sean, to bitwarden
@sean@scoat.es avatar

I guess I’ll be spending tomorrow figuring out best practices for self-hosting ’s server component (or ) on something I can safely access via @tailscale, since my 15+ year relationship with is finally catastrophically and utterly failing me.

Should I open up a Zoom as some sort of support group so we can suffer together?

Edent, to bitwarden
@Edent@mastodon.social avatar

Just checked my - I have over 1,000 passwords stored in there 😱

Should I go through and delete the ones I never use?
Or should I just ignore the obsolete ones?

jonoabroad, to bitwarden
@jonoabroad@mastodon.nz avatar

Okay folks,

I'm wondering about migrating the family from 1Password.

I'm going to have a play, are there resources people recommend?

I'm a little confused about what the self hosted OS version provides.

agnes, to fedora

I spent most of my Saturday playing with my new DIY Framework 13 @frameworkcomputer and it was super fun & amazing! 💖 So far, I:

  • Installed #Fedora 38 and discovered it uses DNF (not APT)
  • Got #VirtualBox then immediately uninstalled it in favor of QEMU/KVM
  • Migrated from 1Password to #Bitwarden
  • Got Slack then immediately uninstalled it since it conflicted with Bitwarden installation

Plus I went down a few rabbit holes here and there, because that’s how you learn #Linux! 😂

image/jpeg
image/jpeg

rfc1149, to bitwarden

For now five days, developers refuse to realize that the problems with their extension is solely due to the transfer from GitHub to addons.mozilla.org. The latest version of the extension on addons.mozilla.org is half the size of the previous ones and of the GitHub version (they should be identical!): https://github.com/bitwarden/clients/issues/6286

koehntopp, to passkeys

OK, so...

only lets me create a on the desktop, not on mobile

only lets me add a new passkey on mobile, not on desktop.

Even after logging in with passkey, PayPal requests a TOTP token additionally.

When i try to send a paymen, PayPal needs to "confirm my identity". ("WhatsApp" - WTF???)

I have rarely seen a bigger mess and security theatre. PayPal, do better. You should be one of the leaders of secure enduser friendly authentication.

iamkale, to random

It looks like BitWarden is following suit with 1Password and returning "uv:true" in WebAuthn authentication requests even though the user isn't prompted for anything more than to confirm the use of a passkey. The unlocking of the vault is considered the user-verifying event...

As an end user I appreciate the streamlined experience. But as an RP I'm disappointed - what if vault unlock occurred 5/10/30 minutes prior? Someone could cruise by someone's desk when the vault is unlocked and auth as the vault owner and the RP would be none the wiser 😢

It's a tough middle point that passkey providers have to try and find 🥴

onthefencedev, to bitwarden
@onthefencedev@twit.social avatar

As a developer the biggest irritation I have with is that it doesn't take ports into account when displaying suggested logins; so logins saved for localhost:1234 will also be displayed for localhost:9876.

I mentioned it on the birdsite a while ago and they responded saying such a feature would be useful but it never materialised.

Thinking about moving to but initial testing shows the same limitation - unless there is a setting somewhere.

Seems like an obvious use case.

ilyess, to security
@ilyess@mastodon.online avatar

If you're using #bitwarden, make sure to change the KDF algorithm to Argon2id^1 which is much more robust against GPU-powered attacks compared to its counterpart.

You can play around with this little calculator to see the impact of each algorithm on cracking cost estimation: https://passwordbits.com/passphrase-cracking-calculator/

#security #infosec #password

epixoip, to random

Happy !

I've cracked billions of from tens of thousands of in the past 12+ years, and because of this, I likely know at least one for 90% of people on the Internet. And I'm not alone! While I primarily crack breached passwords for research purposes and the thrill of the sport, others are selling your breached passwords to criminals who leverage them in and attacks.

How can you keep your accounts safe?

  • Use a ! I recommend @bitwarden and @1password

  • Use a style - four or more words selected at random - for passwords you have to commit to memory, like your master password!

  • Enable MFA for important online accounts, including cloud-based password managers!

