14 ms·
Bitwarden: Avoid at all costs (outage issue)
Bitwarden is experiencing an outage right now.
What I learned about it, is that they can remotely disable your browser extension which is assumed to work in offline mode. So, as soon as you have an internet connection — you get blocked.
This is what happened to me like 30 minutes ago or so. Just cannot log into my account and verify a transaction because I'm stupid enough to trust them with my TOTPs and storing temp verification passwords.
The funniest stuff, though, is that the company's damage control is to remove the comments and suspend feedback from it's community forum. Given that I'm a paying customer, I'm a little bit offended by it.
For a secret management company that secured $100 mil recently, it's a clear mark that the enterprise service train is on the way.
I'm lucky enough to have the offline access to the storage. But my trust to Bitwarden as a reliable service is completely ruined. Having this in mind, is there a viable alternative?
PS. Expect Spearrin to appear on HN and bring "personal" apology for the hiccup. But I won't buy it. Password manager services are almost like bank storages but on the internet. Apologizing won't fix the fact you can get remotely locked from the passwords and TOTPs at a pressing moment.
- Reflex0184 4y agoIf you need "seven nines", your best bet might be to host it yourself. Probably not going to find it anywhere for $10/yr
- cabbagesauce 4y agoYou're one of the anon-Bitwarden boys? 1) I want sane error messages on the client side. 2) I want my feedback on community forums not to be shushed. You screwed up — own it. Community mods aren't janitors to wipe out user feedback. 3) I want the extension to be working no matter what kind of server-side problems you have. Let me know about a sync problem but don't terminate my access. But if you do think, that for $12 I get to be treated like an dog, too bad, there's enough options for me to take my business elsewhere.
- ath3nd 4y agoI can recommend Keeper (my current password manager of 2 years) or Passpack (previous password manager of 5 years). Never experienced any problems with either. I am surprised that they are not more popular than "fan-favorites" like LastPass which I absolutely can't stand (it's like from the dark ages UX wise) or 1Password, or, for that matter, Bitwarden. Bitwarden particularly experience degradation of service like every month or so, maybe due to their popularity.
- intuxikated 4y agoisn't keeper the one that sues people that disclose security vulnerabilities? I'd stay away as far as I can from that one.
- viro 4y agoIdk why you think you should be able to login to a cloud SaaS product while its down. From your comment here I highly highly doubt you were at all even remotely civil in that forum post $12 a month doesn't mean you get to be an asshole to people. Not all forms of Auth can be done locally, for example most 2fa requires server access.
- russelg 4y agoNot even 12/m, it's per year!!
- cabbagesauce 4y agoI can feel uncalled hostility in your attitude, dictated by your conjecture which isn't the right indicator to make judgement about this specific incident. Ad hominem is irrelevant here since it's not about me but service operations. Anyway, I'll still respond. >Idk why you think you should be able to login to a cloud SaaS product while its down The application works without internet access. > Not all forms of Auth can be done locally, for example most 2fa requires server access. TOTP validation can be done at the offline level. And the hardest proof of it is that the tokens themselves are generated offline. All that is required at the server side is shared secret and a Unix time syscall. This gets done at the browser extension level[0], no network required. [0] https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Date/now https://developer.mozilla.org/en-US/docs/Web/JavaScript/Refe...
- cuteboy19 4y agoWhen you are on some corp firewall or mitm bitwarden has a very strange error message about owning keys or something. Took me a while to figure out the problem
- cycomanic 4y agoWhat do you mean apart from the local solutions like pass or keepass, hosting yourself for under $10/year is absolutely trivial. I mean just spin up the smallest free instance on oracle free cloud and run vault warden there. If you want additional data safety spin up another instance and synchronize your database or synchronize to a free Dropbox drive. If you don't want to rely on a free cloud product go to lowendtalk and find an offer for a minimal VPS, which can regularly found for around $10/year.
