BitWarden
Privacy
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
much thanks to @gary_host_laptop for the logo design :)
and/or Vaultwarden as a selfhosted alternative.
Vaultwarden is a great piece of self hosted server software, which meshes with Bitwarden software perfectly. And for people who can't self host, IMO Bitwarden gives you more than enough bang for your buck with their own hosting plans.
It's one of the few examples of software being open source and ethically making money regardless. (For comparison, Standard Notes has tried pretty hard to make sure non-paying users have an inferior experience even if they self-host literally everything.)
<$1/mo for bitwarden hosted premium is a no brainer for me
I was really disappointed about standard notes' plans. Took me forever to get everything set up to self host, only to find I couldn't even use markdown unless I bought a license? Silly.
I'm excited that the bitwarden phone apps are getting a brand new native version for ios and Android soon.
Is Keepass there? Good. Upvote.
Prefer KeepassXC but let's be honest, the best password manager is the only you actually use and keep using.
I would only use KeepassXC
+1 For KeepassXC, I use it in combination with syncthing to have my passwords available on all devices.
Still using KeepassXC on desktop and laptop and KeePassDX on mobile.
I use Bitwarden for passwords. Just works so well.
KeepassXC and KeePassium for TOTP codes. I keep the database in the cloud but sync a key with Syncthing that’s needed to unlock the database on the devices themselves.
Locally hosted bitwarden (vault warden) that is only accessible on your local network is the way to go. When a new sync is needed away from home, wireguard VPN to connect back in makes everything nice and secure. Otherwise most of the time the vault is cached to the device locally so you don't need to phone home to access passwords.
I like ProtonPass. It’s nice.
And they are really moving quickly with development. I feel like we're getting new features monthly
Same. The UI is pretty good and modern, they support TOPT and cards as well and the development is being done at a good pace.
Keepass + Syncthing is a great combination.
And with Syncthing's Untrusted Device Encryption feature I can use my VPS as an extra node for synchronization without worrying touch if it becomes compromised without me knowing.
KeepassXC & Syncthing
And I do keepassdx on Android, with a (phone-specific) database synced with syncthing
P.S. syncthing is fantastic: I hope more people consider hosting discovery servers and especially relays
I use keepass with my database on onedrive.
Then i connect every device to said onedrive account, copy the private key manually on each device that i need to use.
I secure my databse with said private key + a passphrase.
Might not be the best setup, but i feel like with passphrase+key i am secure enough to have the db file in the cloud.
you could encrypt onedrive with cryptomator
If you are into the command line, pass is also neat. You can even have your keys in a git repo and access it with a FOSS Android app (requires some dedication to set it up). It's very useful to feed passwords to scripts without hardcoding them in the source.
KeepassXC, Passbolt
KeePass for me. I keep my encrypted vault in my 2 factor encrypted gdrive. Get the best of both worlds. No traditional cloud that's a target for hackers and I have passes I can share across devices.
I really enjoy 1Password for easy vault sharing between family members. I was able to get my (not so technically literate) siblings and dad onto my family plan. Baby steps!
No mention of Enpass? Stores more than just passwords, can be synced locally over wifi or in the cloud without using Enpass servers.
It's not open source and they haven't had a security audit in a while AFAIK, I used to use it too but migrated to Proton Pass for these reasons https://discussion.enpass.io/index.php?/topic/404-security-audit/page/6/
KeePassXC my beloved
I love Dashlane, someone tell me why it’s bad.
I know they recently published the code for their clients, so that's a plus. But I can't find any independent audits for their architecture or clients.
While all mentioned options does have independent audits done.
Microsoft Excel file
Post-it notes on the monitor.
Under the keyboard for added security.
Pass (Password Store)
I've been using Proton Pass since it launched and I think it's really really good.
Positives:
- Nice integration with both desktop and mobile
- Integrated in the proton suite, which I was already using
- Allows you to generate an email alias for each login automatically. Websites will never have your real email and you can easily generate a new alias if one has been compromised
- Supports 2 factor authentication via TOTP, works really well
Negatives:
- No passkey support yet
- Free version only supports like 5 email alias
Can someone explain what those password managers are doing better than Firefox?
I guess a bunch of things, as they are specialized apps:
- proper auth. I think with Firefox you can have a password, but a password manager will have multiple options for 2fa including security keys, and on phone fingerprint unlock etc. In general, password managers are more resistant to malicious users gaining access to your device.
- store all kinds of stuff. Not everything happens in the browser, and it's just convenient to have an app just for credentials. Many password managers allow to store and autofill credit cards too, for example.
- on the fly generation of aliases. Password managers have external integrations. For example proton and bitwarden can integrate with simplelogin.io to generate email aliases when you choose to generate a new username.
- org-like features. Password managers can be also convenient for sharing with family (for example). I do manage a bitwardes organization used by all my immediate family, which means I can share credentials easily with any of them. Besides the sharing I can also ensure my (not tech savvy mom) won't lock herself out (emergency breakglass access configurable) and technically enforce policies on password strength etc.
- as banal as it is, self-managing. I like to run my own services and running my own password manager with my own backups gives me peace of mind.
- another perhaps obvious point. More compatibility? I can use my password manager on whatever device, whatever browser. For some, it might not change anything, but it's a convenient feature.
As a personal addition, I would say that I simply want the cornerstone of my online security to be a product for a company that is specialized in doing that. I have no idea how much effort goes into the password manager from Mozilla, for example.
I need to enter passwords in lots of places that aren't a browser.
If Firefox's password keeper meets your needs, then I would endorse using that, for sure.
No love for Nextcloud Passwords or Passman? Both have plugins for Nextcloud and have Android Apps.
My favorites:
- Proton Pass
- Pros: Aliases, Proton integration
- Cons: No passkeys (yet), native desktop apps in beta
- 1Password
- Pros: SHH agent integration!
- Cons: Least open
- Bitwarden
- Pros: Most open, self hosting option
- Cons: least polished user experience