  • Harden your master password by tweaking your password manager's KDF settings! For , use Argon2id with 64MB memory, 3 iterations, 4 parallelism. For and other PBKDF2 based password managers, set the iteration count to at least 600,000.

  • Use unique, randomly generated passwords for all your accounts! Use your password manager to generate random 14-16 character passwords for everything. Modern password cracking is heavily optimized for human-generated passwords, because humans are highly predictable. Randomness defeats this and forces attackers to resort to incremental brute force! There's no trick you can do to make a secure, uncrackable password on your own - your meat glob will only betray you.

  • Use an ad blocker like Origin to keep you safe from password-stealing and other browser based threats!

  • Don't fall for attacks and other social engineering attacks! Browser-based password managers help defend against phishing attacks because they'll never autofill your passwords on fake login pages. Think before you click, and never give your passwords to anyone, not even if they offer you chocolate or weed.

  • : require ad blockers, invest in an enterprise password management solution, audit password manager logs to ensure employes aren't sharing passwords outside the org, implement a Fine Grained Password Policy that requires a minimum of 20 characters to encourage the use of long passphrases, implement a password filter to block commonly used password patterns and compromised passwords, disable authentication and disable RC4 for , disable legacy broadcast protocols like LLMNR and NBT-NS, require mandatory signing, use Group Managed Service Accounts instead of shared passwords, monitor public data breaches for employee credentials, and crack your own passwords to audit the effectiveness of your password policy and user training!

Codixer, to Dragonlance
@Codixer@enshittification.social avatar

I just had to steal this from , it's about all your stuff. Instead of being relient on the constant threath of loosing your account. Or what about losing your centrally accessed account because thinks you are not worty of his platform?

This is the exact reason why I started to more stuff like a / vault, my own instance and for fun, a instance. Planning to setup later probably.

c0dec0dec0de, to bitwarden
@c0dec0dec0de@hachyderm.io avatar

Bitwarden’s been throwing warnings on my phone telling me to scale back my hashing parameters because they might fail on this device.
Of course, now that I post about it, it’s not doing it so I can’t screenshot it…

tecnotestering, to bitwarden Spanish
mjgardner, to bitwarden
@mjgardner@social.sdf.org avatar

I am so glad I moved from #Authy to #Bitwarden a year or so ago, precisely because of declining #desktop support. Now the decline has an death date: August 2024. https://www.bleepingcomputer.com/news/security/twilio-will-ditch-its-authy-desktop-2fa-app-in-august-goes-mobile-only/

#2FA #InfoSec #CyberSecurity #security

amadeus, (edited ) to linux
@amadeus@mstdn.social avatar

Has anyone got running on their distribution? The application opens for me, but none of the buttons are clickable. I tried to make sense of the Getting Started section in the wiki and used the commands outlined alongside flatpak run to no avail.
https://github.com/quexten/goldwarden
Would be nice not to have to stare at ('s) smeary scaled UI and instead use a nice app like Goldwarden. 🤓️

Mehrad, to archlinux
@Mehrad@fosstodon.org avatar

Has anyone any idea why
the nodejs-lts-gallium was replaced with nodejs-lts-hydrogen for the bitwarden-cli package in extra repo package:

https://gitlab.archlinux.org/archlinux/packaging/packages/bitwarden-cli/-/commit/e33b3e709183cda239fb3756d8039b86fa326c8f

I'm having dependency conflict on one machine and I wonder:

  1. why pacman cannot handle it as gallium os only needed for bitwarden-cli
  2. why do they conflict even when the package names are different

merryfaith, to bitwarden

So I learned the hard way to maybe not randomly generate passwords I don't have memorized at all via services like @bitwarden when I need said password to utilize an app to clock into work, because when there's an issue with the password service missing your encryption key that "impacts a small number of users" and turns out I'm one of the lucky few, it definitely makes things difficult.

Still love and since I began using it in 2017, have never had to check out github bug reports or community boards or the subreddit to see if others are experiencing similar issues (though to be fair, I haven't found anyone talking about the same error I am getting on any of those sites, and I googled a LOT while troubleshooting).

adingbatponder, to bitwarden
@adingbatponder@fosstodon.org avatar

Do I do the workaround to be able to install in by permitting the insecure package which is listed in the error message as EOL
{
nixpkgs.config.permittedInsecurePackages = [
"electron-24.8.6"
];
}
or is there a better solution (other than bitwarden-cli).

