7 ms·
+1 for Bitwarden. It is literally the best solution out there. Been getting to increase uptake in personal circles with (very) limited success. The wife keeps t
by eyeundersand 10mo ago
+1 for Bitwarden. It is literally the best solution out there. Been getting to increase uptake in personal circles with (very) limited success. The wife keeps trying to convince me that the ship has sailed in trying to protect info online. She's probably right.
- stronglikedan 10mo ago> Bitwarden Best when paid for so you can do 2FA with TOTP codes!
- Yodel0914 10mo agoI’ve never paid and Bitwarden does 2FA/TOTP for me?
- chinathrow 10mo agoIs this sarcasm?
- troyvit 10mo agoI self-host through Vaultwarden but I think I miss this. Besides, I feel like paying these guys anyway just for the great product. We use 1Password at $dayjob and it's so primitive by comparison.
- shinypants 10mo agoWhat is lacking in 1Password by comparison? I pay for a family plan but maybe I should switch next year.
- troyvit 10mo agoHere are the things that get me, and maybe it's because I haven't configured it well yet. 1. On firefox first start-up is slow after unlocking to actually find a password for a site. The interface says, "No logins for xyz.com" for maybe 5 seconds before the login loads. 2. Along those lines when I open it first thing in FF the box for its password isn't focused and I have to click it. 3. The keyboard combo to open it also only works in Chrome. 4. To add a new login I have to go to the site. I haven't figured out how to do it from within the plugin. 5. We get alerts at least once a week about service disruptions but they don't seem to actually affect me. 6. I like Bitwarden's command line tool but I bet 1Password has something at least as good that I haven't found yet.
- jnrk 10mo agoReally? I find it to be the complete opposite.
- nagisa 10mo agoTOTP works with vaultwarden.
- NetMageSCW 10mo ago1Password supports TOTP?
- sam345 10mo agoYes definitely. Works great.
- troyvit 10mo agoOh cool! I'll have to dig into it.
- sam345 10mo agoHow is 1password primitive? It does totp. It integrates with TPM in Windows hello. It does sh keys and has its own agent which is a huge help. It's sync is nearly instantaneous. It handles multiple accounts with ease.
- smsm42 10mo agoIt costs $10/year, so there's really no reason to not pay for it.
- antiframe 10mo agoI have two reasons not to pay for it: 1) Aegis is free. 2) I rather not have my second factor be stored in the same database as my first factor.
- Koffiepoeder 10mo agoThe moment you put TOTP in Bitwarden it is no longer a 'second factor'. Pretty bad security advice to be honest. Better to use hardware tokens or a secure phone (with enclave) instead (never SMS though).
- Aeolun 10mo agoI think it’s mostly nice for places that require TOTP but don’t actually rate carrying around/plugging in a yubikey for.
- deleted 10mo ago[deleted]
- Marsymars 10mo agoIn most cases a true second factor isn't really what any involved party cares about. My bank (I mean, they use SMS, but pretend they use TOTP) just care about not having to spend money on support because I used "password1!" as my password for every account and lose all my money. I just want to log in to my bank. If I've got a long, random, unique, securely-stored password, I don't actually care about having a second factor, I'm just enabling TOTP so that I don't have to copy/paste codes from my email or phone.
- ratherbefuddled 10mo ago> If I've got a long, random, unique, securely-stored password, I don't actually care about having a second factor I'm not comfortable with my entire online identity being protected by a single line of defence which is a company that I'm paying a few dollars a month to. Not having to type 6 digits off a phone is a pretty minor convenience for me.
- Marsymars 10mo agoDo you then avoid syncing any passwords to your phone to avoid having your two factors in the same place? (And similarly, avoid syncing SMS to any devices where you do have passwords.)
- Xerox9213 10mo agoI convinced my wife to start using a password manager, too (Bitwarden). Now she stores all of her very guessable, short, similar passwords in a manager. Sigh.
- Aeolun 10mo agoSo happy to not have to remember whether the [firstname][lastname][number] password ended with a 4 or 5
- NewsaHackO 10mo agoI use a similar service, I always wonder what sort of risk having one point of failure has though. I know 2FA helps, but a particularly motivated person with access to you physical still may be able to get both, espically if it for an investigation of some sort.
