14 ms·
Bitwarden: Free, open-source password manager
- dang 7y agoPrevious discussions: 2019 https://news.ycombinator.com/item?id=18433144 https://news.ycombinator.com/item?id=18433144 2018 https://news.ycombinator.com/item?id=17503917 https://news.ycombinator.com/item?id=17503917 2017 https://news.ycombinator.com/item?id=15733540 https://news.ycombinator.com/item?id=15733540 https://news.ycombinator.com/item?id=14865932 https://news.ycombinator.com/item?id=14865932 https://news.ycombinator.com/item?id=14264117 https://news.ycombinator.com/item?id=14264117 2016 https://news.ycombinator.com/item?id=12676979 https://news.ycombinator.com/item?id=12676979
- theferalrobot 7y agoFor people who don't want to go through the trouble of self-hosting and also don't want to pay for a subscription I have had pretty good luck with Enpass. * It stores an encrypted file on a cloud storage platform of your choice (gdrive/dropbox etc) and syncs across devices. * No subscription fees
- itake 7y ago> Stores up to 20 items How is this possibly a replacement for Bitwarden considering they don't have any limits on the number of passwords for the free accounts?
- theferalrobot 7y agoYou pay once for cloud based sync instead of annually
- cassianoleal 7y agoI used Enpass for a little while a couple years ago. It was ok but not great. Eventually I decided to migrate off it and was not impressed by their export functionality. I had to literally go through every entry to make sure it made sense, check against the GUI to make corrections, and even then reimporting into either LastPass or 1Password was another full round of checking item per item. I hope it got better but if you're on it I'd advise you look into that as soon as possible as your database only tends to grow and with it the difficulty of migrating off when the time comes.
- jf 7y agoAs someone who has used 1Password for many years, how does Bitwarden compare?
- dev_dull 7y agoOn my opinion no reason to switch if you paid for the licensed version and don’t use safari on Mac. Definitely consider it over the $5/month subscription to 1Password or if you need shared vaults.
- itake 7y agoI have been using Bitwarden because its free for about 1.5 years. The UX experience is so bad on both mobile and extensions. If the extensions closes, like when you copy the password and paste it into the box, it looses its location, so you have to re-find the account, click on it, and then copy the username. You get what you pay for.
- viraptor 7y ago> If the extensions closes, like when you copy the password and paste it into the box, it looses its location, so you have to re-find the account That's not my experience. The account details stay open for me. For me the UX is not amazing, but ok. A bit better than LastPass, a bit worse than 1password.
- itake 7y agoThis happens to me on Firefox. https://recordit.co/QdK2FrRoYX https://recordit.co/QdK2FrRoYX I copy the password, go to paste it in and it loses the selected account: https://recordit.co/jrvUFWCPkS https://recordit.co/jrvUFWCPkS Here, I go to add an account. I generate a new password and then I try to paste it into the text box to verify it meets the website's password rules. I then go back to hit save, confirming that it worked and it loses the entry. Sooo frustrating.
- nightski 7y agoYou can just right click on the text box and use the context menu to make this task much easier.
- dev_dull 7y agoI’m a little put off by the login and service. It’s just one more thing that can be shut down. Especially since iOS and android allow syncing on remote services such as dropbox and iCloud (how it works in 1Password ver 6 and below). There’s really no necessary need for a centralize service. Create the encrypted vault in your preferred cloud storage service and locally and sync across all devices.
- TheThickOfIt 7y agoYou can always self host if you're worried about that
- edoceo 7y agoBitwarden can be self hosted and has apps for all the things.
- dev_dull 7y agoI’m not really looking to self host, just sync with an vault File via Dropbox, drive, iCloud etc.
- skinnyasianboi 7y agoJust self host and there is no thing like "can be shut down"
- dangom 7y agoYou are right. Yet hosting an encrypted 10kb for each user means that even if Bitwarden had a million free users it'd need no more than 10GB of cloud space to store all data. Consider syncing at startup or on adding new entries and the number of requests is also negligible. Not really a service that the company would ever had to cut to save money. What makes you so sure that dropbox and icloud will never be shut down?
