rsyring
7 hours ago
Very insightful blog post listed by another user as a sub-comment. Worth posting as a top-level comment:
https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden
Previously discussed: https://news.ycombinator.com/item?id=48163389
nugget
7 hours ago
Great find. This blog post - and specifically the background of the new management team - convinced me to start looking for a Bitwarden alternative. I’m watching the same “boil the frog” strategy unfold at Namecheap, and erode much of the brand trust they had built up over a decade, and it’s a shame.
jventura
4 hours ago
> I’m watching the same “boil the frog” strategy unfold at Namecheap, and erode much of the brand trust they had built up over a decade, and it’s a shame.
What's happening with Namecheap? I've been a user for a long time and haven't noticed anything.. Maybe I'm one of the frogs being boiled!
ygjb
4 hours ago
Same question, I use CloudFlare for alot of API DNS stuff but register with name cheap because it's been a a good service provider so far.
turtletontine
7 hours ago
Have you settled on a BitWarden alternative, or a short list you’re considering?
birksherty
6 hours ago
Proton Pass. I stopped using Bitwarden for a different reason, the mobile app was too slow when not connected to internet. I can't accept such slowness, the company will definitely give justifications for this. But I don't care, let me see my passwords or notes for a website immediately. Proton Pass is better in this regard.
doodlesdev
5 hours ago
Proton Pass cannot be self-hosted.
jchw
4 hours ago
I am using Keepass XC + Keepass DX synchronized with Syncthing. There's really nothing to self-host, other than throwing Syncthing on a NAS so you can make sure you have at least one machine online at all times. But even that isn't critical, since both Keepass XC and Keepass DX have a "Merge" option if anything falls out of sync.
jonny2811
3 hours ago
ive used keepassxc forever, switched to proton pass after the release, because i was managing my db in git and it was always a pain to keep in sync, but switched back a couple of weeks ago with exactly the same setup, syncthing and KeepassDx also works suprisingly well.
mostly i was missing power user features and especially ux for the browser plugin, namely you can't operate it fully with the keyboard, with keepassxc you can
sliken
5 hours ago
As as self-hoster, I recommend vault warden. Supports 2fa, written in rust, works pretty well, is easy to backup, and you can use bitwarden's phone client.
I'm curious why other self hosters think it's a bad idea.
BrandoElFollito
38 minutes ago
I moved to the cloud for a simple reason: if I die tomorrow people who depend in the service are screwed. And this is an important service, like email or digital archives.
nightski
10 minutes ago
I'm confused, so you are self hosting it for other people?
dwedge
3 hours ago
> and you can use bitwarden's phone client
What will you use when this stops working in the near future?
haellsigh
3 hours ago
You use Keyguard (https://github.com/AChep/keyguard-app).
movsx
4 hours ago
Presumably, it's a memory hog. What is your RAM usage?
ulimn
3 hours ago
I think the memory hog you're thinking of is the official Bitwarden self-hosted backend. Vaultwarden is pretty light on resources.
rented_mule
3 hours ago
For me, vaultwarden's RSS is ~45 MB, with ~13MB of that being shared. I have it running as a secondary thing on a 512 MB machine and don't notice it's there. Is there a reason you presume it's a memory hog?
movsx
3 hours ago
I'm surprised, actually. I expected at least an order of magnitude more. In my humble opinion, this is still a lot of memory -- probably an order of magnitude (or even two) more than what is realistically required for the task. But this is just my own philosophy, and I do realize that the days of careful memory utilization are long gone.
Thanks for sharing.
nh2
3 hours ago
For me, RSS 35 MB, SHR 23 MB. The vaultwarden executable is 38 MB (typical Rust executable that links Rust code statically, and only dynamically links libssl.so and libc.so dynamically).
So probably its RSS usage is just mostly its own executable code?
zikduruqe
41 minutes ago
But passwordstore.org can.
No reason to use anything more complicated.
missmewiththatl
5 hours ago
As a self-hoster, I don't think password managers should be self-hosted.
Oxodao
5 hours ago
On the contrary. If there's one thing you should self-host is definetly password manager.
nine_k
3 hours ago
Why, you can of course self-host it, too, but the infrastructure should be entirely separate.
tappio
5 hours ago
I don't see much reason not to self-host a properly built password manager like Vaultwarden or something similar? The clients keep a local encrypted copy of the vault, so the server only needs to be up for syncing. If it went down for a week, you probably wouldn't even notice unless you were saving new logins. And even if the server got hacked, everything on it is encrypted. Why do you think it should not be selfhosted?
