TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Bitwarden – Open Source Password Manager

337 pointsby GutenYealmost 7 years ago

33 comments

ohthehugemanatealmost 7 years ago
I switched from LastPass to bitwarden in November, and I love it.<p>- it&#x27;s FOSS, and audited, so it&#x27;s software I can trust<p>- great UX on Firefox, chrome, and even Edge. I had my issues, but the project improved them away very quickly.<p>- sharing support for families or organizations.<p>- convenient standalone clients for win&#x2F;Mac&#x2F;Linux... And even the CLI.<p>- built in 2FA code generation for each entry, so I don&#x27;t need a separate app for that.<p>- the best autofill I&#x27;ve experienced, on desktop browser and even on mobile(!)<p>- open API so there are third party clients available<p>- the lead developer is super responsive on GH, so I&#x27;ve been able to contribute.<p>- cheaper than the alternatives (at least at the time), and I feel good about where my money is going.<p>I can&#x27;t recommend it strongly enough. It&#x27;s one of the OSS applications that has a permanent place on all my devices, right up there with Firefox quantum in my &quot;great examples of OSS&quot; liste.
评论 #17505778 未加载
评论 #17505642 未加载
评论 #17505478 未加载
评论 #17508254 未加载
评论 #17507920 未加载
keehunalmost 7 years ago
I really, really want to be a big fan of Bitwarden. I even used it for the past year and a half. However, the last time HN talked about Bitwarden 7 months ago, I listed some reasons[0] why Bitwarden still fell massively short of 1Password, and I feel that those three points have not been addressed (which I believe impacts the friction&#x2F;convenience of using Bitwarden).<p>My three points then were:<p>1. A stand-alone desktop app. Quite annoying to have to open up a browser every time I want to access a password. Basically, it&#x27;s as inconvenient as Keychain on OSX if you&#x27;re not using a browser when you need a login info. This could be solved if the browser plugin popup could be persisted as its own window.<p>2. iOS app is not polished. Not sure about Android app as I&#x27;ve not used it. (* biggest problem then was how slow search was. It has been improved although nowhere as fast as 1Password&#x27;s—still)<p>3. In the Safari extension, I would love to be able to search and use item entries that are not specific to the domain. Sometimes, I have other info in secured notes or password entries without a domain that I want to get to from the extension. In these cases, I&#x27;ve had to leave the browser and open the actual app to get access to them.<p>I just migrated from Bitwarden to 1Password a few days ago and have been much happier since—especially with 1Password&#x27;s ability to generate 2 factor tokens and put them in your pasteboard automatically so you don&#x27;t ever have to pull up an Authenticator app!<p>[0]: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15734260" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=15734260</a>
评论 #17504323 未加载
评论 #17504495 未加载
评论 #17505089 未加载
评论 #17505956 未加载
评论 #17505113 未加载
评论 #17509137 未加载
m_sahafalmost 7 years ago
There are also two Bitwarden-compatible API implementations in Rust[0] and Ruby[1]. Their main advantage, IMO, is them doing away with the requirement of Microsoft SQL Server.<p>[0] <a href="https:&#x2F;&#x2F;github.com&#x2F;dani-garcia&#x2F;bitwarden_rs" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;dani-garcia&#x2F;bitwarden_rs</a><p>[1] <a href="https:&#x2F;&#x2F;github.com&#x2F;jcs&#x2F;bitwarden-ruby" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;jcs&#x2F;bitwarden-ruby</a>
评论 #17504919 未加载
评论 #17504470 未加载
评论 #17504205 未加载
nickjjalmost 7 years ago
If anyone wants an open source command line driven password manager that doesn&#x27;t require signing up or hosting anything, I recommend checking out &quot;Pass&quot;. It piggy backs off GPG encryption.<p><a href="https:&#x2F;&#x2F;www.passwordstore.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.passwordstore.org&#x2F;</a><p>I use it to manage over 300 passwords and other sensitive blobs of text (it lets you save arbitrary text snippets) and also has some nifty quality of life features like auto-copying a password to your clipboard for 30 seconds when you want to access a specific password.
评论 #17507082 未加载
pmontraalmost 7 years ago
<a href="https:&#x2F;&#x2F;github.com&#x2F;bitwarden&#x2F;core&#x2F;blob&#x2F;master&#x2F;README.md" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;bitwarden&#x2F;core&#x2F;blob&#x2F;master&#x2F;README.md</a><p>SQL Server 2017, really? Interesting choice. Open source but we have to pay licenses for the database if we want to self host. I wonder what was wrong with PostgreSQL or MySQL even if they&#x27;re using .NET Core as a language.<p>Edit: there is an issue for that <a href="https:&#x2F;&#x2F;github.com&#x2F;bitwarden&#x2F;core&#x2F;issues&#x2F;10" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;bitwarden&#x2F;core&#x2F;issues&#x2F;10</a>
评论 #17505674 未加载
评论 #17505500 未加载
评论 #17507707 未加载
评论 #17505316 未加载
jhabdasalmost 7 years ago
For years I&#x27;ve discouraged use of clouds for storing passwords. But because Bitwarden is FOSS software, encrypts data on the client, has good cross-platform support, and can operate if the company goes out of business they have won me over for the storage of secrets I&#x27;m not reserving for the sneakernet.