- Wowfunhappy 7y ago> Not really a service that the company would ever have to cut to save money. That never seems to stop them. How much money could Google Reader possibly have cost to maintain?
- dangom 7y agoVery interesting. Has anyone been using it as a daily driver and could comment of safety, reliability and browser integration? How well do they behave compared to e.g. 1Password?
- jammygit 7y agoGood Linux support and no issues
- dragosiulian 7y agoI’m a very happy user (Firefox and iOS). Switched from LastPass about a year ago (found it on hacker news back then) and never looked back. I can’t compare it to 1Password, since I never used it.
- dorchadas 7y agoI switched from LastPass today, and already liking it a bit more. Not as slow and doesn't slow down on forms, for one!
- slimginz 7y agoSwitched to it after the most recent data problems with LastPass. It’s pretty good for me overall. The app and browser plugins are very similar but you do drop the icon on the right of text fields you can click to auto fill (There is an auto fill option but it’s in beta and slightly buggy). Overall though, I’m happy with it especially since it’s open sourced.
- codewritinfool 7y agoMe too. Also, there are some sites where LastPass could never manage to find the login fields and didn't fill them correctly or at all. I've yet to see Bitwarden screw this up.
- kerpele 7y agoI use on Mac (Firefox & Safari) and iPhone, wife uses on Mac (chrome) and Android. Neither has had any issues in the past year and a half outside of mild confusion about the new Safari extension after Apple removed support for the old extension format.
- sdan 7y agoI'd still much rather stick with https://www.passwordstore.org/ https://www.passwordstore.org/. It's encrypted with your keys (which I didn't see on Bitwarden's site) and has plugins for Chrome/Firefox (you can setup keyboard shortcuts to fill in your info automatically as well) and works with Git. Although it is a bit of a hassle to setup on mobile devices (I use Pass for iOS), the security and functionality it provides is worth it.
- edoceo 7y agoHow about sharing password with a team?
- notpiika 7y agoYou can use gopass[0] for that. It's pass but with syncing capabilities. [0]: https://www.gopass.pw https://www.gopass.pw
- edoceo 7y agoI should have said non-technical team. Currently we're kicking around passbolt - but, if there is time on Feature-Friday I want to eval BW
- sdan 7y agoIn this case, Pass is probably not the right solution for you. It's a bit hard to setup keys and then share them over Git... which is most likely a bit too complicated. This being said, QtPass is a GUI for Pass, but not the best when compared to stuff like Bitwarden (presumably, haven't used it) or Lastpass.
- pedrogpimenta 7y agoI'm interested. Is it more secure than KeePass?
- jsmith99 7y ago
- joe_the_user 7y agoYou know, I just had a thought. What I would like is password protected, "password notepad". When activated, it remembers the text of passwords, shows it to you in text when you go to a website and then you type it into the site. (people looking over your shoulder is a way overestimated danger, the password-hiding thing dates to shared terminals). The thing I hate about password managers is I am afraid I would stop knowing my passwords. This would allow me to remember my passwords since I would type them each time. I've only seen Firefox and Chrome's built-in password managers so maybe this exists already. But it seems a decent way to do it.
- Ao7bei3s 7y agoYour proposal: * Encourages bad (easy to type, and potentially memorable) passwords and password reuse (probably the single best way to get compromised). (I have several hundreds of unique passwords.) * Makes phishing easier. (People are bad at consistently checking the URL bar correctly char for char and every time.) * Is inconvenient. * Can be done with any existing password manager. * About shoulder looking... I don't know about you, but I frequently need my passwords at work when colleagues are watching, or when I'm sharing my screen in a (often recorded) conference call.
- joe_the_user 7y ago"Encourages bad passwords" - It seems pretty implausible a sequence of word-number-word-number is going to be inherently that weak. "Makes phishing easy" - The manager would be checking the URL bar in the same fashion as a regular password manager. "Is inconvenient" - Is not terribly inconvenient "Can be done with any existing password manager" - Great, I suppose I should just get started using them then.
