I find this move concerning, and wish that the Founder had looked for a new CEO that shared his values rather than a Private Equity and Mergers Expert.

Furthermore, the change to the GRIT motto is worrying. Trust is useless without Transparency when it comes to code and security.

      • refract@lemmy.zip
        link
        fedilink
        English
        arrow-up
        5
        ·
        edit-2
        1 hour ago

        But you still use the official BW client apps, correct?

        Unless you forego usage of the clients and access Vaultwarden through the browser (removing accessibility and convenience especially on mobile), it is not an e2e replacement solution.

        Are there any alternative FOSS clients/apps that work with Vaultwarden?

        Edit: I see further down that the official client is open source, and would get forked in the event of any fuckery. So I’m sticking with Vaultwarden + Official client app approach for now.

        • Iced Raktajino@startrek.website
          link
          fedilink
          English
          arrow-up
          2
          ·
          48 minutes ago

          I just use the webapp UI and don’t bother with the clients/extensions. Easy enough to just log in, copy/paste from there.

          But yeah, the official client (and probably browser extension as well) would probably be forked if/when needed.

    • zikzak025@lemmy.world
      link
      fedilink
      English
      arrow-up
      54
      arrow-down
      1
      ·
      4 hours ago

      KeePassXC is the best FOSS option, but you’ll need to figure out self hosting if you want to sync the database between devices.

      • M1k3y@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        19
        ·
        4 hours ago

        As the database is encrypted in your device, you dont really need to self host. A keepass database in the Google cloud is not really problematic, although you should still choose a more private cloud provider.

          • Victor@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            14 minutes ago

            Which algs would that be? ed25519 okay? Is that even an encryption alg? I’m not too hot with encryption.

          • mnemonicmonkeys@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            14
            ·
            3 hours ago

            Assuming you have a degoogle’d phone. The syncthing-fork devs announced that they aren’t going to certify for Google Play when that’s made a requirement in a few months

            • meathappening@lemmy.ml
              link
              fedilink
              English
              arrow-up
              6
              ·
              2 hours ago

              Ugh, I forgot about this. Aren’t you still going to be able to install apps from third-party marketplaces? I thought the plan was just that the phone was going to hassle you and require multiple hoops.

        • Quetzalcutlass@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          3 hours ago

          And you can use a keyfile separate from the database for even more security. If the database is backed up on Google Drive and the keyfile is saved on a USB or in a (non-Google) email somewhere for the rare times you add a new device, your passwords should be safe even from keyloggers or Google themselves.

    • meathappening@lemmy.ml
      link
      fedilink
      English
      arrow-up
      14
      arrow-down
      1
      ·
      4 hours ago

      Coincidentally, I moved to self-hosting Vaultwarden last night, which is open source but compatible with Bitwarden. If you want a simple transition and are capable of hosting it yourself, that would be my recommendation.