If you rely on Bitwarden, they've changed leadership and are now on the PE extract-and-exit track. Start working on your backup/exit strategy as soon as you reasonably can.

https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden

The Quiet Renovation at Bitwarden - ByteHaven - Where I ramble about bytes

Back in March, I wrote about Bitwarden doubling their Premium price — and specifically how they did it. Buried in a feature announcement. Priced in fake...

@mhoye What is the best non-self-hosted option? 1Password?
@espadrine @mhoye I was about to ask this. Or at least a reasonable solution that is reasonably unlikely to go pear-shaped.

@espadrine @mhoye depends how you feel.

If you're happy to take a risk that the bitwarden client apps may enshittify too but somebody may fork them and keep them real, then vaultwarden is a great option.

Otherwise I have no current recommendations.

@paul @espadrine @mhoye
VaultWarden is only available self-hosted, to my understanding.
@chronohart @espadrine @mhoye yes it is. Sorry, I mis-read the question!
@espadrine @mhoye 1Password is all in on slop, unfortunately.

@theorangetheme @espadrine @mhoye

great, so Proton has a MAGA CEO, Bitwarden has PE, and 1Password is slop

guess I just need to keep working down the list

https://www.privacyguides.org/en/passwords/

The Best Password Managers to Protect Your Privacy and Security - Privacy Guides

Password managers allow you to securely store and manage passwords and other credentials.

Privacy Guides

@jokeyrhyme I don’t know anything about the author of this article (and you presumably don’t know anything about me either) so take that into consideration and be skeptical if you deem it appropriate, but there’s apparently good evidence that Proton’s CEO is _not_ MAGA. Phew.

https://medium.com/@ovenplayer/does-proton-really-support-trump-a-deeper-analysis-and-surprising-findings-aed4fee4305e

Does Proton really support Trump? A deeper analysis (and surprising findings)

Recently, allegations surfaced on Reddit that Proton (or at least Proton’s CEO) supports Trump. Hillary Keverenge from Tech-Issues Today…

Medium

@leigh well, the broader picture is definitely better

but it was the "today the tables have completely turned" comment made there that concerned me, as that seemed like unnecessary flattery / sycophancy and not an especially accurate assessment

i mean, both parties are firmly USA imperialist and capitalist, so there's a limit to how much better one party can be over the other party in most aspects

and sure, we did see some antitrust moves against Google and Facebook, but these seemed more about finding some way to punish them for alleged censorship of conservative views online, and instead of breaking up monopolies we ended up with drastically reduced moderation of hate speech

but i retract my "Proton CEO is MAGA" assertion, the bigger picture doesn't demonstrate a commitment to that dogma, this does seem more like a poorly-worded or insufficiently-detailed "hooray for seeming to be less stupid than usual" post 🤷

@jokeyrhyme I *strongly* agree with you on these points! :)

@espadrine @mhoye "Start a collective" is annoying advice. But here it makes a lot more sense than usual. Find 10 people, one of whom is willing to learn yunohost in exchange for beer. Costs maybe EUR5 per month on Hetzner. For almost all services this would be be a terrible solution. But Vaultwarden is unique...

Uptime: it doesn't matter. All your clients cache your entire vault. You can add new passwords. No Internet required. The server only matters for synchronisation, which happens in the background when the server comes back up. It would be unusual if a multi-day outage affected you at all.

Security: your vault is end-to-end encrypted. The admin can't access anything in your vault, and neither can the hackers who blow the server wide open. Unlike Lastpass, in Vaultwarden this is actually true.

Enshittification: your sysadmin is Judas? Export your vault, import it into a different instance. And while you're setting that up, your client caches still work. You're scared of Bitwarden because they have the resources to re-engineer the whole platform while stringing you along. Your small-time Judas does not.

I'm happy to give you an account on my server. But that's maybe taking trust to extremes...

@mhoye Let's wait and see whether/how it could affect
https://github.com/dani-garcia/vaultwarden
GitHub - dani-garcia/vaultwarden: Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs

Unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs - dani-garcia/vaultwarden

GitHub
@mhoye I would like to change password managers less often please.

@tkalvas @mhoye

Bitwarden: about to be gobbled by private equity
KeepassXC: went all-in for AI sludge recently
1Password: see “KeepassXC”
LastPass: surely you jest

“Piece of paper in a locked box” is looking like a better option by the day.

(I have enough AppleThings that Apple’s password service is semi-workable for the time being, but that doesn’t help me much at work, or people who don’t want to deal with AppleThings.)

@dpnash @mhoye There was a non-AI KeepassXC fork pretty much immediately, but this is the full extent of my knowledge of it.

@tkalvas @mhoye

Update: I went ahead and imported all the Bitwarden logins to Apple Password. I’m not wild about this, since I don’t really want to add another fairly deeply-rooted plant to Apple’s walled garden, but at least the two fates seen above (“gobbled by private equity” and “heavily contaminated by AI dreck”) seem less likely there. I’m keeping the Bitwarden account for a while at least, until I can see if something better comes along, but I’m not holding my breath.

@mhoye The alternatives are slim to none. I'm wondering how independent Vaultwarden is, I really have no idea what else is a good option.
@mhoye this news got me worried about the client (as a server replacement exists Vaultwarden). Luckily it is Open Source, any forks alive yet?
(I have enough load as FreeBSD ports maintainer and have zero experience with app building)
@mhoye UGH. We really need a nonprofit community-led password manager. Unfortunately that's a lot of hard work at a time when lots of programmers are struggling to get/stay employed, so it's not looking good
@mhoye I bailed when, a year or two ago, a problem with THEIR servers prevented me from accessing my local passwords.
@mhoye My plan since forever has been to, well, never have anything important. It's worked so far. However; if you are in the situation where you do need things secured on your computer, there are legitimate FLOSS options out there.
@mhoye ah crap another thing I gotta self host? oh well seems to be the way of the world these days