12 ms·
For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault: > At Bitwarden we take this trusted relationship with our users seri
by ddejohn 4y ago
For anybody else left wondering, Bitwarden does encrypt (nearly) everything in your vault:
> At Bitwarden we take this trusted relationship with our users seriously. We also built our solution to be safe and secure with end-to-end encryption for all Vault data, including website URLs, so that your sensitive data is “zero trust” secure [1]
I haven't used LastPass in years, but the recent news made me wonder how Bitwarden was handling URLs.
[1] https://bitwarden.com/resources/zero-knowledge-encryption-white-paper/ https://bitwarden.com/resources/zero-knowledge-encryption-wh...
- dreamyfigment 4y agoI wonder what 1password does
- vermilingua 4y ago1password’s security design whitepaper can be found here: https://1passwordstatic.com/files/security/1password-white-paper.pdf https://1passwordstatic.com/files/security/1password-white-p... It’s quite good.
- dreamyfigment 4y agoThanks! They seem to encrypt everything too. Items contain overviews and details which are encrypted separately by the vault key. We encrypt these separate so that we can quickly decrypt the information needed to list, sort, and find items without having to first decrypt everything in the vault. Item overviews include the item fields needed to list items and to quickly match items to websites, such as Title, URLs, password strength indicator, and tags.
- _-____-_ 4y agoAdditionally, 1Password makes the extra effort to never even send the URLs of your accounts to their servers. Even with their Watchtower service, which notifies you of breached accounts and websites that support 2-factor authentication, your passwords and website URLs are never sent to 1Password servers. https://support.1password.com/watchtower-privacy/ https://support.1password.com/watchtower-privacy/
- cmsj 4y agoThey still require that your vault be hosted by them though. Terrible policy.
- newman314 4y agoYup. Still pissed that 1Password removed the standalone option.
- KneePassXC 4y agoThe standalone option is called KeePassXC; it's a perfect password-manager man. Not a single other tool is better than it. /HappyCustomer.
- hoistbypetard 4y agoI had been a very happy customer for years before they started moving to that policy. It's what finally made me set up a vaultwarden instance and migrate all my stuff over. I didn't like the move to a subscription model, but I'd have sucked that up if I could've continued to bring my own sync.
- voltaireodactyl 4y agoMy exact situation as well. I moved from 1P7 to Bitwarden, along with my entire company.
- dylan604 4y ago*for some. For those of us that have been using it for long enough, we can still use the "classic" version stuck at v7, but it means being able to self host. no monthly SaaS fees.
- thewebcount 4y agoFrom what I can tell, v7 is Intel-only. That means when Apple sunsets Rosetta 2, it’s not going to work anymore. I’ll need to switch to something else before then, but hate Electron, and all the other options seem to use it (and now 1Password does, too).
- drrlvn 4y agoWonder no more: https://blog.1password.com/what-we-dont-know-about-you/ https://blog.1password.com/what-we-dont-know-about-you/
- pigsty 4y agoI feel like there should be a law of the internet for this. The more a company asserts that their data is secure and encrypted and you should trust them, the more likely it is to leak and be proven to be massively vulnerable. It’s fine to store your passwords online for convenience, but as a user, it’s important to accept that it’s no longer your private password and will, at some point, leak.
- djbusby 4y agoPigSty's Razor
- _0w8t 4y agoIt all depends on how the data are encrypted. With a sensible design capturing the encrypted storage will only reveal the number of encrypted records, rough estimates on their size, and time stamps.
- accrual 4y agoIdeally it would be an opaque blob with no information about the number of records or their size, just the total size and maybe a last modified or accessed time.
- _-____-_ 4y ago[dead]
- sacnoradhq 4y agoBitwarden, Keeper ($ but trusted at megacorps), and good ol' PasswordSafe are the safest solutions. I run BW with Yubikey 2FA and a local hosted sync server. KeePassX/C perhaps. Vault for secrets management. Never touched LastPass, 1Password or any of these other mickey-mouse commercial apps that invariably claim "military-grade encryption" or "unhackable" when their fundamental constructions are crap.
- xenospn 4y agoDo you have any evidence to back your claims about 1password?
- onphonenow 4y agoI do passwordsafe on google drive. I feel google does a good job w security / main risk a computer I’m using getting compromised
- jcpham2 4y agoExcept or unless your google account gets locked. Any number of reasons and posts HN horror stories exist about other users getting locked out of their lives because of a user account or lack of access thereof
- onphonenow 4y agoThat’s a risk. I pay for my account to try and mitigate this risk so I’m the actual customer, not advertisers. Google workspaces has a support assisted recovery option. I host dns separately from google as their admin level recovery may require some dns signaling. Other steps include a yubikey etc . I’ve actually had the experience of losing all my Authenticator codes on an iPhone upgrade which at the time was how I did 2fa - so had to go through recovery for many providers. My top takeaway - if I was paying for service it was possible if sometimes a bit time consuming. If I wasn’t it was hit or miss. Other tip? Google Authenticator may not backup to iCloud!! I had 20 codes in it including some really hard to fix ones.
- 4y ago
- pedrovhb 4y agoDoesn't necessarily mean it's safe. Say there's passwords accidentally appearing in logs as part of a traceback - even if the passwords are kept encrypted, just having access to the logs is enough. Even if everything is encrypted client-side, it could appear as part of a client crash dump being sent by telemetry. Leaked plaintext databases aren't the only possibility.
- nicce 4y agoBitwarden caches Web urls as well on its browser extensions. Sometimes it knows that you have saved login for the specific web page before you have logged in. Certainly LastPass had urls unencrypted for this specific reason - to show users that you have saved login for this page, would you like to login? It is the endless usablity vs. security battle. Of course, there are better ways to implement this than LastPass has done.
- deleted 4y ago[deleted]
- fsckboy 4y ago> safe and secure with end-to-end encryption for all Vault data, including website URLs end-to-end encryption means something like https, it's a communication quality between trusted parties https://www.ibm.com/topics/end-to-end-encryption https://www.ibm.com/topics/end-to-end-encryption
- saurik 4y agoI would hope not... that term should be reserved to indicate that the data is encrypted on one of your devices and is merely passed encrypted through their servers to your other devices.
- kaoD 4y agoUnless I misunderstood you, the article directly contradicts your point: > Password managers [...] In this case, however, the user is on both endpoints and is the only person with a key.
- heavyset_go 4y agoAnd Bitwarden can be self-hosted for those that are weary about using SaaS password managers.
- semi-extrinsic 4y agoNitpick: "weary" == "tired", "wary" == cautious
- WesolyKubeczek 4y agoI can read the sentence with both versions and it still makes sense…
- dmix 4y agoIt should be “weary of” not “weary about”
- WesolyKubeczek 4y agoYes. But “wary of” and “weary of” both work. :-) English is my third or fourth language, so I guess I’m less sensitive to mistakes like that.
- heavyset_go 4y agoThanks for correction.