Barrin92
3 hours ago
you just listed all the reasons why you don't need to self host yourself
SV_BubbleTime
2 hours ago
Thanks, on these topics I feel like I’m fucking crazy for not wanting to self host.
If you believe that the technology works, that encryption is happening and that the decryption is only happening on your local machine then why in the fuck would I host this myself?
You need to believe that it does not work when they do it, but does work when you do it.
I have not seen any evidence of that.
jazzyjackson
5 hours ago
Can’t relate. If you’re worried about you’re own reliability to keep it online, just keep paper backups
cortesoft
5 hours ago
What? Why not?
torzer321
5 hours ago
password managers should not involve hosting at all, use something file-local, keepass(xc) or alike
nine_k
3 hours ago
It should be something like, well, git (but likely not directly git): something that replicates easily, so that you'd have a remote copy accessed via internet ("hosted"), and local copies where you see fit.
rascul
2 hours ago
pass can use git
SV_BubbleTime
2 hours ago
Keepass people always in these topics with ”offline rules!! … now let me tell you how I use it with a copy on my phone and sync it with Dropbox and a backup on a git repo”
jazzyjackson
5 hours ago
What’s wrong with self hosted vaultwarden ? I guess there isn’t a FLOSS extension client/app?
dwedge
3 hours ago
Presumably the bitwarden apps will stop working with them eventually
pas
3 hours ago
addig Vaulwarden compatibility to already FOSS mobile password managers might be the path of least resistance
or pooling together tokens and asking Claude nicely to make a mobile app
limagnolia
3 hours ago
Or just fork the OSS bitwarden client?
dwedge
2 hours ago
With android changes this year how do you deploy it?
alasano
3 hours ago
That's funny, Bitwarden and Namecheap are the two things I've migrated away from as well.
The switch to Vaultwarden was insanely easy.
movsx
an hour ago
Just curious, why Namecheap?
28304283409234
an hour ago
And gandi.net.
backlit4034
6 hours ago
GlassDoors reveal the other side of the story
https://www.glassdoor.com/Reviews/Bitwarden-Reviews-E4337610...
alt227
6 hours ago
Wow, another site that now refuses to play ball unless you sign in.
Guess I'll never be visiting Glass Door again then.
to11mtm
6 hours ago
GlassDoor has been gross about this for years.
Not sure if still the case but normally you have to not only 'sign in' but also feed them information (e.x. salary at a position, write a review, etc.) in order to be able to view much of anything.
They also do not give a shit about obvious 'juicing' (i.e. when it is obvious that upper management and/or HR is adding reviews where the 'con' reads like one of those softball warning phrases in a job description.)
encom
5 hours ago
This is the fate of every online review site. Every single one. Including IMDB as I realised yesterday while trying to find something to watch.
The most egregious example I've found was that the Danish postal service had something like a 4,8/5,0 rating on Trustpilot. You'll be hard pressed to find a more inept, corrupt and universally hated company. So in an attempt to improve their public image, they decided to game the ratings, instead of actually delivering mail properly.
happosai
6 hours ago
With the AI(?) bots doing a DDOS on on public websites via residential proxies the future is all website will require login.
nine_k
3 hours ago
In the specific case of Glassdoor, leaving a review about an organization sometime requires a proof that you work there, e.g. receiving a pass code sent to a work email. I'd say that this is reasonable, and makes gaming the reviews much harder.
waltbosz
4 hours ago
Can't the bots just sign up for accounts?
happosai
3 hours ago
Yes they can. But then you see which account as took part of the DDOS scraping, and delete all accounts that match the pattern and site gets back under control.
Fundamentally it's all a game of whack-a-mole for admins unless some kind of microtransaction system is invented. Then a DDOS scraping event is just extra revenue.
chanux
6 hours ago
I can kind if understand how forcing everyone to add on to the pile of content, from a business point of view.
However they may have proved that they are indeed.. trash. Maybe even a few times.
One such case was https://www.forrester.com/blogs/glassdoors-mishandling-of-cu...
