, where you can trade off security for convenience if you want.

    Some (not all, I know) passkeys are tied to a device. Stolen device means stolen passkey, and it's potentially very difficult to recover from that. Passkeys are also locked to a certain standard, passwords have no such restrictions.

    Tbh I don't understand the move for passkeys replacing passwords. They should become the second factor when a user wants additional security. They're perfect for that niche.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 4 points 3 months ago

    Passkeys provide a secure way to authenticate while also being convenient. With the tradeoffs you mentioned.

    I don’t like the push for only allowing some vendors to issue keys and to not allowing exporting and backups. And password should still be an option.

  • source
  • parent
  • [–] 1 point 3 months ago (1 child)

    Password can also very easily be stolen during phishing, while passkeys are phishing resistant.

    And while a hardware passkeys can be stole and used, those who steal them will still need the pin to use them, and the two major hardware passkeys options now (Yubico and Token2) both have some pin brute force protection in their firmware to slow someone down long enough for an account to be secured another way.

    As for passkeys on phones, they require the pin or biometric used to unlock the phones to be used.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 3 months ago*

    "Difficult to recover from" was referencing setting all of your accounts back up. I should have also included "lost" and "broken" to make that more obvious. Many hardware (most? all?) passkeys do not allow for backup and restore.

    But I do see an issue with stolen hardware passkeys being used for access too if they're a primary factor. With the mitigations you mentioned hopefully holding up.

  • source
  • parent