- teekert 10mo agoI switched from Bitwarden to Proton pass (because we got Proton family) and I find to be equally good. Ineven find sharing credentials a bit easier as it does not require organizations, you can just share with individuals. Proton also has a separate 2fa totp app.
- johnisgood 10mo agoWhy do we need a separate 2FA TOTP app for anything? :| I have a feeling too many people have no idea what TOTP is, and how easy it is to implement.
- pixxel 10mo ago[dead]
- smsm42 10mo agoBitwarden supports TOTP too, even though it's not entirely obvious from the UI.
- CaptainNegative 10mo agoTOTP inside a password manager doesn't make much sense to me. What's the point of two factor auth if both factors are stored together?
- behringer 10mo agoBingo. You need to use a different totp.
- klardotsh 10mo agoI don’t know the “correct” answer, but here’s my answer as someone whose TOTP are split across a YubiKey and Bitwarden: I store TOTP in Bitwarden when the 2FA is required and I just want it to shut up. My Vault is already secured with a passphrase and a YubiKey, both of which are required in sequence, and to actually use a cred once the Vault is authenticated, requires a PIN code (assuming the Vault has been unlocked during this run of the browser, otherwise it requires a master password again). At that point, frankly, I am gaining nearly nothing from external TOTP for most services. If you have access to my Vault, and were able to fill my password from it, I am already so far beyond pwned that it’s not even worth thinking about. My primary goal is now to get the website to stop moaning at me about how badly I need to configure TOTP (and maybe won’t let me use the service until I do). If it’s truly so critical I MUST have another level of auth after my Vault, it needs to be a physical security key anyway. I was begging every site ever to let me use TOTP a decade ago, and it was still rare. Oh the irony that I now mostly want sites to stop bugging me for multiple factors again.
- hombre_fatal 10mo agoNow that I'm not only using a Macbook and iPhone, I've been looking for cross-platform solutions. For a week I've been using KeePassXC + Syncthing between four devices. Syncthing is also syncing my Obsidian vaults which has replaced Apple-only Notes.app. Bitwarden is definitely more polished, and Syncthing is definitely (much) more fiddly than using Bitwarden's and Obsidian's ($5/mo) native syncing tools. But I like the idea of having the same syncing solution across all apps on all devices. Curious if anybody can recommend this setup or if collisions will make it unbearable.
- echelon 10mo ago> Now that I'm not only using a Macbook and iPhone, I've been looking for cross-platform solutions. 1password works in all the places, it's just not open source.
- Yodel0914 10mo agoNot sure about Obsidian sync, but for Bitwarden you can self-host Vaultwarden.
- Tallain 10mo agoThis is the same setup I used for years with no issues, both KeePassXC and multiple Obsidian vaults, along with some other random files and folders. Syncthing is pretty much rock solid. Now I have the KeePassXC database stored on my NAS which is even simpler.
- Joe_Cool 10mo agoThe cool thing with KeePass is that each client is also a local backup. It's pretty neat.
- inquirerGeneral 10mo ago[dead]
- seemaze 10mo agoI originally started using Bitwarden to achieve sync across Mac, Windows, and Linux machines, along with all major browser platforms. It's been great!
- theonething 10mo agoCan anyone with experience with 1Password and Bitwarden share their opinions on each. I've been on 1Password for years and am wondering if I'm missing anything.
- whatevertrevor 10mo agoI might be that guy soon. I really don't like Bitwarden's extensions, they have clunky UX, are slow and often don't even respect my settings. Autofill is a crapshoot, especially on Android. And they have performance issues with the Firefox and Chrome(-based) extensions so it's not even platform specific.
- hexbin010 10mo agoSame experience here
- bfg_9k 10mo ago1P is closed source and have had a number of breaches in the past. Bitwarden have had none that I'm aware of, and they're FOSS. I however have been preferring ProtonPass lately (also FOSS) and really like the layout over BW.
- Huppie 10mo ago> and have had a number of breaches in the past Do you have a source for this claim of multiple past breaches? The only one I know of is the Okta breach. For me they're still firmly in the 'one of the best options out there' category because cross-platform usability is incredibly good imho. I will admit it's been quite a while since I migrated from KeyPass so maybe these other options have improved too.
- jbmoney 10mo agoThis is either ignorance or throwing shade at 1Password. Outside of their Okta thing (which didn't impact vaults as far as I'm aware, and was more Okta's fault) they never had a compromise. They are definitely an excellent provider.