Tinotin, to Vivaldi

I have a mystery when it comes to synchronizing with my user. For some reason the backup creation password has not worked for me, whereby the data is encrypted.
But I had backed up the key in a text file. And as a security measure copy that content into notes....

hl0dwig, to bitwarden
@hl0dwig@g33ks.coffee avatar

my annual plan is ending on the next month... time to switch for :opensource: solution & celebrate their new EU servers 👌

https://bitwarden.com/resources/move-to-bitwarden-from-other-password-manager/

masek, to bitwarden German

My setup:

  • Primary storage ist via with a local installation (both needs to be version 23.10 at least)
  • Secondary storage is a 5 NFC which I carry with me. This one alllows me to use the passkey on my iPhone (iPad not tested yet)
  • Tertiary storage is another (cheaper) Yubikey which is deposited in a safe at home

Both Yubikeys are protected by a PIN which my wife knows. That way I canot lose access to my account and have taken precautions in case I become incapacitated.

But this setup requires quite some time for each web site to switch to passkeys. That's why I am so angry with companies like Paypal who make it practically unusable.

chm, to bitwarden German
@chm@swiss.social avatar

So, nun knapp 600 Passwörter und sichere Notizen von nach gezügelt.
Ging schneller als schnell.
Besonders schön: auch alle wurden problemlos übernommen.
Einziges Manko: Anhänge kann ProtonPass bisher noch nicht.

thomy2000, to firefox
@thomy2000@fosstodon.org avatar

Just finished helping my grandfather solve some of his issues with . He didn't know how to create lists of contacts. I quickly set this up and closed maybe 1000 tabs (I don't know how he opened that many). I was also surprised to see he still uses , although all his extensions were gone. Reinstalled , and . Now he's fully open sourced again. He even mentioned that he thought about sponsoring Thunderbird.

fabio, to bitwarden
@fabio@manganiello.social avatar

Just migrated from to .

Same API, same features, same UI, and support for other DBs than MSSQL.

One single stand-alone application vs. Bitwarden’s 10 Docker containers. 70MB of RAM vs. 2GB. 3MB of db storage vs. 300MB.

Why was a password manager supposed to take so many resources in the first place? Just because it runs on a Microsoft-only stack and on .NET’s inefficient VM? Just because somebody thought that it was a good idea to separate everything into different containers (even icons and 2fa are modeled as separate services in Bitwarden)?

It reminds me of my recent migration from Mastodon to Akkoma. I got more features, 5GB of RAM freed up and 300GB of storage freed up almost overnight.

Writing and running inefficient software that pointlessly consumes all the resources available on a machine should be a crime in a world with limited resources.

It makes me think of how much shitty bloated software like @bitwarden, probably based on awfully inefficient languages and frameworks like Java, Ruby on Rails and .NET, is running out there, pointlessly sucking up resources for doing simple jobs that could easily be done with 99% less resources.

Today’s developers, spoiled by IDEs, powerful machines, docker-compose and shortsighted “just throw more RAM at the problem” approaches, have forgotten how to write efficient software. Time for them to learn how to write good efficient software again. Software doesn’t eat the world. Only shitty software built on shitty framework does.

governa, to bitwarden
@governa@fosstodon.org avatar

vs. Pass: What's The Best Password Manager? :bitwarden: :protonmail:

https://itsfoss.com/bitwarden-vs-proton-pass/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • everett
  • ethstaker
  • thenastyranch
  • magazineikmin
  • modclub
  • rosin
  • khanakhh
  • osvaldo12
  • Youngstown
  • slotface
  • Durango
  • kavyap
  • DreamBathrooms
  • megavids
  • ngwrru68w68
  • tacticalgear
  • InstantRegret
  • Leos
  • cubers
  • mdbf
  • normalnudes
  • tester
  • GTA5RPClips
  • anitta
  • cisconetworking
  • provamag3
  • lostlight
  • All magazines