- torstenvl 4y agoEnpass - Local-first so you own your data - Open about technical documentation and assisted in providing encryption scheme info to an open-source vault reader (so you own your data...) https://github.com/hazcod/enpass-cli https://github.com/hazcod/enpass-cli - Works with lots of cloud/sync providers - Cross-platform (Windows, macOS, Linux, iOS, Android) - Browser integration (Safari, Firefox, Chrome, Edge, Opera, Vivaldi) - Lifetime license for $79.99
- lake_vincent 4y agoWow, okay, yeah, I'm actually sold. There's a CLI for desktop, and it's on both ios and android. Damn. Will gleefully fork over $80 for a lifetime license if it's as good as it seems. Why have I never heard of Enpass before? Anyone have any reason to not switch from Bitwarden to Enpass right now?
- Macha 4y agoIt depends if you feel happy entrusting your passwords to what is ultimately a closed source client. I do not. Moving to self hosted vaultwarden from keepassxc-in-syncthing was a big leap. A closed source client is a leap too far.
- torstenvl 4y agoIt's a closed-source UI on top of sqlite/SQLCipher. You'll be fine.
- CameronNemo 4y agoI mean sure... But why go out of my way to use closed source software when the open source options are right there?
- lake_vincent 4y agoFor me it's the features I mentioned above - having a CLI on desktop, and both ios and android apps is so huge because I have devices in all three ecosystems! One password manager that works seamlessly across devices is very appealing to me. The Bitwarden mobile experience needs a lot of polish, if Enpass is better I would switch.
- cabbagesauce 4y agoSo, as expected this is the response from the BW people. No one got hurt, no one to be blamed. Grab a beer, turn on your Netflix and be happy. Hello, Thank you for contacting Bitwarden. If you are receiving this message, you have contacted us about errors accessing your Bitwarden account. We would like to first apologize for any inconvenience. Access should no longer be impeded when authenticating. In our mission to continually strengthen services and protect Bitwarden users, we have employed many protections to that end. These are ever evolving and constantly being tuned. With these in place, there is potential for temporary false positives. The team is committed to refining and improving these protections. We thank you for bringing this to our attention, and for your understanding. If you have any further questions, please let us know. -The Bitwarden Team
- mistrial9 4y agoIn our mission to continually strengthen services and protect our brand we have employed many protections for our remote monitoring, control and IP... what do people expect? all the wrong management are attracted to security products for exactly the reasons you suspected all along.. Lock-in is profits!
- doodlesdev 4y agoThere is no lock-in to Bitwarden, stop spreading FUD. I'm not really sure how long this is going to be like this with the VC money, but right now: - Everything is open source - You get to self host - You get to export your database at any time - You don't even need to pay to use it if you don't want to Are local password managers objectively more secure and reliable? Yes. Does that mean that Bitwarden is just an awful product by a money seething corporation that wants to lock you into their product and dime you till your last cent? Not so sure about that.
- cabbagesauce 4y ago...not yet. Just as Authy was a nice TOTP software. Until they introduced their vendor lock-in TOTP format.
- PenguinCoder 4y agoI also got hit by this, with the message "Access denied, contact customer support" ... Access denied for MY personal password database! I get that Bitwarden uploads the DB file to their cloud for seamless sharing, but why the hell is my local login/decryption reliant on THEIR login service being up?? Not acceptable.
