A review of my experience with Bitwarden after several years of self-hosting it, and why I decided to move away from the password manager.

Note: this is not my article.

  • turdas@suppo.fi
    link
    fedilink
    English
    arrow-up
    91
    arrow-down
    1
    ·
    3 days ago

    My review of your post: you need to stop using so much emphasis on everything. Not every instance of the word Bitwarden needs to be italicized. Also five different ways of storing passwords sounds insane, and harping on for a dozen paragraphs about Bitwarden’s security incidents only to settle on another SaaS password manager sure is a choice.

    • A_norny_mousse@piefed.zip
      link
      fedilink
      English
      arrow-up
      9
      arrow-down
      1
      ·
      3 days ago

      The outward appearance might not be your style, but they make good points, provide facts to support them and most importantly, they remain polite about it.

      I personally think the article is worth reading, at least until just before the last chapter, in which the author outlines their own convoluted ideas. And that’s where such things belong: in the last chapter.

      only to settle on another SaaS

      Do you mean Vaultwarden? AFAICS they do not “settle” on it, but they do argue that it is much lighter in almost every respect. And since it is Bitwarden compatible the comparison is valid.


      Frankly, I think most people just got salty because of the javascript overlay which I found pretty funny; a mild prank and a good demonstration of the power of javascript.

      • turdas@suppo.fi
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        3 days ago

        Do you mean Vaultwarden? AFAICS they do not “settle” on it, but they do argue that it is much lighter in almost every respect. And since it is Bitwarden compatible the comparison is valid.

        I don’t know which one I mean, because OP never says which SaaS password manager they switch to, they simply say they switch to a proprietary SaaS password manager:

        For group A I’m going with a SaaS password manager that offers proper vault sharing, integrates with the tools clients actually use (SSO, browser extensions on corporate machines, audit logs), and takes the hosting burden off my plate. The platform is proprietary, which I would normally not be thrilled about, but given that the scope of this group is client work only, I’m accepting the trade-off.