- viraptor 7y agoIf you can remember your passwords, they're likely not great passwords to begin with. I've got hundreds of logins and remember only 2 - the password manager one and gmail which a lot of important things hang off of. The big issue these days is users sharing a password between sites, so having them unique/random is the game.
- m_sahaf 7y agoThere's compatible Bitwarden server written in Rust called bitwarden_rs[0] for those who don't want to run the official Docker image with the requirement of Microsoft SQL Server and the demand for 2GiB of RAM. [0] https://github.com/dani-garcia/bitwarden_rs https://github.com/dani-garcia/bitwarden_rs
- Karupan 7y agoIf anyone is looking to cross compile bitwarden_rs for the Raspberry Pi, I documented the steps in a gist[0] [0] https://gist.github.com/Checksum/5c604c8d1180dd060aebf51026215977 https://gist.github.com/Checksum/5c604c8d1180dd060aebf510262...
- odensc 7y agoIs there a reason you couldn't use the official `raspberry` Docker tag?
- odensc 7y agoIt's listed here: https://github.com/dani-garcia/bitwarden_rs/wiki/Which-container-image-to-use https://github.com/dani-garcia/bitwarden_rs/wiki/Which-conta... Says it works on Raspberry Pi 2 or newer. Do you have a 1?
- StavrosK 7y agoDoes that give you access to all the features, or do you still need to pay?
- brunoqc 7y agoI wish the Bitwarden mobile app would support multiple accounts so I could use a server at work and another server for my personal stuff.
- wideasleep1 7y agoI just sign in as another (email) user.
- ViViDboarder 7y agoThat would require logging out and back into the mobile client every time they leave and start work... that’s pretty tedious.
- wideasleep1 7y agoNot at all..a few clicks. Safer, as well...I use email addresses no one else knows.
- ViViDboarder 7y agoHmm. That’s a good point. Do other apps do this? I had already left LastPass for KeePassXC by the time my company adopted LastPass, so I’m not sure how other apps handle this.
- h4waii 7y agoYou can probably install and run it under a different "user". If you're using Android, Shelter [0] and Island [1] can provide isolation, depending how your device is configured. Shelter is FOSS, Island is not. 0. https://f-droid.org/en/packages/net.typeblog.shelter/ https://f-droid.org/en/packages/net.typeblog.shelter/ 1. https://island.oasisfeng.com/ https://island.oasisfeng.com/
- alistproducer2 7y agoGiven the requirements of self hosting, ill just stick with keepass. The desktop and mobile clients are great and I can host them on my nextcloud and grab them over WebDAV.
- StavrosK 7y agoI use BitWarden but Keepass2Android is the best mobile client of any platform, by far.
- christilut 7y agoYou can self host Bitwarden or use the cloud version
- alistproducer2 7y agoI should've been more clear. I don't host the clients; rather, I host the databases. That's why I prefer keepass - it's just an encrypted db which is lightweight and the clients tend to be lightweight as well.
- IronWolve 7y agoIts good for personal use, but enterprise features are weak/missing and the layout isnt very enterprise ready. I tried their "Organizations" feature out to see if I could deploy it at work instead of teampass, and it wasn't comparable. They are still fixing and developing, so it might be enterprise ready someday. It really is a nice with all the addons. I use the bitwardern docker version for people to use, I have it installed, but for my own use, sticking with keepass.
- justin_oaks 7y agoI reviewed Bitwarden for use in my company a few months ago. I discovered that there was no way for an admin to allow the recovery of an account (i.e. allowing a master password reset). This is a non-starter in my organization since some small percentage of the users will forget their master password. Has anyone else been successfully using Bitwarden in a team setting? If so, how do you work around the limitation I mentioned and other such things?
- nine_k 7y agoI suppose it's for the same reason as why you cannot reset your forgotten private SSH key. Secrets are only stored encrypted, and the key is derived from the master password, not known to any admins. Cracking the admin account or the entire server gives the intruder very little. So, it's a feature. You may not want this feature, though.
