Elektrine lite

← Feed

@mesamunefire@piefed.social

I Do Not Recommend Bitwarden

2026-05-02 05:07 UTC

A review of my experience with Bitwarden after several years of self-hosting it, and why I decided to move away from the password manager. Note: this is not my article.

Replies (8)

  • @turdas@suppo.fi 2026-05-02 05:48

    My review of your post: you need to stop using so much emphasis on everything. Not every instance of the word Bitwarden needs to be italicized. Also five different ways of storing passwords sounds insane, and harping on for a dozen paragraphs about Bitwarden’s security incidents only to settle on another SaaS password manager sure is a choice.

    Open ##2274981

  • @ccunning@lemmy.world 2026-05-02 05:56

    What’s with the sketchy domain name? Doesn’t really instill trust enough for me to click on let alone listen to their opinion.

    Open ##2275702

  • @A_norny_mousse@piefed.zip 2026-05-02 09:22

    What’s with the downvotes? The article makes good points, and brings them across politely: it’s a $100M for-profit company it’s heavy (compared to Vaultwarden, a Bitwarden compatible Rust rewrite) its code base requires proprietary MS libraries and other esoteric (seen from the POV of a *nix user) stuff. I might have summarized this one badly, just read the chapter, it’s not long. My guess is people are salty because they use Bitwarden and don’t like to see it criticized they got upset by the javascript overlay which is hilarious imo. I certainly got rick-rolled for a hot second. FWIW, I don’t serve my password database on the www at all. It sits on my own server and I can access it with all my devices, but the software to do that is local only.

    Open ##2304180

  • @one_old_coder@piefed.social 2026-05-02 06:26

    Your JS overlay is annoying and stupid.

    Open ##2321267

  • @deegeese@sopuli.xyz 2026-05-02 14:27

    But what if you don’t want to self host your password manager? Any non terrible choices?

    Open ##2321277

  • @eager_eagle@lemmy.world 2026-05-02 17:26

    Bitwarden’s npm distribution pipeline stayed compromised for approximately 19 hours and 334 developers had enough time to pull the malicious package before it was caught. It was actually about 90 minutes Everyone running bw in a CI pipeline just handed the attackers whatever else happened to live on that machine. only if they installed bw in that time window Otherwise yes, I agree it’d be better if the CLI was written in a non-JS/TS ecosystem. Perhaps Rust or Go. And the criticisms to list including secrets are super valid.

    Open ##2321280

  • @punrca@piefed.world 2026-05-02 18:50

    I use KeepassXC on my laptop (completely offline), export the encrypted backup copy and store the backup offline copy and in cloud. Also, I manually import the backup file into my Keepass2AndroidOffline android app (it’s a hassle, but I’m okay with it) But for normies (non-technical folks), the benefits and convenience of using a cloud-based password manager is far outweighed by any security vulnerabilities in such password managers. Also, Bitwarden’s source code is open-source (unlike other closed-source password managers), so I trust it more.

    Open ##2321289

  • @NGC2346@sh.itjust.works 2026-05-03 13:25

    Dude it affected devs through Bitwarden CLI, it aint that deep my boy, and self hosting it protects you in this regard because you dont need to update your instance the millisecond a vulnerability or a malware is pushed, giving the time to review the changelog and changes. Chill out.

    Open ##2321314