- deleted 4y ago[deleted]
- Georgelemental 4y agoKeePassXC (https://keepassxc.org/ https://keepassxc.org/) - open source, full featured, standard file format, bring your own cloud storage
- doodlesdev 4y agoAnother options is pass [0], which uses GPG to encrypt your stuff. Everything happens through the CLI but there are also GUI frontends for it. There's also gopass [1] which is very similar and compatible but does some extra stuff such as versioning with git. Similarly to this API compatibility there's KeePassDX [2] for mobile phones which is compatible with the KeePass database format. There's also KeePass [3] which is the original built with .NET. I personally use Bitwarden though because maintaining sync of databases on mobile phones is painful. Also keeping backups up to date is hard and time consuming, I do export my encrypted database once in a while though. [0]: https://www.passwordstore.org/ https://www.passwordstore.org/ [1]: https://www.gopass.pw/ https://www.gopass.pw/ [2]: https://www.keepassdx.com/ https://www.keepassdx.com/ [3]: https://keepass.info/ https://keepass.info/
- max-m 4y agoPersonally I use the official KeePass 2 executable via Mono on my desktop. I would have given KeePassXC a chance but it lacks the trigger system or a simpler alternative. I use the trigger system to sync my local database with a copy on my server via the help of a shell script (because I couldn't get the SFTP / scp plugins to work properly). The trigger runs when the local database is being saved. As a first step it disables itself, as a last step it enables itself again. As a second step the trigger calls my script which downloads the database from my server. Then it runs the sync action against the freshly downloaded database and afterwards the trigger calls my script again and instructs it to upload the database to my server. I suppose this might be problematic if multiple devices try to change the remote file at the same time but that's nothing I have to worry about and other solutions like using Dropbox or other cloud storage solutions would run into some sort of problem as well (but at least you might be given the choice of which version to keep). On my Android phone I use Keepass2Android and it's built-in SFTP support to open the remote database (and also keep a local offline-copy). When saving it seems to synchronize with the remote file first before uploading the file, so even if I change entries on both devices the copy on my server shouldn't lose any entries. But I haven't really tried to break it yet.
- stoplying1 4y agoOh it's only been two days and my comment was right. And applies here again as yet more startup-esque pw manager alternatives are being suggested. https://news.ycombinator.com/item?id=32738675 https://news.ycombinator.com/item?id=32738675
- yogenpro 4y agoI've been using Bitwarden's clients (browser extension, mobile apps, desktop apps) with a self-hosted vaultwarden [1] server. It's marginally free if you are already self-hosting other stuff. I'm hosting it on a raspberry pi 4b at home and exposing it to public Internet through Cloudflare zero trust (also free). Had no problems so far. [1] https://github.com/dani-garcia/vaultwarden https://github.com/dani-garcia/vaultwarden, note that it's different from Bitwarden's official server (https://bitwarden.com/help/install-on-premise-linux/ https://bitwarden.com/help/install-on-premise-linux/), uses less CPU/memory, and enables premium features like TOTP for free.
- alyandon 4y agoAdded bonus - even if the client extensions/app stopped working you can still log into the vaultwarden web UI to access your secrets.
- password4321 4y agoVaultwarden "is the way" if you need a polished iOS client, almost too good to be true now that VC's are involved.
- Szpadel 4y agovaultwarden is awesome, just make sure you have some reliable automated backup (preferably cloud) for disaster recovery.
- elashri 4y agoIam curious how you made the clients connect to the server behind CF zero trust. have you white-listrd a path or so for them?
- dugmartin 4y agoI have a similar setup but using a $5/month VPS that I also host a few other personal/family apps on. It works really well but I’m wondering how long the api will stay open and accessible given their recent huge VC investment.
- 4y ago
- breakingcups 4y agoCensoring the forum comments is definitely a very different kind of secret management!
- viro 4y agoI highly doubt this kid was civil in that forum post.
- gremlinsinc 4y agoI think maybe a good alternative type solution would be instead of a 'hosted' thing, I'd just like something like Bitwarden but your data gets pushed to devices it needs to be on, so it's always in a local database, and maybe you back it up to drive/dropbox easily, but the server just tracks when something changes/needs pushed and basically handles syncing stuff, other than that it doesn't keep any password data encrypted or otherwise, it's just a bridge.
- doodlesdev 4y agoThat's possible with KeePassXC (desktop) [0], KeePassDX (mobile) [1] and Syncthing [2]. Best thing about it is that the bridge between devices is also end-to-end encrypted, which is a nice bonus if you want to sync something else. I wish there was an easier all-in-one application for this kind of stuff though, would be much easier to maintain and setup for family/friends. [0]: https://keepassxc.org/ https://keepassxc.org/ [1]: https://www.keepassdx.com/ https://www.keepassdx.com/ [2]: https://syncthing.net/ https://syncthing.net/
- aaasss333 4y ago
- slenk 4y agoI recommend hosting yourself if you are worried about a company on the internet controlling access to your passwords... You attack Bitwarden but how would this be any different with the other hosted password services?
