Great find. This blog post - and specifically the background of the new management team - convinced me to start looking for a Bitwarden alternative. I’m watching the same “boil the frog” strategy unfold at Namecheap, and erode much of the brand trust they had built up over a decade, and it’s a shame.

> I’m watching the same “boil the frog” strategy unfold at Namecheap, and erode much of the brand trust they had built up over a decade, and it’s a shame.

What's happening with Namecheap? I've been a user for a long time and haven't noticed anything.. Maybe I'm one of the frogs being boiled!

Same question, I use CloudFlare for alot of API DNS stuff but register with name cheap because it's been a a good service provider so far.

Have you settled on a BitWarden alternative, or a short list you’re considering?

Proton Pass. I stopped using Bitwarden for a different reason, the mobile app was too slow when not connected to internet. I can't accept such slowness, the company will definitely give justifications for this. But I don't care, let me see my passwords or notes for a website immediately. Proton Pass is better in this regard.

Proton Pass cannot be self-hosted.

I am using Keepass XC + Keepass DX synchronized with Syncthing. There's really nothing to self-host, other than throwing Syncthing on a NAS so you can make sure you have at least one machine online at all times. But even that isn't critical, since both Keepass XC and Keepass DX have a "Merge" option if anything falls out of sync.

ive used keepassxc forever, switched to proton pass after the release, because i was managing my db in git and it was always a pain to keep in sync, but switched back a couple of weeks ago with exactly the same setup, syncthing and KeepassDx also works suprisingly well.

mostly i was missing power user features and especially ux for the browser plugin, namely you can't operate it fully with the keyboard, with keepassxc you can

As as self-hoster, I recommend vault warden. Supports 2fa, written in rust, works pretty well, is easy to backup, and you can use bitwarden's phone client.

I'm curious why other self hosters think it's a bad idea.

> and you can use bitwarden's phone client

What will you use when this stops working in the near future?

Presumably, it's a memory hog. What is your RAM usage?

I think the memory hog you're thinking of is the official Bitwarden self-hosted backend. Vaultwarden is pretty light on resources.

For me, vaultwarden's RSS is ~45 MB, with ~13MB of that being shared. I have it running as a secondary thing on a 512 MB machine and don't notice it's there. Is there a reason you presume it's a memory hog?

I'm surprised, actually. I expected at least an order of magnitude more. In my humble opinion, this is still a lot of memory -- probably an order of magnitude (or even two) more than what is realistically required for the task. But this is just my own philosophy, and I do realize that the days of careful memory utilization are long gone.

Thanks for sharing.

For me, RSS 35 MB, SHR 23 MB. The vaultwarden executable is 38 MB (typical Rust executable that links Rust code statically, and only dynamically links libssl.so and libc.so dynamically).

So probably its RSS usage is just mostly its own executable code?

I moved to the cloud for a simple reason: if I die tomorrow people who depend in the service are screwed. And this is an important service, like email or digital archives.

I'm confused, so you are self hosting it for other people?

Yes I was - for me and my family (and a few friends)

As a self-hoster, I don't think password managers should be self-hosted.

On the contrary. If there's one thing you should self-host is definetly password manager.

Why, you can of course self-host it, too, but the infrastructure should be entirely separate.

I don't see much reason not to self-host a properly built password manager like Vaultwarden or something similar? The clients keep a local encrypted copy of the vault, so the server only needs to be up for syncing. If it went down for a week, you probably wouldn't even notice unless you were saving new logins. And even if the server got hacked, everything on it is encrypted. Why do you think it should not be selfhosted?

you just listed all the reasons why you don't need to self host yourself

Thanks, on these topics I feel like I’m fucking crazy for not wanting to self host.

If you believe that the technology works, that encryption is happening and that the decryption is only happening on your local machine then why in the fuck would I host this myself?

You need to believe that it does not work when they do it, but does work when you do it.

I have not seen any evidence of that.

Can’t relate. If you’re worried about you’re own reliability to keep it online, just keep paper backups

What? Why not?

password managers should not involve hosting at all, use something file-local, keepass(xc) or alike

It should be something like, well, git (but likely not directly git): something that replicates easily, so that you'd have a remote copy accessed via internet ("hosted"), and local copies where you see fit.

Keepass people always in these topics with ”offline rules!! … now let me tell you how I use it with a copy on my phone and sync it with Dropbox and a backup on a git repo”

But passwordstore.org can.

No reason to use anything more complicated.

[deleted]

What’s wrong with self hosted vaultwarden ? I guess there isn’t a FLOSS extension client/app?

Presumably the bitwarden apps will stop working with them eventually

addig Vaulwarden compatibility to already FOSS mobile password managers might be the path of least resistance

or pooling together tokens and asking Claude nicely to make a mobile app

Or just fork the OSS bitwarden client?

With android changes this year how do you deploy it?

That's funny, Bitwarden and Namecheap are the two things I've migrated away from as well.

The switch to Vaultwarden was insanely easy.

Just curious, why Namecheap?

I honestly don't remember what annoyed me at first.

But auto renewals not working at times for some reason, credit cards not being saved, prices rising vs competitors.

Just switched everything to CloudFlare since I'm always pointing to it anyways and use a lot of their services.

And gandi.net.

GlassDoors reveal the other side of the story

https://www.glassdoor.com/Reviews/Bitwarden-Reviews-E4337610...

Wow, another site that now refuses to play ball unless you sign in.

Guess I'll never be visiting Glass Door again then.

GlassDoor has been gross about this for years.

Not sure if still the case but normally you have to not only 'sign in' but also feed them information (e.x. salary at a position, write a review, etc.) in order to be able to view much of anything.

They also do not give a shit about obvious 'juicing' (i.e. when it is obvious that upper management and/or HR is adding reviews where the 'con' reads like one of those softball warning phrases in a job description.)

This is the fate of every online review site. Every single one. Including IMDB as I realised yesterday while trying to find something to watch.

The most egregious example I've found was that the Danish postal service had something like a 4,8/5,0 rating on Trustpilot. You'll be hard pressed to find a more inept, corrupt and universally hated company. So in an attempt to improve their public image, they decided to game the ratings, instead of actually delivering mail properly.

With the AI(?) bots doing a DDOS on on public websites via residential proxies the future is all website will require login.

In the specific case of Glassdoor, leaving a review about an organization sometime requires a proof that you work there, e.g. receiving a pass code sent to a work email. I'd say that this is reasonable, and makes gaming the reviews much harder.

Can't the bots just sign up for accounts?

Yes they can. But then you see which account as took part of the DDOS scraping, and delete all accounts that match the pattern and site gets back under control.

Fundamentally it's all a game of whack-a-mole for admins unless some kind of microtransaction system is invented. Then a DDOS scraping event is just extra revenue.

I can kind if understand how forcing everyone to add on to the pile of content, from a business point of view.

However they may have proved that they are indeed.. trash. Maybe even a few times.

One such case was https://www.forrester.com/blogs/glassdoors-mishandling-of-cu...

In my eyes they are in the same class of Facebook, uservoice, Pinterest, Quora etc.

What’s wrong with Pinterest? (I don’t use it)

Ironic, given their name.

[flagged]

[flagged]

All but one of the reviews for my company are completely fake (at Glassdoor).

it goes into an infinite redirect loop for me. lol.