frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Get your passwords out of Bitwarden while you still can

https://www.osnews.com/story/145029/get-your-passwords-out-of-bitwarden-while-you-still-can/
53•speckx•1h ago

Comments

eleventen•54m ago
I think this is a little hyperbolic. The product may drop features, increase prices, and squeeze its free tier users. Everything enshittifies. But the idea that password export might disappear or be degraded? Nah. You'll be able to jump ship any time you want.
tremarley•46m ago
Never underestimate the lengths companies will go to, to enshittify their product to squeeze customers for money.
eleventen•41m ago
Name one major password manager that blocks or paywalls export.
kpozin•37m ago
- Authy

- Google Authenticator

Someone1234•33m ago
Notably not password managers.
MostlyStable•28m ago
Google Authenticator has an export-as-QR-code function that several other authenticator apps can parse. Is it the best/most convenient implementation? Obviously not, but you can absolutely export the codes.
eleventen•25m ago
Not password managers of course, but thanks for reminding me that I should figure out how to ditch Authy.

https://github.com/BrenoFariasdaSilva/Authy-iOS-MiTM is going to be my project for the afternoon.

Ringz•4m ago
Ente Auth

is a good alter. Works perfect for me.

vallassy•44m ago
>You'll be able to jump ship any time you want.

Famous last words...

AdmiralAsshat•6m ago
I mean, LastPass was a train wreck after their breach, but they didn't go as far as trying to stop me from exporting my vault when I switched to BW.

The idea of BW doing a rug pull and suddenly removing the ability to export your vault I think would trigger a class-action lawsuit.

e40•7m ago
I don't know why this is framed as "jumping ship" ... of course you can stop using it any time (and use your periodic export to go elsewhere).

The real issue is potential data loss. Remember LastPass? Bought by someone and downhill it went, with multiple security incidents.

Someone1234•54m ago
I think the caution around Bitwarden is justified; and I think it is good that the message is getting out there. I will say "while you still can" is hyperbole, and will do more to distract from the larger (correct) point about Private Equity.
avgDev•46m ago
A tale as old as time, enshitification.
PaulHoule•34m ago
Sometimes I think when a startup announces that they are being acquired their competitors have a meeting that morning and announce that they're going to start dialing for dollars. Since acquisitions almost always hurt customers I wonder if we can start creating "poison pills" that deter them.
MostlyStable•32m ago
While I'm not _happy_ about the messaging changes, those alone are not enough to do more than start paying closer attention. I highly, highly doubt that vault export would be the first meaningful feature change, and so I think there will be stronger signals of actual issues before then.

As I understand it, so far the only actual change is an announced increase in prices. Obviously, from the consumer perspective, cheaper is better, but this is a product where I think that a subscription plan makes sense (and the free tier, for now, still exists), and so I'm not going to get mad about price changes. Competitors exist and one doesn't think the new price is worth it, then switch to one of them (using the very-much-still-available vault export).

I don't think the warning is crazy or anything, but in my personal opinion it's a little stronger/earlier than is warranted and the current appropriate response is careful watching.

poisonborz•32m ago
Clients are OSS, I wonder why nobody did a Vaultwarden-style fork of them yet that would watch over upstream changes.
subhobroto•26m ago
Vaultwarden is a very lean implementation of Bitwarden but if you want to look into an alternative to the Bitwarden ecosystem, I recommend - AliasVault https://github.com/aliasvault/aliasvault - check it out!
pattilupone•29m ago
WOW. Quietly editing the 4-year-old blog post is super slimy, holy crap. Also seems like since this story was published, they edited the 4-year-old blog post again. The story points out

>But the explanatory paragraph at the bottom of the same post still says the old ones: Inclusion and Transparency. Crandell’s name is still on it. The post now contradicts itself, and nobody wrote a new one.

Looking at the post right now, they've corrected it to Innovation and Trust.

cjwoodall•29m ago
I wish companies that offer such a core technology and what not were at times entered into a public trust, similar to how some public lands are managed, that would protect them from private equity takeovers; I know it defeats the purpose of the companies in the first place (making money), and it probably would backfire in myriad worse ways than the problems it might solve... But I do think there are many options for how products, services and what not can be structured that give the people who maintain them what they need to thrive; without mining the users for money.

Overly idealistic thinking, maybe... but still thinking.

throwaway85825•16m ago
Public management exists for natural monopolies where no market competition is feasible. The role of the public entities is to protect competition. In this case that would be mandating import/export interoperability.
subhobroto•24m ago
I'm a huge fan of AliasVault https://github.com/aliasvault/aliasvault - the author is responsive, receptive. The whole ecosystem is opensource.

Bitwarden/Vaultwarden had a good run but if someone's going to self-host Vaultwarden, I would encourage people to look into AliasVault instead. It's a complete opensource ecosystem.

cjs_ac•21m ago
I store my passwords using this: https://www.passwordstore.org/

It's a shell script that stores passwords in a git repository, containing one file per entry. The files are encrypted using a GPG key. Because it's just a git repository, you can synchronise it between devices using whatever infrastructure you want. I use a FOSS client for it on iOS, and there was one for Android before I got an iPhone.

jrm4•14m ago
Third-party password management as an isolated paid service (i.e. you don't get password management unless you pay specifically for the password management) is just a terribly bad idea all around.