- Canada 4y agoNo matter what password you use, I highly recommend regularly exporting a plaintext copy of it to somewhere safe like an encrypted volume on one or more of your devices. Just do it once a month - mount the volume, export the database in plaintext directly to the volume, then unmount it. If your password manager locks you out because of a bad software update, service outage, or you hold the wrong passport and got sanctioned, or whatever, at least you will still be able to access the vast majority of your credentials. Special password databases are nice and convenient, but plaintext is usable forever.
- zen_1 4y agoOr just use KeePassXC+nextcloud/syncthing as others have suggested, it's just an encrypted database with no cloud bullshit.
- avg_dev 4y agoCan you please explain why this is an improvement over the parent comment solution?
- rainbowzootsuit 4y agoMy interpretation is that it is already self hosted, with cloud-type features, but without having to do something different, occasionally, to keep a safety net. People tend to forget to do the non-habitual, slightly painful steps. Setup your self hosted infrastructure with all the automated redundancy you want ahead of time and let it roll.
- zen_1 4y agoBecause KeePassXC (or any other offline password manager) cannot lock you out as long as you remember your password, and you can completely avoid storing your passwords in plaintext.
- avg_dev 4y agoI believe I will take this advice. Thanks for saying it.
- _wldu 4y agoThe Design Flaws of Password Managers - https://www.go350.com/posts/the-design-flaws-of-password-managers/ https://www.go350.com/posts/the-design-flaws-of-password-man...
- Canada 4y agoThe design flaws of these systems are the fact that they are terrible at changing passwords, dealing with the arbitrary password requirements of many sites, and dealing with the fact that many sites require the storage of additional secrets for practical use that cannot be generated. (eg. secondary passwords or pin codes for privileged operations within the application, mandatory security questions, etc)
- Georgelemental 4y agoKeePassXC supports all of that?
- boloust 4y agoI believe the comment you're replying to is referring to the weaknesses of deterministic password generators.
- aborsy 4y agoEven Google and AWS have outages. Bitwarden has rarely had issues. And this is all free service. Customer expectations have skyrocketed.
- cabbagesauce 4y agoHello. I'm paying for the service. My expectation is as simple as being able to log into the password manager when the cloud has an outage and I don't experience any problems. When they did disable my log in attempts, they showed the centralized — we own your data type of an issue.
- viro 4y agodid you use 2fa?
- deleted 4y ago[deleted]
- AdamJacobMuller 4y ago> remotely disable your browser extension which is assumed to work in offline mode This seems incorrect. I experienced this issue while I was working on 1 computer which I infrequently use so I was logged out of BitWarden. Trying to login gave me that oblique error message. I was on a conference call (and presenting of course) so I needed the password Right Now so I pulled out my laptop, which was still logged in, and was able to access the password without issues. I'm not sure exactly when this issue started/stopped, but, I probably use my phone vault 20x a day and I never saw the issue there either, only with the one computer which was logged out. I really don't get all of the hate on here for BW. Are people annoyed or jealous because they just got funding? I understand people suggesting alternatives (and that's great -- monocultures are bad) but some of the comments on here (including, frankly, the OP's topic and message) are just rude. I'm a user of both the hosted BitWarden and multiple VaultWarden_rs instances and it works well for me and meets my needs. It's been very reliable to the point where if I didn't see this post, I would have just assumed the earlier issue was some fluke and moved on without a 2nd thought. I'll probably be accused of being a shill for them and legitimate criticism is warranted, but, too much of this seems like bad faith.
- throw149102 4y agoIt sounds as if you only were able to access the password because you had a second device that happened to already be logged in. My guess is that if BW's login servers were having a temporary outage, had you not been logged in you wouldn't have been able to login and therefore been unable to get the passwords.
