15 ms·
I recently made the switch from LP to bitwarden and have been incredibly happy about it. I can self host everything + the autofill and UI polish (browser extens
by gcommer 8y ago
I recently made the switch from LP to bitwarden and have been incredibly happy about it. I can self host everything + the autofill and UI polish (browser extensions, mobile app, CLI) is much better. AND it's FLOSS ((A)GPLv3).
Even including the self hosting setup, my all-in migration time was <30 minutes.
I looked through a ton of other options like keepass and the author's own PfP. But mobile, web, and yubikey support are all very important requirements for me.
- hughes 8y agoI love bitwarden also. Having tried a few password managers, it has the most pleasant mobile experience.
- kevingrahl 8y ago+1 for Bitwarden! Switched to it somewhat over a year ago from LastPass after I read up on LastPass’ ‘security’. The only thing I dislike about Bitwarden is that on their iOS app it sometimes takes a while (>30s) to load the search function. I love that their chrome extension has a dark mode!
- toyg 8y ago30s seems a lot, I never see that. Maybe it depends on the amount of pwds saved...
- kevingrahl 8y agoI do have quite a lot of entries..
- lazycouchpotato 8y agoTheir Android app is notoriously slow as well in search.
- zaphodq 8y agoSame here migrated to bitwarden from lastpass. So far my experience with bitwarden has been great. Bitwarden apps are very good.
- latchkey 8y agoOk, I'll bite... I tried to import from LastPass and ran into this error: https://github.com/search?q=org%3Abitwarden+exceeds+the+maximum+encrypted+value+length&type=Code https://github.com/search?q=org%3Abitwarden+exceeds+the+maxi... So the notes fields can't store more than 10k, which isn't going to work for me at all. Update: Found this python script and ran it. https://github.com/bitwarden/web/issues/194#issuecomment-464468578 https://github.com/bitwarden/web/issues/194#issuecomment-464... Only had two notes that were too long. Added them in by hand. Problem solved.
- tluyben2 8y agoI love Bitwarden but this is indeed a big and weird pain.
- senectus1 8y agoseriously, send a support request in. the Main dev is very responsive... will even have a chat on Reddit if you're inclined.
- latchkey 8y agoI did. Linked me to the article saying to hand edit my CSV file to figure out which fields are too big and delete the data. This is a years long outstanding issue. https://help.bitwarden.com/article/import-data/#troubleshooting-import-errors https://help.bitwarden.com/article/import-data/#troubleshoot...
- deleted 8y ago[deleted]
- donkeyd 8y agoIn the comments on the article, someone asks about Bitwarden. The author mentions there's a possible vulnerability, but in depth research isn't worth it, because he doesn't get paid for reporting vulnerabilities. This scares me about all these 'better than Lastpass' open source alternatives. First, they tend to get less attention from the infosec community. Secondly, I need to make sure to properly secure the server I'm running it on myself, of which I'm not 100% sure I can do myself, nor most developers I've worked with, let alone any person not working in IT.
- htfy96 8y agoBitwarden paid for a third-party security audit last year and no major issues were found.[0] They also have their own bug bounty program at [1]. [0]: https://cdn.bitwarden.net/misc/Bitwarden%20Security%20Assessment%20Report.pdf https://cdn.bitwarden.net/misc/Bitwarden%20Security%20Assess... [1]: https://hackerone.com/bitwarden https://hackerone.com/bitwarden
- org3432 8y agoAudits can be hit and miss, I’ve seen high quality code review companies just miss major and obvious mistakes in the security by simply not tracing the execution logic step by step in critical code sections and instead just scan the code for common known mistakes based on code fragment matching.
- craftyguy 8y ago> Audits can be hit and miss, The same could be said for proprietary applications, which may never see third party audits because 'meh, customers have no access to our source and IP protection or something'
- zulln 8y agoThey have a vulnerable disclosure program, not bug bounty, as they are not paying for bugs reported there. Which is a shame, I have reported bugs to a lot of other password managers, but will not dedicate time to one that is not paying me for it.
- rahulrrixe 8y agoI second it. I also switched from LastPass to Bitwarden. The main reason was now my data which are online is more valuable than it used to be a few years ago and I don't want to be the scapegoat of their failure in case if it happens. Another reason, It has a polished app and works flawlessly on all the platforms and I can host it myself.
- Fire-Dragon-DoL 8y agoHow did you perform the switch? I reviewed lastpass export function and it outputs an entirely non compliant csv file. It's probably impossible to parse...
- ZeWaren 8y agoAlso very happily self hosting bitwarden. Bitwarden is using Microsoft technologies. If running a MSSQL server is too much for you, you can use alternative servers which are fully compatible with the official clients: - https://github.com/dani-garcia/bitwarden_rs https://github.com/dani-garcia/bitwarden_rs - https://github.com/jcs/rubywarden https://github.com/jcs/rubywarden
- eeZah7Ux 8y ago...but it's written in node