4 ms·
I find it ironic that they claim "[s]ource code transparency is an absolute requirement for software solutions like Bitwarden" on their website yet they require
by theta_d 7y ago
I find it ironic that they claim "[s]ource code transparency is an absolute requirement for software solutions like Bitwarden" on their website yet they require SQL Server 2017, a completely proprietary RDMBS.
- Unklejoe 7y agoI don't think it's that ironic. All of the software written by "Bitwarden" is open source. The fact that it uses some pre-existing propriety software doesn't change that. If it did, then that logic could really be extended to any piece of software written for Windows.
- theta_d 7y agoIt's ironic b/c they claim source code transparency is an absolute requirement yet they rely on something that is not source code transparent to store the data. You can write open source code for Windows all day long and it doesn't change the fact the your code is open source. However, to claim that you need transparency for your security product and then build it on top of a proprietary storage engine is incongruent.
- floatboth 7y agoSecurity requirements all apply to the client side. The storage on the server doesn't matter. You could upload directly to the NSA and it will still be fine. Also, there are many server implementations other than the official one.
- e12e 7y ago> they rely on something that is not source code transparent to store the data. They rely on it to store encrypted data. If I recall correctly they use an authenticated aes cipher - and the Free software part can verify that correct data is read back (ie: it decrypts and authenticates).
- Tepix 7y agoThere's an unofficial rust implementation that uses SQLite https://github.com/dani-garcia/bitwarden_rs https://github.com/dani-garcia/bitwarden_rs
- ViViDboarder 7y agoIt also supports MySQL now too.
- firepoet 7y agoWell if crypto is managed outside the database I don’t think it’s a huge problem.