- Mave83 4y agoJust install yourself a vaultvarden, migrate your data and reconfigure your client to your own Bitwarden server.
- throwaway67743 4y agoThey don't disable it remotely but their apps and browser plugins will log you out and destroy local copy (experienced the same when my vaultwarden instance didn't return a response it liked due to MySQL breaking) Annoying, but I think I see the benefit (kill it if it might be tampered with etc)
- Decabytes 4y agoDamn I literally just created my Bitwarden account today and then immediately experienced this problem. I thought I was doing good not getting last pass, and needed the iOS app so that disqualified KeePassXC. What am I left with 1password?
- DavideNL 4y agoPerhaps try KeePassXC on Desktop + Strongbox on iOS.
- luckman212 4y agoStrongbox looks amazing, thank you.
- throw149102 4y agoLots of people are mentioning that you can host these types of things yourself, I want to say that that is not a solution at all. The entire point of these hosted password services is that they are a turnkey solution - I could give them to my mom, who knows nothing about technology, and trust that they work. I like using a turnkey solution myself even though I could self-host because I don't want to spend brain cycles on solving the "syncing passwords across multiple devices" issue. I don't quite understand why Bitwarden even needs to have you login in order to access the passwords. Surely you could just have the salted+hashed passwords on device, and Bitwarden just syncs that data from device to device. If you work in an organization and need to revoke access, just change the password. No need to manage whether or not someone is logged in to Bitwarden.
- throw149102 4y agoAlso re: the comparisons to AWS or Google Cloud - it's still totally different. This is more like your car being unable to start because it can't connect to the cloud. I don't expect that driving my car needs internet access, and I wouldn't expect Bitwarden needs internet access to serve me my passwords that have already been synced.
- OJFord 4y agoYou have to log in to the extension to unlock passwords every so often though right, more than once per browser session? Presumably that's server-authenticated, and what broke here.
- Schroedingersat 4y agoThere's no reason for that to involve a remote server. You have the local encrypted database. You have the key. Opening your front door doesn't require a trip down to the hardware store whe$e you brought it.
- OJFord 4y agoTrue, but if you go down that route there's no reason for a remote server at all. (Cf. pass.) I was just suggesting what seems to me a likely cause, since everyone was talking about 'phoning home' and 'remote disabling' as though it was intentional or more dodgy.
- alexalx666 4y agoself-hosted bitwarden with vaultwarden is the best, you can use their iOS, linux, mac apps
- thenoblesquid 4y agoBitwarden: so hot on HN right now. This is fresh on the heels of the article that was on the front page about their $100 million VC news.
- replwoacause 4y agoWith the recent news of their 100 mil cash infusion, and now this, I'm not feeling great about Bitwarden ATM but none of the other options sound stellar either.
- anotherevan 4y agoFor those suggesting to "just" use KeePassXC and KeePassDX, the sticking point for me is that the UI experience with Bitwarden in my desktop browser and on Android is just so darn good. How do the KeePass' compare? P.S. I do use a KeePassXC vault for a small amount of stuff. Discovered KeePassDX for Android this week from a recent HN comment. It is very good. After playing with it for ten minutes I deleted the other two Keepass apps I had on my phone.
- bpye 4y agoI switched from KeePassXC to Bitwarden (self hosted with Vaultwarden) a couple years ago. The experience is considerably better, the BW iOS app is great, and the Firefox extension also works reasonable well. I could never get integration in either case to work as well with KeePassXC. I'm confident if BW pull any real nonsense, there will be a fork of the client, and there's no reason for Vaultwarden to go away...
- cycomanic 4y ago> I switched from KeePassXC to Bitwarden (self hosted with Vaultwarden) a couple years ago. The experience is considerably better, the BW iOS app is great, and the Firefox extension also works reasonable well. I could never get integration in either case to work as well with KeePassXC. I'm confident if BW pull any real nonsense, there will be a fork of the client, and there's no reason for Vaultwarden to go away... What were the issues with keepassxc integration? I have been using it and it generally works flawlessly integrating with firefox, the only thing is that you have to sometimes press the reconnect to keepass in the extension if you shut down keepass while Firefox was running. Keepassxc also provides an ssh agent and works as my secret provider, that also works without problems if it wasn't for gnome keyrings which decides that it will stick around after you log into gnome (which I rarely do). Does BW provide secret integration?