评论 #17504600 未加载
ramses0almost 7 years ago
<a href="https:&#x2F;&#x2F;www.passwordstore.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.passwordstore.org&#x2F;</a>
评论 #17504863 未加载
评论 #17505078 未加载
评论 #17504210 未加载
albertopalmost 7 years ago
First paragraph on their page disqualifies it completely. I do not want my passwords on anybody’s servers.<p>Our secure cloud syncing features allow you to access your data from anywhere, on any device! Your vault is conveniently optimized for use on desktop, laptop, tablet, and phone devices.
评论 #17504263 未加载
评论 #17504401 未加载
评论 #17504670 未加载
评论 #17504618 未加载
widerporstalmost 7 years ago
I&#x27;m using KeepassXC on desktop, Keepass2Android on mobile and Dropbox for syncing the database and I&#x27;m quite happy with it. Bitwarden looks a bit more polished, but are there any other advantages over Keepass?
评论 #17505143 未加载
评论 #17508721 未加载
ron22almost 7 years ago
I love Bitwarden. I signed up when it first launched and happy to see it continue to add features. One of the only projects I pay to support the project rather than to get access to the additional premium features.
anotherevanalmost 7 years ago
I recently switched to BitWarden from Lastpass after trying a few different options including pass, Enpass and KeePass options.<p>95% of my usage is in the desktop browser, and the UI of their add-on is great, IMO.<p>Lastpass&#x27; had been getting worse for some time, and their shuttering of Xmarks finally left me with no good reason to stay.<p>Using the add-on with Firefox on my phone is reasonable, although could be a bit better. Phone experience in general I&#x27;d say is also quite reasonable - not used it that much yet, but I think it is quite comparable to other offerings.
评论 #17504608 未加载
czei002almost 7 years ago
On problem with password managers (that are using web authentication to create&#x2F;manage an account for backing up the password manager in the cloud) is that the authentication password can be leaked during the authentication process. For example, the storage provider for password manager backup can simply read the password from the authentication web page since this web page is hosted at the provider. This is problematic if the authentication password is also used to encrypt the password manager, i.e. the provider could decrypt the password manager with the authentication password. You would actually need two passwords; one for authentication and one for encryption. Unfortunately, you usually don&#x27;t even have the option to choose two passwords.<p>To solve this problem I&#x27;m working on FejoaAuth (<a href="https:&#x2F;&#x2F;fejoa.org&#x2F;fejoapage&#x2F;auth.html" rel="nofollow">https:&#x2F;&#x2F;fejoa.org&#x2F;fejoapage&#x2F;auth.html</a>). FejoaAuth uses an authentication protocol that does not leak the user password to the provider who is going to store the password manager. This protocol is run in a trusted browser plugin in order to ensure the correct execution of the protocol. Thus you can use a single password for authentication and password manager encryption.
commanderkeen08almost 7 years ago
Here’s why I switched from 1Password—<p>I recently picked up a Pixelbook and have gone all in on ChromeOS. Its replaced my MBP. But unfortunately, that meant parting ways with 1Password.<p>I needed a new password manager with the following: Self hosted TOTP support (have since decided not to use this) A web UI IOS app with face&#x2F;Touch ID.<p>I tried the 1Password subscription but 1Password X just felt too clunky and I wasn’t in love with storing on their server.<p>Keepass&#x2F;XC&#x2F;whatever was a hot mess for me. I really wanted to use it and the idea of keeping and syncing a single db file still really appeals to me, but the ecosystem is such a mess. I tried running a self hosted container for Keepass Web but I kept having to enter a Dropbox API key on every client. I also couldn’t find an iOS app that supported Face ID or the option for storing TOTP. Maybe it’s a better experience on Android. On top of that, the UI was pretty jarring all around.<p>Bitwarden still has some work in the UI department. The lack of keyboard shortcuts and a native app adds some resistance but it’s manageable for me.
duxupalmost 7 years ago
I&#x27;ve been a Keepass user for so long I just haven&#x27;t wanted to switch. I just don&#x27;t want to use someone else&#x27;s server... or setup my own. Even so best of luck to them.