- paulddraper 7y ago> you cannot reset your forgotten private SSH key. You can though. If you lose your private SSH key, you regenerate it, and the server admin resets your public key. Zero data loss. I think the better analogy would have have been a disk encryption key. But note that consumer facing encryption tech (Mac, Windows) generally doesn't stick to "user forgot key = user lost data". > So, it's a feature. You may not want this feature, though. Yeah, I must agree I do not want this. I understand it is more secure but it is also more user hostile. I'll take the risk of a compromised admin (assuming strong password and TFA of course) over "sorry you lost all your data." Data integrity is just as much a part of security as data privacy.
- amcsi 7y agoThough whatever data is "lost" in a password manager is usually recoverable; each password could be individually reset in each website. True though that it's a pain.
- paulddraper 7y ago
- infinityplus1 7y agoThere are no screenshots of the UI on the homepage. Adding them would be helpful.
- strathos 7y agoI found the pricing to be a bit confusing. I'm self-hosting it now and been happy with it, but when installing for the first time I couldn't find how to share some of the passwords with another user. Well it turned out that in self-hosted instance you don't have that possibility to share to another user without a paid license. Ok, fine by me so I bought the one year premium for the self-hosted instance as from one of the tables in their website it said that would be needed. So now I had the one year premium with all the nice features but still I couldn't share passwords. Importing the license key to create an organization (for sharing) failed every time. I contacted their support and found out I had just misunderstood the pricing. To create an organization you need an organization license, which was another roughly ten euros a year. After bying that I had it working as I wanted. Their support also gave the possibility to get money back from the unneeded personal premium license as it wasn't needed for my usecase, but I kept it as I found the price to be quite ok. So that might have sounded like a rant, but my only issue was that I didn't understand the pricing for self-hosted. My one year is up soon and I will be renewing my license as we've (as in me and my wife) been happy with Bitwarden.
- chmars 7y agoIn 1Password, you cannot share passwords at all … (Sharing is useful if you set up new accounts for other users.)
- bad_user 7y agoWe've been using Bitwarden at work, the Teams plant, paying $15 per month, or $180 per year for 10 users. The only reason for why I picked it is its open source nature, otherwise I would have gone for 1Password Teams. The pricing is odd. For example you can't self host it yourself without paying for a license. The code is AFAIK open source, so you could maintain your own fork with the required code branches removed, if you wanted to. I do hope the author doesn't pull a bait and switch, after enough users go down this route. Don't get me wrong, I'm actually not looking into hosting it myself, I'm glad to pay for a hosted service, but with open source I want that possibility to be there and I don't want licensing per user for self-hosting either. And currently I like what the author has been doing. Adding some code in there that makes it require a license, but that you can remove, is totally fine. But I'm seeing more and more open source apps turning proprietary nowadays and I don't look kindly to such bait and switches, because I end up using those apps because they are open source. Like it is the case for Bitwarden, otherwise there are often better proprietary options available. From a usability standpoint, Bitwarden is unfortunately inferior to 1Password in every way. But it works fine for our purposes, for now. And Bitwarden is better than LastPass in case you're wondering, even if it has some missing features. The official servers are slow. I just had multiple login failures. I'm assuming that it's experiencing issues due to being featured on HN right now, but this isn't the first time that it's happening. But as long as it is _open source_ and as long as it does a reasonable job, then I'll keep supporting it. Because I'd rather pay for open source solutions.
- thatsnotmepls 7y agoDoesn't it bother you that even though it is open source, it is essentially maintained by one person [1]? What happens to the SaaS offering if he gets run over by a car? [1] https://github.com/bitwarden/server/graphs/contributors https://github.com/bitwarden/server/graphs/contributors
- bad_user 7y agoOpen Source means that it can be forked. If that guy gets hit by a bus and if the app is useful enough (and it is), then a fork will happen. And I can always do some contributions myself. And if I'm wrong and that fork doesn't happen, then nobody (with resources) wants it, in which case might as well let it die. The bus factor for open source stuff is great, even with zero contributors at any point in time. In contrast when a proprietary app gets killed (either due to acquisition or b/c it's not profitable) then it's gone for good. If a proprietary app changes, to include ads or anything that you don't like, there's absolutely nothing you can do but switch to something else or bend over.
