If you are interested in privacy you are probably interested in password storage … plus I wanted everyone to know about the inevitable future enshitification of this product. Spread the word and replacement recommendations are welcome too.

    • That’s the difference between libre software and merely open source software.

      Libre licenses make it hard or impractical to close the source at a later date.

      Open source licenses are much more permissive and allow any entity to produce a closed source derivation at any time.

      Libre licenses are all about strategically protecting the software commons from privatization.

  • Jul ( irotsoma@piefed.blahaj.zone ) 
    link
    fedilink
    English
    arrow-up
    33
    ·
    4 months ago

    Vaultwarden will survive. Since the client is open source, once they close the API and break compatibility of the clients with Vaultwarden, the old version of the app can simply be forked and rebranded. I also do hope that the KeyGuard app will continue to support vaultwarden as well since if bitwarden closes the API and makes a breaking change, as is likely to happen, it will break KeyGuard as well, but it will still work with VaultWarden for some time.

    The real issue is that many people who are using Bitwarden aren’t savvy enough to host Vaultwarden in a secure way. Many people are careless with things like secret keys and such and dont know how to properly secure a web facing app or a VPN into their local network. But anyone who self hosts should result learn those things anyway. This one just happens to be a particularly high risk since it contains all of your passwords for everything else.

  • yuman ( yuman@programming.dev ) 
    link
    fedilink
    arrow-up
    22
    ·
    4 months ago

    if you were looking for an excuse to torpedo this abomination, here it is. hosting this gargantuan stack just for an encrypted csv file? at least the client (electron) gobbles up RAM like it’s free while being bug-compatible with whatever chrome version was current half a year ago.

    sadly, news ain’t great on the other side of the fence - keepassXC dev is all-in on vibeshitting; latest non-polluted version is 2.7.9.; works fine and the stuff they’re working on is pretty far from essential. some unknown folks forked it but who’s to say what their expertise is.

    never thought I’d disable my autoupdate timers but here we are. keep your eyes open.

      • yuman ( yuman@programming.dev ) 
        link
        fedilink
        arrow-up
        15
        ·
        4 months ago

        the dev vibecodes; I make a distinction between using the crap as a boilerplate helper and a full-blown agentic “hey computer, do this but do it super-good!”. not only that, they got a super-asshole vibe as they removed claude traces from the repo and then flaunted that it’s so people won’t know what parts were vibeshat. “good luck finding the cutoff point”, I’m paraphrasing here.

        to each their own, but that’s a hard pass for that fork from me.

    • What do you mean by “gargantuan” stack? I have a single docker container for vaultwarden that was very easy to set up and it uses less than 100mb of ram.

      Not sure about the client claims though. I haven’t really looked into it that much. Are you saying all versions of the client and extensions of BitWarden have issues?

  • fira ( fira@lemmy.today ) 
    link
    fedilink
    arrow-up
    8
    ·
    4 months ago

    I have nothing but good things to say about Proton Pass. Syncs across iOS, macos, PC & Linux, stores not just usernames & passwords, but short notes, product keys, & can generate temporary email addresses that can be disabled when they start receiving spam

      • I do it all the time and it works fine. I designate my phone as my primary computing device and I always update my password database on that device and then synchronize it across to my computer using these things called USB flash drives

        • csolisr ( csolisr@hub.azkware.net ) 
          link
          fedilink
          arrow-up
          1
          ·
          4 months ago

          There’s the problem - not everyone is able or willing to physically connect a separate device to manually transfer the password vault file (for example, on partially airgapped systems or corporate environments). I personally use a self-hosted Vaultwarden for that reason - I’d rather have my main password storage device be one that is safer from being stolen (my home server)

    • Doesn’t keepass only work on a single device? Meaning that you have to handle syncing the database file yourself. I prefer selfhosting vaultwarden. Maybe these changes will make me migrate to something else but for now I’m very satisfied with vaultwarden and the bitwarden client.

      • Yeah, I just leave the file in a NextCloud sync directory. All my desktops and laptops download it automatically, and it’s trivial to download to my phone. As an added bonus, my fucking password manager isn’t exposed to the open internet where every hacker who finds it is gonna wonder what’s inside.

        • You need two apps though and I personally have more faith in vaultwarden being stable than nextcloud.

          Glad your “fucking” password manager isn’t exposed to the internet. Mine isn’t exposed either since I use tailscale to access it. Your comment leads me to believe that your NextCloud instance IS exposed to the internet. Wouldn’t that mean that if a hacker gets access to your account they could also get your keepass file as well?

