3 ms·
I leave the really unimportant crap in the Firefox "generate and remember this login", the regular passwords in Bitwarden, and financial passwords in my head.
by PennRobotics 5y ago
I leave the really unimportant crap in the Firefox "generate and remember this login", the regular passwords in Bitwarden, and financial passwords in my head.
Answering the original question: I trust that Bitwarden's Github source is what drives their service and that their popularity ensures the source is audited on a regular basis by reasonably skilled software folks. It's the same degree of trust I give to the people that build every reasonably vulnerable product I use: elevators, phones, cars, door/window locks, etc.
-----
For me (and perhaps only me) a more pressing concern is that fingerprint scanning is common in apps that are meant to protect data: banking apps, stock market apps, Bitwarden.
NOBODY makes a significant effort to hide fingertips. Cameras are cheaper, more accurate, and more numerous than ever. People don't clean every surface they touch. It can't be so difficult to 3d print a mold and find the right material to make a false finger.
Android's security model has a nice built-in feature: If you have someone's phone for a few seconds and know their unlock code (not too tough to espy... right, Ye?) you can keep retrying the false finger for that person until it works. Only then do you switch to the important app.
Oh, and... Fingerprints, unlike master passwords, are nearly impossible to change.