- fbnlsr 7y agoI've switched from KeePassXC, stored on my Google Drive with an offline key file, to BitWarden last month. I previously was a customer of LastPass and switched to KeePassXC after being tired of LastPass' UI mess. Anyways, BitWarden works absolutely flawlessly. There are a few things here and there that I'd wish it had, like the ability to create templates for custom categories, but apart from that, it does an amazing job. The websites autocomplete works really well, and I was pleased to see that I can unlock my vault on my phone with my fingerprint reader. Migrating data from KeePassXC to BitWarden went smoothly. I took a moment to clean my database and reorganize a few stuff. The database takes a bit of time to load, but nothing that's a real bother. The only thing I don't store in BitWarden is the 2FA TOTP I use (mainly Google Authenticator) as I feel it breaks the entire concept for 2FA. I've seen people on HN do it, but to me it just feels wrong.
- flanbiscuit 7y agoI currently use KeePassXC and think it's great. What made you switch? BitWarden seems interesting but it's not completely free and you'll need their servers (or you can set one up yourself). Granted I also use Google Drive to sync my KeePass db so I'm also using someone else's servers but I've been considering changing that to syncthing to cut out the server.
- DeadBabyOrgasm 7y agoI'm also curious about the same thing. Ever since I started using KeePassXC's autotype feature, I haven't been able to go to any other password manager. Even with the degraded mobile options and having to build my own syncing with things like rclone. Does Bitwarden have that autotype option? If not, I'm wondering how difficult it would be to build it myself, if only for the desktop clients.
- thatthatis 7y agoFor business users, can a single password be stored in multiple “shared folders” or groups? For example, can I share a password with both “marketing” and “customer support” The lack of this is one of the biggest pains I have with LastPass
- rolandboon 7y agoYes, that feature is called "Collections". An item (login, card, secure note, etc.) can be shared into multiple collections (only within one organization). For each collection per user permissions (none, read, write) can be set.
- rb666 7y agoBig fan of Bitwarden! I have tried almost all the password managers over the last few years, and this is the one I finally settled on. Every previous one had some element that bothered me or was principally wrong.
- thrownaway954 7y agomy only gripe with Bitwarden is that it only allows one login per website that I've seen. At work we use DashLane cause you can have multiple saved logins per website, which is a God send when dealing with multiple clients. Bitwarden is great for personal use, but I can't use it at work cause of this one missing feature. If anyone knows of a way to make it have multiple logins per site, I'm all ears as I would love to get rid of DashLane and it's horrible Chrome Extension.
- tsegratis 7y agoAny subdomain seems to be enough. For instance I have two bitwarden logins: 1) support.server.com 2) server.com Both are always available, no matter it's for www.server.com or mail.server.com
- thatsnotmepls 7y agoAre you saying that I can only have one saved account for say twitter.com? That's definitely a killer for me.
- ViViDboarder 7y agoI’m not sure what OP is on about, but I’ve got plenty of sites with multiple logins just fine... I’m using Bitwarden_rs as a server, but the official Apps all support it great, so it would strike me as a surprise if the official server didn’t have this ability too.
- brewdad 7y agoHe's wrong. I have nine Twitter accounts saved on my Bitwarden. I don't use more than 2 currently, but I've played with different ways to differentiate my interests/follows over the years, and have never had any issues with multiple logins. In fact, Bitwarden moves your most recently used login to the top of the list so you don't have to hunt for it.
- rson 7y agoYou absolutely can have multiple accounts per website. Just add an additional entry to the vault using the same url.
- theta_d 7y agoI find it ironic that they claim "[s]ource code transparency is an absolute requirement for software solutions like Bitwarden" on their website yet they require SQL Server 2017, a completely proprietary RDMBS.
