3 ms·
I see a few things that might be worth adding, as some were explicitly why I switched from LastPass a few years ago: * Security model. What is stored server-si
by gregmac 4y ago
I see a few things that might be worth adding, as some were explicitly why I switched from LastPass a few years ago:
* Security model. What is stored server-side unencrypted? In what circumstances is the server-side encrypted data available on the server in plaintext?
* Defaults: "parent-safe"? What trade-offs are made with the defaults picked?
* Ability to edit (Android) app associations. Bitwarden has this, and it solved a huge problem I had with duplicates on LastPass. There's URI entries like androidapp://com.example.app that are easy to manually merge and keep together with corresponding web sites.
* Domain matching. Bitwarden can do: base, host, exact, starts with, or regex. Lastpass had an "equivalent domains" managed from obscure settings, which never really worked the way I wanted. I used to have a billion entries for things in .mydomain.com, but bitwarden fixes this and by setting that flag properly I get only relevant things for each internal app. At the same time, for .myapp.com and .myapp.local I can get the default dev login, so when I deploy a new instance/tenant for dev, it "just works".
Username generation. Can it do plus-addresses? Catch-all domains?