RE: https://infosec.exchange/@masek/116579264376811608

I suggest being careful and vigilant in regards to what might be happening to #Bitwarden under it's new management. It could be slowly marching towards #enshittification.

At this point in time, I would probably recommend #Proton Pass over Bitwarden for new users.

#foss #bigtech #digitalsovereignty

@zevsu Ah fucking Christ on a crutch...Only if I can't find a better option, I might go back to Proton Pass...If need be. As thankfully, its easy to transfer out of Bitwarden...

I'm going to be paying attention very carefully to what is happening now. As those corpo suits can't help but ruin cool projects with their filthy hands and ideals. 🫠

@WanderingInDigitalWorlds @zevsu If it goes South, the "easy to transfer" part will likely become not as easy pretty fast...
@gagagoogle
Well if you're using one of the local (open-source) client apps over the web version I'd really hope they can't remotely block you from using the vault export feature if they wanted to, since the local client on Android for example seems to store a copy of them offline(?)
But maybe they could remotely log you out of your account, I'm unsure, but I wouldn't fearmonger too much yet.

@gagagoogle @zevsu I'd hold off on the fearmongering as the situation hasn't even degraded fully yet. There are signs as the crows caw and the tea leaves have landed in a way that tells of an old white man being an absolute weapon in a corporate setting. There is still time for him not to fuck this up...

Edited bit: I wasn't sure if he was directly to blame for the LastPass incident, I meant to imply that something similar could happen, my mistake. My goose on the loose energy is high today!

I will give it a month, before making my decision, as I won't let the situation get too bad before bailing if necessary...

@WanderingInDigitalWorlds
Also worth keeping in mind that self-hosted/local solutions like KeePass(XC) exist if you prefer having the most control over your passwords and are able to keep backups of them safely
https://essentials.techlore.tech/#password-managers
SPA Essentials

Your non-negotiable toolkit for security, privacy, and anonymity — every recommendation vetted and trusted by Techlore.

Techlore

@zevsu I'm not ready for that self-hosted side quest...Too much is happening. I don't have a third machine that could host all my stuff and things. Once my upgrade happens sometime when the prices drop; that is when I can jump into the abyss of self-hosted and come out of it with a fully gray beard and an aversion for sunlight.

I did look at NordPass, 1Password, and perhaps ProtonPass if needs must as the Devil of Capitalism Drives. I can see Bitwarden collapsing like LastPass did because CEOs don't learn from their mistakes (it's better to never hire them again when they fumble the bag that hard).

@WanderingInDigitalWorlds
I understand, just wanted to mention it.

I believe that #ProtonPass is definitely the best alternative to Bitwarden, other atlernatives like 1Password are proprietary and thus worse.

@zevsu They might be proprietary, but, sometimes I am not too picky for a temporary port of call until I can find a better open source alternative. I don't feel proprietary is 100% the enemy all the time, but it damn well can be weaponized if the corporate or private culture shifts.

Which is why I tend to prefer open source more than proprietary...Ugh, I just wish that the tech scene could chill the fuck out for at least a year before making disastrous choices. Like hiring CEOs that failed users in huge public facing ways. Man, tricking sand into doing complex math for us was a fucking mistake.

Or jumping on the cursed gassed up LLM bandwagon and fail so hard...It's like a real life satire, that hurts millions of users because the shit was never going to be ready for real world usage.

@WanderingInDigitalWorlds
Yeah, I feel you. And well, I just think that passwords are incredibly sensitive, so for that you must use something as transparent and trustworthy as possible (and imo being open-source is a bare minimum prerequisite for that).
And Proton generally has good reputation in the privacy and transparency space as well
@zevsu Yeah, open source can at least be investigated while proprietary is hidden from sight and can eventually be breached in dark places regardless of the secrecy!