- bpye 4y agoI found it kind of a pain to keep the Firefox extension connected. Additionally, I never found a solution for sync I was happy with - I had settled on OneDrive and there is an open source OneDrive sync client for Linux, but I had a couple instances where I ended up with conflicts and having to copy new or modified entries over manually. I’m not sure that any sync client is great across all of Windows, macOS, Linux and iOS - but I use them all frequently. I can’t really comment on secrets, I use a YubiKey for SSH and GPG for signing Git commits so I’ve never needed to look into it.
- hadet 4y ago
- hadet 4y ago
- cutierust 4y agoGuys keepaasxc + keepassdx + Syncthing work just fine. For $10 nobody will answer to you. Yes, Syncthing doesn't work on iphone, buy your mother an android , or buy yourself a tie machine and write apps for windows Phone
- password4321 4y ago> buy yourself a tie machine and write apps for windows Phone Took me too long to realize you probably meant ti[m]e machine, but I still don't see how that would fix getting a non-techy off their iPhone.
- anotherevan 4y agoWhat do we want? TIME TRAVEL! When do we want it? THAT'S IRRELEVANT!
- pvinis 4y agoactually syncthing on iOS is pretty great using https://apps.apple.com/app/id1539203216 https://apps.apple.com/app/id1539203216. I'm nothing more than a very happy user.
- 8K832d7tNmiQ 4y ago>because I'm stupid enough to trust them with my TOTPs and storing temp verification passwords. I'm sorry, but isn't the highlight of your problem is that you did not separate TOTP with any service that depends on it, including BW?
- cabbagesauce 4y agoGood point. At one moment, I switched to BW premium exactly for convenience purposes. Before that, it was Authy for TOTP handling and BW for password manager.
- stereoradonc 4y agoNo problem here. No drama. No sweat. No anxiety.
- h0ldnack 4y agoHa, I switched to keepassxc this week because of the VC funds sketched me out. Makes me sad because I don't know what password manager to recommend for average users now.
- aorth 4y agoOh my gosh, this is crazy. They can remotely disable your browser extension? I had just recently convinced a few people to switch from LastPass to Bitwarden. Personally I use pass with git, but that solution is not for non-technical people! What are the alternatives for our non-technical family and friends? Should we be encouraging Firefox and Chrome's built-in password managers?
- pvinis 4y agoI’m curious why no one is recommending 1Password. I use it and it’s pretty nice. Closed source though. Is that the reason people don’t recommend it here?
- nokya 4y agoGood to know. Thanks.
- polski-g 4y agoWe ended up going with Team Password Manager. It's just shocking how bad multi user password management systems are. It was bad ten years ago and nothing's changed.
- lawgimenez 4y agoMigrate to Bitwarden is in my roadmap. Guess I have to scrap it now.
