this post was submitted on 20 Oct 2024
628 points (87.5% liked)

Technology

58863 readers
4526 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
(page 4) 50 comments
sorted by: hot top controversial new old
[–] [email protected] 129 points 4 days ago (15 children)

Oh, for fuck’s sake. Can we have a decent password manager that isn’t tied to a browser or company? I pay for Bitwarden. I’m not being cheap. But open source is more secure. We can look at the code ourselves if there’s a concern.

[–] [email protected] 28 points 4 days ago (10 children)
load more comments (10 replies)
load more comments (14 replies)
[–] [email protected] 30 points 4 days ago (9 children)

Keepass vault synced over syncthing.

I keep not regretting it.

[–] [email protected] 32 points 4 days ago (4 children)

Was going to be my solution as well, bjt Syncthing-Android just got discontinued.

load more comments (4 replies)
load more comments (8 replies)
[–] [email protected] 6 points 4 days ago (1 children)

Sooo, where's ProtonPass at? They're open source and non-profit, right?

[–] [email protected] 12 points 4 days ago (2 children)

The server is not open source and I wouldn't trust a business that is not just working on password managers.

[–] [email protected] 14 points 4 days ago (3 children)

and I wouldn't trust a business that is not just working on password managers.

Because..? They're a privacy tool oriented company, no?

load more comments (3 replies)
load more comments (1 replies)
[–] [email protected] 10 points 4 days ago
[–] [email protected] 19 points 4 days ago (5 children)

Well this ain't good. I don't really feel like switching apps.

load more comments (5 replies)
[–] [email protected] 61 points 4 days ago (4 children)

Goddammit. It's getting to the point I'm going to have to figure out how to write my own app for this.

[–] [email protected] 6 points 4 days ago* (last edited 4 days ago) (6 children)

It shouldn't even be that complex...

I might be mistaken, but ultimately a password manager is basically nothing more than a database of passwords in an encrypted zip file, right? That could entirely be self-hosted with off the shelf open source applications stringed together.
All you'd need is a nice UI stringing it all together.

Edit: I'm not sure why people are downvoting me. Is that not what a password manager essentially is?

[–] [email protected] 30 points 4 days ago

Keepass is exactly that. Basically all the client side parts, and the database is a single encrypted file that you can sync however you want.

[–] [email protected] 11 points 4 days ago

I've done basically this in the past by encrypting a text file with GPG. But a real password manager will integrate with your browser and helps prevent getting phished by verifying the domain before entering a password. It also syncs across all my devices, which my GPG file only worked well on my desktop.

[–] [email protected] 6 points 4 days ago

That is the bare minimum of a password manager like Bitwarden.

[–] [email protected] 3 points 4 days ago

Yup, thanks. Was thinking along these same lines.

load more comments (2 replies)
load more comments (3 replies)
[–] [email protected] 214 points 4 days ago* (last edited 4 days ago) (3 children)

This is an important issue IMO that needs to be addressed and the official response by Bitwardens CTO fails to do so.

There is not even a reason provided why such a proprietary license is deemed necessary for the SDK. Furthermore this wasn’t proactively communicated but noticed by users. The locking of the Github Issue indicates that discussion isn’t desired and further communication is not to be expected.

It is a step in the wrong direction after having accepted Venture Capital funding, which already put Bitwardens opensource future in doubt for many users.

This is another step in the wrong direction for a company that proudly uses the opensource slogan.

[–] [email protected] 64 points 4 days ago (2 children)

Welp, I guess another time to move here soon.

And I just fucking vouched for them to a friend recently 🤡

Didn't know about VC funding these parasites using their funding to turn everything into shite.

What's the current "best" alternative? Keepass?

[–] [email protected] 17 points 4 days ago (1 children)

I haven't jumped yet, but the Proton suite is looking more and more appealing. I've been eyeing them as a Gmail replacement, but I've been happy with my VPN and password management providers. As this reduces the bundle makes more sense.

[–] [email protected] 29 points 4 days ago (2 children)

They have a solid value proposition but don't like putting all my eggs all in one basket both for security and monopoly reasons.

They seem to be gunning for one stop shop and I think they are doing decent shop but I just don't like the idea after what Google did to us.

Situation is a bit different but gonna need to tka the lessons and not let these corpos do this again.

load more comments (2 replies)
load more comments (1 replies)
[–] [email protected] 100 points 4 days ago (2 children)

nothing lasts forever without being enshittified

load more comments (2 replies)
load more comments (1 replies)
[–] [email protected] 23 points 4 days ago

This is disheartening.

[–] [email protected] 86 points 4 days ago* (last edited 4 days ago) (3 children)

Vaultwarden updated link

Open source version of bitwarden written in rust.

Where is the foundation to support foss?!?

[–] [email protected] 53 points 4 days ago (4 children)

If they're moving away from open source/more monetisation then they're going to do one of two things.

1: Make the client incompatible (e.g you'll need to get hold of and prevent updating of a current client).
2: DMCA the vaultwarden repo

If they're going all-in on a cash grab, they're not going to make it easy for you to get a free version.

[–] [email protected] 27 points 4 days ago (1 children)

Don't forget option 3: someone writes a vaultwarden client independent of the closed-source crap.

If you can write a server that fully supports the client via the documented API, then you know everything you'd need to do to make a client as well.

load more comments (1 replies)
load more comments (3 replies)
[–] [email protected] 26 points 4 days ago

You have your link formatted backwards. It should be Vaultwarden, with the link in the parentheses.

[–] [email protected] 7 points 4 days ago

This is by no means to a slight towards bitwarden. Solid product and community

load more comments
view more: ‹ prev next ›