In my eyes they are in the same class of Facebook, uservoice, Pinterest, Quora etc.
wiether
3 hours ago
Ironic, given their name.
e40
an hour ago
All but one of the reviews for my company are completely fake (at Glassdoor).
latchkey
5 hours ago
it goes into an infinite redirect loop for me. lol.
ok_dad
4 hours ago
Excellent now I have to find something else again. You can’t fucking trust anyone not to chase money these days.
Fuck bitwardens creators for selling out. I want them to know they fucking suck.
microflash
5 hours ago
This post is what triggered me to cancel my subscription and migrate away from Bitwarden in July. I’ve seen too many repeats of this show. This has completely soured me from cloud-backed critical software. Slowly moving toward offline alternatives wherever possible and self-hosting when it isn’t.
axelthegerman
5 hours ago
Thank you for linking this, the price increase was indeed communicated to me directly via email but not very clearly
> The price is updating to $1.65/month, billed annually.
Followed by a 25% discount for this reveal only.
Have to go back to my old invoice to see it was $10/y and now the new one $19.80/y
I never liked that I needed to pay premium just for 2FA but this abuse of trust is definitely the end of it.
Too bad I won't get a refund for my Oct 1st renewal but I'll happily cancel as soon as I get vaultwarden hosted.
snailmailman
3 hours ago
One benefit of the current self-hosted option via vaultwarden is that you get 2FA and the other premium features by default.
But it is worrying that they might intentionally break vaultwarden in the future.
theturtletalks
5 hours ago
SSO is the feature many companies put behind their most expensive plans. It's exactly why the personal software revolution will take over SaaS.
The argument here is always why would people spend all this time and money to build custom software when they can just pay a company $20-100 bucks a month? Because that product will become enshittified. It's not a question of if, its a question of when. I thought open-source SaaS would be immune, but clearly not.
TeMPOraL
5 hours ago
SaaS is what killed open source. "OSS SaaS" is just the resurrected undead abominations that somehow manage to trick the peasants and pass off as living.
If you excuse a Warcraft-y metaphor.
Aardwolf
7 hours ago
Ok this is doing some damage. What's a possible alternative that works on both mobile and desktop, doesn't require yourself to run a server, and doesn't have worse reputation?
terminalbraid
6 hours ago
keepassxc works across any major platform, mobile platforms have keepass2android and KeePassium. You don't have to run your own server, but you do need some type of file sharing system to keep them synced. I personally run a webdav share on a vps with some sync scripts to keep a backup on devices otherwise. OneDrive, google drive, dropbox, and others work.
Also protonpass.
Arrowmaster
6 hours ago
I specifically moved away from KeePassXC to Bitwarden with self hosted vaultwarden because the Linux desktop experience and mobile syncing was so terrible. While I love KeePassXC, using it on an immutable Linux distro where everything needs to be Flatpak means the browser extension doesn't work because it doesn't support Flatpak'd browsers back when I switched. Auto type is a security nightmare and is not an option. Syncing does not exist and with the constant death and forking of Syncthing on Android, it became unusable to randomly find out my db hasn't synced for a week and now I have to reset everything with a new fork yet again.
Bitwarden was the no nonsense choice because it just worked.
philsnow
5 hours ago
I used to use gnupass and its variants (including passforios on mobile), but what brought me to bitwarden was being able to make changes on two clients and merge the results cleanly / usefully without needing to do anything manually at all.
How does this work with keepassxc? Does it depend on your file syncing primitive?
Arrowmaster
5 hours ago
When I stopped using KeePassXC, there was no merging. You configured each client to save immediately and reload when detecting the file changed. If you used a tool like Syncthing then you had to monitor for conflicts (which stopped syncing) and manually fix them. If the major clients on Linux, Android, and browser extensions all supported proper syncing on their own, I might switch back.
GordonS
6 hours ago
Any good reason to use keepassxc rather than regular KeePass?
tkuraku
6 hours ago
qwerpy
5 hours ago
At the time I decided to go with regular keepass, it was because setting up OneDrive sync (directly to OneDrive, not depending on a mapped folder because I use as little MS software as possible) and browser extension was easier. And the cross platform UI on KeePassXC just didn’t look and feel good on windows.
Lapel2742
6 hours ago
Proton Pass?
I already have "Proton Unlimited" as a subscription but until now I never used Proton Pass. I thought about giving up on Bitwarden for some time and probably will try it now. AFAIK you can even import your Bitwarden logins.
mpern
6 hours ago
FWIW I moved to Proton Pass after I read the blog post months ago. The switch was seamless except for passkeys (had to enroll new ones; back then I only found a tool to convert Proton Pass passkeys to Bitwarden, but not the other way around)
For me, Pass works much better, especially passkeys on Android. Bitwarden was very flaky in that regard, Proton Pass "just works".