          • I just typed out a response to most of this, and rather than repeat all that, I’ll copy a link here https://lemmy.zip/comment/26557132

            A lot of it can be summed up in that compromising Vaultwarden means everything is screwed while compromising NextCloud is mainly a minor inconvenience. It provides neither information about the database’s password nor any avenue to attempt to intercept the password.

            • potustheplant ( potustheplant@feddit.nl ) 
              link
              fedilink
              arrow-up
              1
              ·
              edit-2
              4 months ago

              EDIT: Forgot to mention the worst part about KeePassXC. It’s vibecoded crap.

              I replied to that comment. You’re assuming that compromising vaultwarden is somehow easier than compromising nextcloud. No idea why. Intercept the password where? I’m using a local client and only syncing the vault. You seem to be pretty unfamiliar with how vaultwarden works.

              • No, I’m assuming that compromising NextCloud is less devastating than compromising Vaultwarden, so I’m taking a calculated risk that my database’s password is secure enough to offset the slightly increased risk of access to the encrypted database because I don’t always get to choose all the software I get to use in every environment I work with, so I might have to use the web client if I can’t get the local client.

                As for you only using the local client, congrats, we don’t always get to choose what we use outside the home.

              • boonhet ( boonhet@sopuli.xyz ) 
                link
                fedilink
                arrow-up
                1
                ·
                4 months ago

                EDIT: Forgot to mention the worst part about KeePassXC. It’s vibecoded crap.

                Is RiiR still all the rage? Perhaps it’s time to oxidize KeePass. There are a few libraries for kdbx files and at least one ready-made CLI.

    • RotatingParts ( RotatingParts@lemmy.ml ) OP
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 months ago
      1. I want to get to my passwords on multiple devices. 2. Bitwarden has a nice feature where you can set up a trusted person to be able to get into your account by sending you an email and if you don’t respond “no” after a set period of time, they get access. This can be very valuable if the you are incapacitated or dead and that (trusted) person needs to take care of things using your passwords. Are those things available in KeePass, if so, great and I’ll have another look!
      • KeePass is just an app that opens files, so yeah, you can access it on as many devices that you want yo setup file syncing with. Syncthing seems to be a popular choice.

        You can setup vaults to be accessible with multiple passwords, if that fits your criteria. Me, I already share the vault with my wife, so that mostly covers the need for emergency access by someone else. If I ever wanted more, I’d probably just put some basic info into my will about how to access the file.

  • Tinkerer ( Tinkerer@lemmy.ca ) 
    link
    fedilink
    arrow-up
    4
    ·
    4 months ago

    How will this affect vaultwarden? I’ve been using it for 5 years and absolutely love it. I’m worried that I’ll need to switch to something else though?

    • The Article says:

      A Note for Vaultwarden Users

      Whether self-hosting stays viable long-term is the real question worth sitting with.

      Right now it works because Bitwarden’s clients are open source and the server API is public. Vaultwarden implements that API, and the official apps can’t tell the difference. That depends on Bitwarden continuing to publish open source clients and not restricting which servers they’ll talk to — neither of which is guaranteed under new management.

      The brake on the worst case: self-hosting is a listed Enterprise feature that generates real revenue. Killing it upsets paying business customers. That matters.

      The catch: what Bitwarden sells to enterprises is their own official server stack, not Vaultwarden. Vaultwarden exists in a space they’ve tolerated but never endorsed. If the calculus shifts, the tolerance ends without any announcement. Just let the API drift until compatibility breaks on its own.

      I don’t think that’s imminent. But I also thought the free tier commitment was ironclad, and “Always free” isn’t on the page anymore.The real safety net is that Bitwarden’s clients are Apache 2.0 licensed. A fork would need a rebrand to stay clear of the trademark — different name, tweaked UI, same engine — but that’s a speed bump, not a wall. The web vault works through any browser regardless of what happens to the apps, so worst case you’d lose autofill temporarily while a fork caught up. Inconvenient, not catastrophic. Vaultwarden itself is already proof the model works.

      Watch the clients. If they go closed, the community will notice fast, and the fork will follow.

    • It shouldn’t in theory. Worst case is if bitwarden closes source, just fork the latest current open version and use it.

      Ideally, a group, either independent or joining with vaultwarden devs, can build/maintain the frontend for vaultwarden that is bitwarden.

  • altphoto ( altphoto@lemmy.today ) 
    link
    fedilink
    arrow-up
    3
    ·
    4 months ago

    I just tested aliasvault and its pretty good. You can even just import your pre-enshitification Vaultwarden export file.

    One thing I noticed though is that your entries must have a collection or else they don’t export. But close to easy as pie to leave vaultwarden behind with their Nazi CEO.