Waiting for people to get this.

e40•9m ago
A bad idea for you. My non-technical family members can barely use 1Password and it is the easiest of the lot. The idea you promote is just not realistic.
baal80spam•5m ago
Not really. That something is convenient doesn't mean that it's a good idea. It's always a matter of convenience vs security.
bilal4hmed•7m ago
This is getting so tiring. What are the other options out there now?
skarz•5m ago
ProtonPass

Flipper One – we need your help

https://blog.flipper.net/flipper-one-we-need-your-help/
571•sandebert•4h ago•271 comments

We're testing new ad formats in Search and expanding our Direct Offers pilot

https://blog.google/products/ads-commerce/google-marketing-live-search-ads/
415•sofumel•5h ago•341 comments

Python 3.15: features that didn't make the headlines

https://blog.changs.co.uk/python-315-features-that-didnt-make-the-headlines.html
172•rbanffy•4h ago•78 comments

Michael Keating has died

https://www.bigfinish.com/news/v/michael-keating-1947-2026
25•speckx•1h ago•10 comments

Lost Images from the 1945 Trinity Nuclear Test Restored

https://spectrum.ieee.org/trinity-nuclear-test
110•pseudolus•4h ago•27 comments

Who Wins and Who Loses in Prediction Markets? Evidence from Polymarket

https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6443103
45•vcf•2h ago•33 comments

FatGid: FreeBSD 14.x kernel local privilege escalation

https://fatgid.io/
41•WhyNotHugo•3h ago•9 comments

Indexing a year of video locally on a 2021 MacBook with Gemma4-31B (50GB swap)

https://blog.simbastack.com/indexed-a-year-of-video-locally/
29•asenna•1h ago•10 comments

An OpenAI model has disproved a central conjecture in discrete geometry

https://openai.com/index/model-disproves-discrete-geometry-conjecture/
1308•tedsanders•20h ago•950 comments

AI is just unauthorised plagiarism at a bigger scale

https://axelk.ee/ai-is-just-unauthorised-plagiarism-at-a-bigger-scale/
444•speckx•2h ago•316 comments

Google's Antigravity Bait and Switch

https://www.0xsid.com/blog/antigravity-bait-n-switch
186•ssiddharth•1h ago•102 comments

Show HN: Rmux – A programmable terminal multiplexer with a Playwright-style SDK

https://github.com/helvesec/rmux
131•shideneyu•6h ago•62 comments

Cekura (YC F24) Is Hiring

https://www.ycombinator.com/companies/cekura-ai/jobs/AiWwUxI-forward-deployed-engineer-us
1•atarus•3h ago

GitHub confirms breach of 3,800 repos via malicious VSCode extension

https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-maliciou...
969•Timofeibu•1d ago•415 comments

The Palomar Lights

https://comics.phillyharper.com/
17•tardismechanic•2d ago•6 comments

IBM invented semiconductor manufacturing automation

https://spectrum.ieee.org/semiconductor-fabrication
38•rbanffy•5h ago•1 comments

Get your passwords out of Bitwarden while you still can

https://www.osnews.com/story/145029/get-your-passwords-out-of-bitwarden-while-you-still-can/
56•speckx•1h ago•27 comments

A Bipartisan Amendment Would End Police License Plate Tracking Nationwide

https://www.wired.com/story/a-bipartisan-amendment-would-end-police-license-plate-tracking-nation...
78•cdrnsf•2h ago•10 comments

Magic the Gathering format: Fun 40 (2025)

https://fabiensanglard.net/mtg/fun//index.html
34•ibobev•2h ago•32 comments

Show HN: I Dedicated 4 Years to Mastering Offline Password Cracking

34•bojta-lepenye•2h ago•1 comments

Mounting Git commits as folders with NFS

https://jvns.ca/blog/2023/12/04/mounting-git-commits-as-folders-with-nfs/
4•pvtmert•2d ago•2 comments

What Do Gödel's Incompleteness Theorems Mean?

https://www.quantamagazine.org/what-do-godels-incompleteness-theorems-truly-mean-20260518/
59•baruchel•2d ago•21 comments

Show HN: I reverse engineered Apple's video wallpapers

https://github.com/kageroumado/phosphene
361•kageroumado•15h ago•87 comments

Flipper One Tech Specs

https://docs.flipper.net/one/general/tech-specs
476•gregsadetsky•21h ago•158 comments

The Letter S, by Donald Knuth (1980) [pdf]

https://gwern.net/doc/design/typography/1980-knuth.pdf
236•bambax•15h ago•41 comments

Haskell Foundation 2026 Update

https://discourse.haskell.org/t/haskell-foundation-2026-update/14136
156•azhenley•13h ago•54 comments

No Slop Grenade

https://noslopgrenade.com/
219•napolux•6h ago•130 comments

DOS Zone

https://dos.zone/
312•rglover•16h ago•72 comments

Shunning AI is the human choice

https://www.thehandbasket.co/p/hating-ai-is-good-actually
279•cdrnsf•2h ago•329 comments

All the bugs they found

https://andreapivetta.com/posts/all-the-bugs-they-found.html
73•ziggy42•2d ago•27 comments