I use Pass for personal logins and sharing family-related accounts with my wife.
rpozarickij
5 hours ago
I'm really happy that Proton Pass provides an option to copy the username/password when you right click on an item. In the Bitwarden macOS app you have to click a dedicated copying button which feels so unintuitive and I had to consciously think about this every time I needed to copy a username/password. And Bitwarden has so many other things that could be improved in its UI, but due to muscle memory I forgot that there exist other password managers out there. So far Proton Pass seems to be much more polished than Bitwarden. Except it took me a while to find how to enable 2FA, which is in "Account and password" (not "Security and privacy") in the account settings.
attendant3446
4 hours ago
Proton Pass has a good backend, but their clients are so-so. Specifically, the auto-fill feature in both browser extension and Android client. The browser extension is also pretty buggy, keeps forgetting settings, and occasionally logs me out.
InsideOutSanta
6 hours ago
I think Proton Pass is currently the best non-self-hosted option, and Proton's corporate structure offers some protection against enshittification.
whynotmaybe
5 hours ago
Keepass on pc, keepass2android on mobile and the file is stored on onedrive. I'm starting to use macos so I'll install onedrive on it. Now onedrive's reputation is Microsoft's but I haven't heard of massive security breaches like many online password manager had.
frevib
5 hours ago
Proton pass.
Proton ticks all good-company boxes. E2ee, majority owned by the Proton foundation, all client-side code is OSS, and some other structures in place to protect themselves from corp greed. Best I could find.
sylos
5 hours ago
Didn't it recently come out that the ceo of proton was donating to far right groups interested in dismantling privacy and security, let alone their racist policies?
fph
4 hours ago
You might be mixing them up with Mullvad.
AlexandrB
5 hours ago
Can you be more specific? A lot of things called "far right" in 2026 are Democrat policies from 2016.
Bloating
3 hours ago
In so far as google translate and my adhd filter can tell, he donated to political party that support marxism … maybe people are figuring-out that authoritarian happens on both sides to the 1 dimensional political spectrum
TeMPOraL
5 hours ago
Writing password down on paper and keeping them in your wallet.
Seriously. About as secure, if you're honest about the actual threat model (vs one security aficionados would like you to assume), and paper can't be enshittified.
Diti
an hour ago
Bruce Schneier [1] thinks it’s a good idea [2] too.
[1]: https://en.wikipedia.org/wiki/Bruce_Schneier
[2]: https://www.schneier.com/blog/archives/2005/06/write_down_yo...
dexterdog
4 hours ago
Don't forget to start each password with an x but don't write that on the paper.
orta
6 hours ago
I like Enpass
hannasanarion
4 hours ago
Is there any writing on it that was written by a human? This blog post is clearly AI.
It's somewhat concerning to me that none of the security conscious people in this thread seem to notice that they are changing their privacy practices based on the advice of a language model pretending to be a person.
Cort3z
6 hours ago
I hate this. So much software I love keeps doing this. redis, docker, now bitwarden. I was so happy with bitwarden. Been a premium subscriber for many years. I have helped convert many people, including whole companies, to use this. Now they are doing us such a disservice. We need a completely free, no-nonsence, alternative. I wonder if it is possible to do a ipfs/torrent version without a central authority to permanently prevent this type of issue.
parineum
5 hours ago
I still use docker and redis for free and it seems like I'll be able to continue using bitwarden for free. I don't see what I've lost.
lisp2240
2 hours ago
What we really need is an alternative to capitalism
halfcat
an hour ago
There are many alternatives.
zackmorris
5 hours ago
I wonder that too, perhaps by encrypting the data with a key generated from a long passphrase meaningful to the user, that nobody could possibly guess. Then just store the data in a permanent cloud like IPFS, pinned with 4EVERLAND, Filebase and/or Pinata:
https://docs.ipfs.tech/concepts/persistence/#pinning-service...
Maybe someone could write a provably private client-based browser decryption script, hosted on various websites. We might need a new browser spec that sandboxes pages until they're unsandboxed, allowing them no egress/ingress or even local storage or cookies.
Or better yet, take that choice away from browser vendors, and create a runtime in the browser that simply can't be observed, perhaps by using zero-knowledge proofs.
