Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You may want to give a try to Bitwarden (https://bitwarden.com/)

I was a long (15years?) paying user of Lastpass, saw the company grow and discussed with the founders when they were just starting. Then the software grew old (and some M&A were dubious)

Switching to Bitwarden was a great choice (since about a year)

(I have no affiliation with Bitwarden, I just work in Information Security and look closely at this kind of software and their tradeoffs)



Thanks for mentioning it, it looks pretty nice. However, as that's something I would self-host, the pricing options do not make sense to me. I'd be willing to pay a one-time fee of $10, maybe $40 for the family variant (though 6 users feels really arbitrary when you self-host). Not $40 per year for little added value (the thing I'd be interested in is 2FA via OTP/U2F, and maybe that shared item thing).

Anyway, I think I'll look at something else for now, I can't really afford that :)


I do self host Bitwarden. There are two possibilities:

- the official docker solution which is extremely complicated

- https://github.com/dani-garcia/bitwarden_rs which is extremely simple and just works. It includes everything for 0 EUR.

I still sent money to both projects because I think they did a nice work.

I find Bitwarden better than LP in handling Android (seems to be better at recognizing places it can fill in) and it is very complete in terms of what the product itself offers. I considered moving mu OTP (currently on Authy) there, up to the moment where I realized I need OTP for Bitwarden itself :)

Otherwise I have no complaints. The sharing part is excellent (much better than LP) - the only thing to be aware of is that once you "share" with a group, the elements is not "yours" anymore. It becomes truly shared within the group. Specifically you cannot "take it back". While it was a bit disconcerting at first, I find it very logical in the long term. And use it extensively with my family.


Thank you for mentioning that alternative, that looks very interesting indeed. May I ask how you sent money to bitwarden? By subscribing?

Your comment on OTP makes a lot of sense. I personally use Aegis from F-droid from OTP (moved from AndOTP), which I quite like.


bitwarden_rs: https://github.com/sponsors/dani-garcia (you can subscribe and then resign - there is no way to make a single payment AFAIK)

bitwarden: I subscribed and then cancelled as there is no single payment either.

As for the OTP, one more point is that in the case where Bitwarden would be hacked, the fact that OTP is somewhere else is a real layer of security.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: