Bitwarden
Privacy
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
much thanks to @gary_host_laptop for the logo design :)
Nobody else here is using Keepass with syncthing for cross-device syncing? I can't dont know of an easier, more more reliable and secure method.
Same here, KeePassXC via Syncthing, has been working like a charm for many years and I love it.
Hello everyone, what is your go-to password manager?
KeePassXC for something hosted locally on your home network. Best aspect of KeePassXC is the support for OTP codes built-in, in my opinion. For mobile OTP codes, I personally use Aegis.
What would you suggest for friends and family that aren’t very tech savvy?
Bitwarden for non-tech-savvy family and friends.
Bitwarden has always worked great for me on android.
BitWarden. All day everyday. Every human
you don't have to be very tech savy to use a password manager. I use a keypass variant for local ones and keep important ones there and bitwarden online with stuff that if it got taken over would not matter.
KeePassXC (Desktop) and KeePassDX (mobile). Offline, local-only password manager. There's also a Firefox browser extension for it too.
If you need it to sync between devices, Syncthing gets the job done by syncing the DB file.
I don't trust any cloud solutions. You're trusting some random company with your passwords. Data breach is inevitable.
i've used 1password forever and have the family plan for my mum and dad and they're fine with it. plus it's canadian not american.
ProtonPass
Proton Pass, I use the full suite so it's just convenient. It also has a few nice functions like e-mail aliases and secure password share links.
Let the proton haters come👀.
secure password share links.
That is one of the things that I really wish were on bitwarden
Keepass and Bitwarden respectively. Keepass has a lot of fringe advantages but most important to me is automation and offline consistency. Bitwarden will let you stay logged in offline depending on the options but it's a bit different and they offer some kind of premium service. They both have good Android apps and Firefox addons
Bitwarden, DON’T self host.
Why not self host?
Because if it’s something that’s vital, you should just pay to have someone else host it. ESPECIALLY if it’s a nominal cost per year.
Thanks for answering. I don't self host it but am interested. It's still a company that i entrust to store highly sensitive data with, hence my interest in self hosting. Usually folks promote self hosting, so i was curious about your comment to not. Agree, that's not something to consider lightly.
Porque no los dos?
Firefox
Can't tell if serious.
Give me reasons to not use firefox's pw manager and I'll jump back to bitwarden
As a general rule, browser based password storage is less secure than a standalone offering. While convenient, Firefox loads the cipher into memory. and stores passwords in a local file (logins.json) encrypted with 3DES (older versions) or AES (newer), using a key derived from an optional primary password. Without a primary password, Firefox uses a blank key, making it trivially decryptable. Even with one, decryption occurs locally but lacks the layered, zero-knowledge design of something like Bitwarden. This makes Firefox stored passwords more vulnerable to something like a virus outbreak on your computer, which can access your Firefox stored passwords.
This is how I understand it. If someone has better intel, or if I need schooled up, do share.
Thank you for taking the time to write this
You are welcome. Anytime. I'm not the sharpest knife in the drawer but I do like to help.
Even if all the rest were true, what virus outbreak would affect me on Linux?
I am basically relaying conventional wisdom I have gleaned over the years of 'best practice'. I also forget that a lot of people in the privacy sphere run Linux solely, where as I run Windows, Linux, and Mac. I hold no high ground in privacy, security, or anonymity. You are certainly within spec to run your network as your requirements deem necessary. I'm just a lot more comfortable not using a browser to store my passwords. If you've got it all down to a note, then rock on my brother and don't let them give you shit about your ponytail either.
You seem to be much more knowledgeable on the topic, and while I would call myself privacy conscious, I would hardly consider myself within the pricacy sphere. How would using something like bitwarden or keepassxc work with entering passwords on websites? Firefox just retrieves it from its vault (as bad as it may be from what I'm reading) and then inserts it into the u/p fields. I've seen LastPass in action plenty, because corporations seem to love it, and I find it anything but seemless. So how do those two aforementioned compare?