Writing this out, I wonder if the issue is due to longstanding incomplete browser architecture, going back to when the web went mainstream in the mid-1990s. Or maybe it's still just an open problem.
Solve private distributed durable storage, along with a base level of secret computation eventually running about the speed of a 6502, 286 or 68000, and we wouldn't need free services that inevitably get privatized and ensh!ttified.
I have no idea if something like this already exists, I'm just speculating as to what base functionality it might need from first principles.
Also I wonder if similar techniques could be recruited to build an OS around cryptocurrency. That way a meta economy could run alongside the corrupt economy, and shield users from currency devaluation and other wealth inequality drivers used by the ultra-wealthy to increase the value of the means of production that they own relatively, so that they can buy more.
Arguably the process of wealth concentration is so fundamental that it puts a countdown on capitalism, driving it towards the late-stage capitalism that we've had since about 1970 when productivity diverged from wages, and eventually revolution which results in socialism/communism or even permanent authoritarian dystopia like on Star Wars. In a way, it's in the best interests of the ultra-wealthy to build meta economies, which of course makes those economies suspect and probably vulnerable to exploits, especially in the AI age. We've seen how crypto has created black markets capable of capturing governments, so maybe we should be careful what we wish for.
But really I just don't want to type my password anymore.
haruka_ff
2 hours ago
Nit: IPFS is never a "permanent cloud", even with pinning services - you stop paying, eventually the data will be gone as no one will serve it anymore. You might be looking for Arweave for better permanence, which 4EVERLAND also supports as a storage target (although there is no way to "update" the data as well)
atomicUpdate
5 hours ago
Why stop at a free password manager? Why not free food, clothes, cars, and everything else while you’re making demands?
Or is it just software that has zero value to you because it’s intangible and you intentionally ignore the time and effort other people spend on it?
vuldin
4 hours ago
I think most people don't mind paying for software, they just mind situations like having to rent software forever (subscriptions), or software companies being ran by people who are only focused on increasing revenue at the expense of actual making good/better software.
lokar
an hour ago
I think subscriptions are fair if you want updates, which for anything security related you do. The alternative (from decades ago) is to re-buy it every few years.
Someone has to pay for ongoing maintenance.
nightski
a minute ago
This isn't about cost. If these projects, like bitwarden were run at cost or even a small profit the cost would be negligible. Instead you see software companies with like 80% margins (or even higher). Not to mention that if the price was reduced to near cost then you'd get more users which would even further decrease the cost.
TitaRusell
3 hours ago
Firefox comes with a password manager built in. Gratis.
Cort3z
4 hours ago
Did you even read what I wrote?
alt227
6 hours ago
I feel like this blog post deserves its own submission to HN
rsyring
6 hours ago
Four months ago: https://news.ycombinator.com/item?id=48163389
alt227
6 hours ago
Thank you
dizhn
7 hours ago
Started humany but degraded into LLM speak towards the end. Especial the Vaultwarden section.
stavros
6 hours ago
It's all LLMese, start to finish. I found it hard to get through. Could have just been a bulleted list and it would have been better.
formerly_proven
5 hours ago
Over 1k words for something which fits in two paragraphs. Painful.
alt227
6 hours ago
So? It was useful information, who cares how it was written.
subscribed
3 hours ago
The information is there, and could fit one paragraph.
Everything else is just a nonsense, watermark and fluff, scamming from time and attention - there's NO value in the filler.
To reiterate: there's no value in this sort of the LLM garbage. There's value in the information, especially when formatted and provided in the humane format.
tuwtuwtuwtuw
5 hours ago
I bet most people that reads blogs care about how they are written.
alt227
3 hours ago
If people dont like how something is written they can move on, they are not being forced to read it.
tuwtuwtuwtuw
3 hours ago
Of course. Or, as we see here, they can critize the content that they thought was badly written. That's also allowed.
Wowfunhappy
7 hours ago
Unfortunately, any "insight" it might contain is ruined by the fact it's clearly written by an LLM instead of a person.
> And it never comes in a single dramatic announcement. It comes in layers. A feature post with a price change inside it. A LinkedIn update nobody made a press release about. A values page that says something slightly different than it did last week. If you’re still on Bitwarden cloud and this is giving you pause — it should. [...] Whether self-hosting stays viable long-term is the real question worth sitting with.