- cross-posted to:
- bitwarden@discuss.tchncs.de
- technology@lemmy.world
- cross-posted to:
- bitwarden@discuss.tchncs.de
- technology@lemmy.world
In the latest episode of “they will always sell you out” - they sold you out! Who would’ve thought.
Hoping for a good alternative client to appear, the writing is on the wall. Vaultwarden can’t exist without “leeching” off of Bitwarden.
Jesus, I’m tired of switching password managers.
KeePassXC + KeePassDX is probably the best option, with the downside of no way to sync easily (syncthing is probably the best option there)
I might switch back at some point, been getting frustrated with the bitwarden extension performance always being so poor.
Merge conflicts are a concern for KeePass, especially for those that don’t want to resolve them. Sync is difficult. AFAIK this is a very common issue with Syncthing setups.
Also, the portability from Bitwarden to KP leaves a bit to be desired, though that’s probably 90% on BW.
Merge conflicts are a concern for KeePass
It’s really not that much of an issue. I sync my database between several devices, some of which are only used occasionally. Rarely do I ever have a merge conflict.
If you’re editing the database on multiple devices before they have a chance to sync with each other, maybe stop doing that. That’s what causes merge issues.
XC is really nice, but the devs are kinda dicks about not integrating some sort of syncing option, instead telling everyone who asks to “just point it to a local folder and use <insert sync tool of your choice> to keep that folder updated.” Which isn’t terrible advice, but some of us don’t have that option on managed devices.
I ended up using Keepass2Android and just pointing it at my webdav server, it seems to work pretty well!
On desktop it’s already taken care of since I put the DB in my folders that already sync via Syncthing.
I love K2A, been using it for well over a decade now. I really should toss the dev some cash… They’ve kept the UI consistent for years.
KeePass isn’t going anywhere. They’re also dragging their feet on passkey support, so you might go with KeepassXC.
They also don’t effectively allow collaboration though, which is my cheif reason for using a cloud hosted password manager.
KeePass isn’t meant to be used that way. It’s a personal password manager. Always has been.
Valid. But it’s also valid that it now doesn’t work for me or anyone who also helps manage other people’s lives or works on a team ¯_(ツ)_/¯
Gotta use the right tool for the job. Sorry KeePass doesn’t work for you. It really is a fantastic piece of software.
I just got Bit warden this year! Gah. Where are we jumping?
Vaultwarden
Vaultwarden relies on Bitwarden existing.
Not really. Convenience relies on the app and browser plugin, but they could be recreated like the server was.
That would be quite nice to see.
KeePass
That’s troubling, I don’t like what this portends.
The new CEOs background especially suggests they’re spiffing up the company for a later sellout, why else would they pick a merger specialist for the role?
Move to KeePassXC or its recent LLM-free fork while you still can, because at some point Bitwarden is going to try to go closed-source again.
Oh crap, how’s KeePass got an LLM involved‽ Time to look into this now…
I did find https://codeberg.org/ChiPass/ChiPass , but it looks like a very new project.
Yeah, I’m no fan of slopcoding either, but this policy addresses those who contribute AI-generated code; it is most certainly not “our devs are shipping AI slopcode”.
Seems a lot here missed this part:
All code submissions go through a rigorous review process regardless of the development workflow or submitter.
Linus Torvalds does the same thing with the Linux kernel. He gets AI-generated slopcode submissions all the time. They’re reviewed by real people, and like most submissions Linus gets, sloppy work is rejected, AI and human alike.
why this over keepassxc?
When someone says “use KeePass”, we generally mean ”use an app based on KeePass".
Personally, I use the OG KeePass (work laptop), KeePass XC (all personal machines), Keepass2Android (personal Pixel), and Keepassium (work iPhone).
Whichever one you use is entirely subjective. Also, XC wouldn’t exist without the OG KeePass, so maybe don’t be a tribal weird-ass over it.
I’ve been wanting to move to KeePass from my current vaultwarden. What’s the most seamless way to synchronize the DB across GrapheneOS and Arch?
I trust Syncthing for syncing files, but it kind of feels insufficient for an actual encrypted database.
What works for you for syncing?
The encrypted database is a file. Syncthing handles it perfectly fine. KeePass’ protocol has versioning and merge support built right in, so all of the KeePass variants work great with each other without issues over Syncthing.
Just make sure you’re not editing the database on multiple machines at the same time - that’ll cause merge conflicts.
Keepassxc and whatever I’m using off f droid for Android. Then is sync with proton drive. Works well for me. I do the same for my one time password backups. You don’t even need to pay for a subscription to proton. These are small files. Free version is good enough
Yes, I use KeePassDX as well.
sync with proton drive
That’s not good enough. Stay entirely offline. Keep your own stuff in sync via Syncthing and Syncthing-Fork daisy chains, especially if they’re small files.
Has the sketchiness around the Syncthing fork hand-off get sorted?
Yes, the previous maintainer of Syncthing-Fork gave it the green light. Honestly, from the explanation they gave, it sounds like they just have major social anxiety. But it’s all settled. Even the maintainer for the Google Play version is good with it.
Vaultwarden here I come
BW news dropped, so you’re going to move to something that still requires the BW app?
Circular logic, friend. Ditch everything related to BW. Move to a truly open password manager like KeePass (including its various forks).
No one is being “sold out” lol. Anyone using the free tier has had a great run with an amazing service without paying a cent. Can’t complain about that.
I already pay for Bitwarden as it’s a great service that brings a lot of value. I’m happy to pay for it, and have zero anger at a company wanting to make money from their product.
Others might disagree, but companies can’t exist without making money. It’s insane that there are somehow still people that don’t understand how business works.
My work just started giving out 6 sponsored family licenses per employee which is awesome, so I’ll actually get to stop paying for it for a while.
Buddy, I don’t know if you’ve been living under a rock but everything a venture capitalist touches is enshittifying. You think any of these companies you’re reading headlines about are suffering to keep their doors open? When google locks down android or X starts including ads in Grok they’re doing it to keep the lights on? You think if Bitwarden started cutting free services and charging more the average employee is going to get a proportional raise to the new profits?
No. We’re not upset because we dont understand that a company needs to make money. We’re upset because we have basic pattern recognition skills and we understand the nature of late stage capitalism on wealth inequality (at least intuitively). This (likely) isn’t some smart business person coming in to balance the books, this is (likely) some rich asshole whose job is to kill the golden goose and sell it for parts before anyone catches on that you need it alive to produce eggs.
You only have the world you live in thanks to capitalism. Without calitalism things like Bitwarden wouldn’t even exist.
Companies exist to make profit. Investors want profit, that’s why they invest. That’s why these products exist in the first place.
There’s no better system than capitalism, and complaining about “late stage capitalism” and blaming everything on it is dumb.
i was just thinking this week with the passphrase addition how good bitwarden is and when will the other shoe drop. There it is.
Keepass (all variants and forks) has a passphrase generator, been built-in for years.
The writing is on the wall for BW, and has been for quite some time now.
Every company is basically evil at this point.
Since Dodge v. Ford Motor Co (1919), if not earlier.
See also: https://reclaimdemocracy.org/corporate-accountability-history-corporations-us/
Yep. Thanks, Dodge brothers, for setting that precedent. Pig fuckers.
I fucking knew this would happen years ago. Something always smelled “off” about BW.
you saw that something on the internet will go to shit in a couple of years? speak to us, oracle! :)
Right? Lmao who would’ve thought??