- hnarn 4y agoIn favor of what? I use BW, I think this is terrible news, but apart from self-hosting I don’t see any viable option.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- gsora 4y agoHosting a Vaultwarden instance on one of the free Oracle ARM VMs is a great alternative to their hosted service. You own your data, get great UX thanks to their mobile clients/extensions. Or… grab a Precursor[0] and import your bitwarden JSON export into its vault app :-) [0]: https://betrusted.io/ https://betrusted.io/
- thanzex 4y agoThis is absolute nonsense. Bitwarden has worked absolutely perfectly for me until now, their clients work just fine and it's the password manager I always suggest to people around me. I do both, self-host vaultwarden for a non-profit and have Bitwarden premium for personal use. A short while ago our server got nearly nuked and our Vaultwarden was down for several days, everyone in the org still could access all of our personal and shared passwords just fine, the extension and the clients stored all the necessary data offline and let us work uninterrupted until we restored the service ( ironically, it held the server's cloud provider credentials too ). I suspect that in case of a complete outage or while not connected to the internet the client will work just fine, but on this instance something got messed up on the autentication/authorization side, so your client tried to authenticate to their server to sync up/do whatever it needs, since the server was not down but experiencing problems it received an error and logged you out. I would argue this is by design, If the server returns an error while logging in there's probably a good reason, and especially in case of an organization account, you shouldn't have access to the passwords anymore. You seem to have had major problems, but I assume it's likely your fault. You should not store all the means of accessing an account in a single place, I too store TOTPs on Bitwarden, but that's just for convenience, I have them on my phone Authenticator app too. But most importantly, as the name suggest, recovery codes ( which is what i assume your "temp verification passwords" are ) should be kept safe and in a separate place altogether, preferably printed even. What you're describing here looks like nothing more than an outage, a thing that literally everyone and their dog experiences, from the non-profit like us to AWS, Microsoft, Google and Cloudflare. Surely nothing to scream "Avoid at all costs" about.
- donutshop 4y agoAgeed. OP's language is disrespectful to say the least. If it wasn't for this post I wouldn't have known there was an "outage"
- cabbagesauce 4y ago> This is absolute nonsense. Bitwarden has worked absolutely perfectly for me until now, their clients work just fine and it's the password manager I always suggest to people around me. Same for me. >I suspect that in case of a complete outage or while not connected to the internet the client will work just fine, but on this instance something got messed up on the autentication/authorization side, so your client tried to authenticate to their server to sync up/do whatever it needs, since the server was not down but experiencing problems it received an error and logged you out. If you're familiar with Bitwarden you're aware there is a Vault lock. When the laptop started and FF was launched, the extension got greyed out immediately. This means there's some sort of preflight init right after browser starts. This behavior is not documented anywhere on their website in the troubleshooting section. And that was my first attempt to figure out the cause. Next thing was to reinstall the application and check if the problem goes away. And only after that the email to support was dispatched. So, enough effort was put before contacting BW staff. The error message is misleading[0]. So I went on to support forum[1] to learn this problem is recurring. And while I was typing my message, I have seen several messages deleted by the staff. Same happened with mine. Given all that, where is my fault exactly? >What you're describing here looks like nothing more than an outage, a thing that literally everyone and their dog experiences, from the non-profit like us to AWS, Microsoft, Google and Cloudflare. It's an outage that indicated that you can loose access to BW Vault anytime they have an outage, means you can loose offline access even if the docs say otherwise[2]. To me it's false advertising at best given the iPhone's vault was in locked state as well but did not show any operational errors. Current BW users got aware of the incident and can draw conclusions and mitigate risks. I'm speaking for my experience and it's avoid at all costs now. [0] https://imgur.com/a/y4qYcFL https://imgur.com/a/y4qYcFL [1] https://community.bitwarden.com/t/an-error-has-occured-access-is-denied-please-contact-customer-service/43482 https://community.bitwarden.com/t/an-error-has-occured-acces... [2] https://bitwarden.com/help/using-bitwarden-offline/ https://bitwarden.com/help/using-bitwarden-offline/
- pwpw 4y agoThis post is so sensationalist and right on the heels of that other article about BW’s new funding that hit the front page. I have to question the motives of OP and some of the commenters. I’ve happily used BW for years without problems. My experience is so far removed from what’s been posted here that I find it hard to take seriously at all. What an incredibly low quality post that does not live up to the standards of quality I expect on HN. There’s a proper way to voice concern and criticism, and this post is simply not that. I’d like to hear dang’s thoughts. I believe the title should be edited and the OP text should probably be as well. To the OP, you missed the mark here, but I believe you can do better on your next post. Hopefully my criticism isn’t received too harshly as it’s intended to be helpful.
- novoreorx 4y agoBitwarden's apps are so poor compare to KeePass apps (KeePassXC and Strongbox), I still can't see any advantage in choosing Bitwarden (or even the self-hosted vaultwarden) over KeePass.