评论 #17504558 未加载
fluxsaucealmost 7 years ago
If you were curious about the Open Source part (I was) - <a href="https:&#x2F;&#x2F;github.com&#x2F;bitwarden&#x2F;" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;bitwarden&#x2F;</a>
amanzialmost 7 years ago
I&#x27;ve been using this for the last few months and couldn&#x27;t be happier. I use the browser extensions in Firefox, Chrome and Edge, as well as the desktop, Android and web apps.
评论 #17504127 未加载
评论 #17504770 未加载
amaccuishalmost 7 years ago
I like Enpass. Syncs to my own nextcloud. What other password managers can do that out of interest?
评论 #17505955 未加载
评论 #17505941 未加载
Mefisalmost 7 years ago
Any reason not to use Firefox&#x27;s own password sync? It&#x27;s been working fine for me so far.
pvgalmost 7 years ago
Has come up a fair bit before.<p><a href="https:&#x2F;&#x2F;hn.algolia.com&#x2F;?query=bitwarden&amp;sort=byPopularity&amp;prefix&amp;page=0&amp;dateRange=all&amp;type=story" rel="nofollow">https:&#x2F;&#x2F;hn.algolia.com&#x2F;?query=bitwarden&amp;sort=byPopularity&amp;pr...</a>
评论 #17504295 未加载
untitled_bobalmost 7 years ago
1Password works great on iOS and macOS but it&#x27;s not open source... and there&#x27;s the subscription they try to impose... and their servers... So I was looking to replace it. Bitwarden could be the one in the near future as Keepass is a real pain on iOS and mac for a non-techie. The problem I still have with bitwarden is that the app won&#x27;t work unless connected to the internet. If the connection is missing you can&#x27;t add or edit anything, store on your device and sync later :-(
ericseppanenalmost 7 years ago
&quot;Each Bitwarden installation requires a unique installation id and installation key.&quot;<p>Sorry, it doesn&#x27;t count as open source if everyone needs your permission to run it.
评论 #17504475 未加载
alexeymetzalmost 7 years ago
This is nice product, but server requirement completely eliminates it as a candidate instead of 1Password for me. I still can&#x27;t find a better open-source solution which works completely offline on desktop, browsers and mobile devices with the possibility of synchronization using 3rd-party services, decent UI and at least the ability to store TOTP passwords.<p>Enpass is good, but it&#x27;s proprietary too.
logixalmost 7 years ago
It&#x27;s full of shills every time there&#x27;s an article about password managers. I wonder if they come from LastPass or 1Password.
Solar19almost 7 years ago
This looks like it could be better than LastPass. Bitwarden is the only password manager that I&#x27;ve seen that officially supports Opera, Vivaldi, and Brave. I wonder what the browser support on Android is like. LastPass seems to work only on Chrome on Android, but I like to use Firefox, Opera, and Samsung&#x27;s optimized browser.
评论 #17504464 未加载
评论 #17507848 未加载
geberlalmost 7 years ago
If you&#x27;re searching for an open-source self-hosted alternative that offers corporate features like LDAP integration take a look at SysPass (<a href="https:&#x2F;&#x2F;github.com&#x2F;nuxsmin&#x2F;sysPass" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;nuxsmin&#x2F;sysPass</a>). Doesn&#x27;t look as nice as Bitwarden though.
rohan404almost 7 years ago
We evaluated Bitwarden to use as our company vault for shared accesses, however found OneLogin to have a better UI, additional functionality (especially when it came to syncing with our Google directory) and the price (for enterprise) wasn&#x27;t too much less than OneLogin (which is negotiable anyways).
评论 #17504395 未加载
ggmalmost 7 years ago
If somebody wrote code to let me send the second factor from a nominated device as my banks use of Symantec technology does.. it would be cool: I keep meaning to remind myself having the second factor inside 1password is not a second independent factor.
tehabealmost 7 years ago
What I really like about Bitwarden is, that you can define several URLs for one entry, I have some services which can be accessed from several addresses (same account) though.<p>It is also possible to define how a URL is matched which is a nice feature too.
solidrakealmost 7 years ago
I love the Linux app, and the integration on browser extensions and Android app, but the Android app is very limited on features. I love projects like this, and support them as a paid member, just like ProtonMail.
cipherzeroalmost 7 years ago
I love bitwarden, and have converted to it. However i just learned about <a href="https:&#x2F;&#x2F;passman.cc&#x2F;" rel="nofollow">https:&#x2F;&#x2F;passman.cc&#x2F;</a> Has anyone used that?
评论 #17505164 未加载
dorfsmayalmost 7 years ago
Can you keep the database on a local disk, Dropbox etc?
评论 #17504260 未加载
评论 #17504242 未加载
xtfalmost 7 years ago
Seriously? A password manager where the desktop app is build ontop of unsecure electron.
评论 #17505513 未加载
vasili111almost 7 years ago
What are the advantages and disadvantages of Bitwarden over KeePassXC?
评论 #17509756 未加载