- Unklejoe 7y agoI don't think it's that ironic. All of the software written by "Bitwarden" is open source. The fact that it uses some pre-existing propriety software doesn't change that. If it did, then that logic could really be extended to any piece of software written for Windows.
- theta_d 7y agoIt's ironic b/c they claim source code transparency is an absolute requirement yet they rely on something that is not source code transparent to store the data. You can write open source code for Windows all day long and it doesn't change the fact the your code is open source. However, to claim that you need transparency for your security product and then build it on top of a proprietary storage engine is incongruent.
- floatboth 7y agoSecurity requirements all apply to the client side. The storage on the server doesn't matter. You could upload directly to the NSA and it will still be fine. Also, there are many server implementations other than the official one.
- e12e 7y ago> they rely on something that is not source code transparent to store the data. They rely on it to store encrypted data. If I recall correctly they use an authenticated aes cipher - and the Free software part can verify that correct data is read back (ie: it decrypts and authenticates).
- Tepix 7y agoThere's an unofficial rust implementation that uses SQLite https://github.com/dani-garcia/bitwarden_rs https://github.com/dani-garcia/bitwarden_rs
- Unklejoe 7y agoI just set up my own Bitwarden server the other day using bitwarden_rs, a third-party implementation written in Rust. It basically gives you all of the premium features for free, as opposed to the official server which requires a license. I really wanted to run the official server, but they offered no option of a lifetime license (only a yearly license). For what it's worth, I would have been willing to pay a lot more for a license that never expired. The whole reason I'm hosting the server myself in the first place is because I want _full_ control, so a subscription based license doesn't really fit well there. Given that the project is licensed under the GPL, the license is effectively a donation anyway, so I hope they consider offering a lifetime license for those who want to self-host.
- pkalinowski 7y agoI'm using Bitwarden and 1Password at the same time (private and company use). 1Password pros: * very polished UI, pleasure to use * good UX in general 1Password cons: * I have constant issues with it loosing connection with browser. Extension just randomly stops working for few days. Tried to fix it multiple times, never succeeded * Price (too expensive for my private use) Bitwarden pros: * Free * Very simple app, easy to use * More reliable than 1Password for me * Fills login pages quicker than 1Password * Feels quicker and more snappy than 1Password Bitwarden cons: * Lacks 1Password polish, generally UX and UI needs some work * Can't login using fingerprint on Mac * Crashes on my iPad when trying to save new credentials (need to report it as a bug, but I didn't go around to it yet) * Slow on Android All in all, I'm very satisfied with Bitwarden and use it daily.
- davefp 7y agoI have the same situation, Bitwarden for personal use and 1pass at my job. 1pass does a few things better (2FA, background agent so I don't have to log into the browser and desktop app separately, general level of polish), but apart from that they're largely interchangeable for me.
- not_a_cop75 7y agoIf everyone took your advice and used 1pass, then I doubt 1pass would be able to defend itself against the coming hack attacks. I do say this in a bit of ignorance, but they don't imho possess the resources to defend against the complete list of cybercriminals out there.
- herohamp 7y agoCan I get a source for this? This just seems like a meatless claim meant to harm a company
- amdavidson 7y agoWho do you suggest does have the resources? Bitwarden is essentially the work of one person[0]. Are you suggesting that we only rely on Apple Keychain and Chrome password sync due to their MegaCorp backing? 0: https://github.com/bitwarden/server/graphs/contributors https://github.com/bitwarden/server/graphs/contributors
- mwexler 7y agoBitwarden has changed my life: it's the first password manager I can get my family to use. The commercial ones all had ads or upsells that interfered with the experience, while Bitwarden just worked. Props to this creation.
- shelune 7y agoI changed from LastPass to Bitwarden. Have been quite satisfied with it so far. The save suggestion was annoying sometimes but overall everything works pretty fine. Would recommend it to everyone in need of a password manager now.
- RHSeeger 7y agoIs it possible to migrate (export then import) data from bitwarden? I'd like to sign up for a free account, and I'm wondering if I'd be able to move my data to a private (bitwarden_rs) instance later.