Bitwarden Vs Vaultwarden: Review & Comparison

  Рет қаралды 49,167

Pro Tech Show

Pro Tech Show

Күн бұрын

Пікірлер: 64
@ProTechShow
@ProTechShow Жыл бұрын
I've uploaded a dedicated video with my thoughts on storing 2FA tokens in Bitwarden: kzbin.info/www/bejne/bGWZlZ-nmciVg80
@hugbearsx4
@hugbearsx4 2 жыл бұрын
What I appreciate the most is that you don't just give a verdict or rating, instead you go into a fair amount of meaningful detail justifying your view. Thanks a lot for your effort, it's ACTUALLY helpful!
@ProTechShow
@ProTechShow 2 жыл бұрын
Thanks! Glad to hear it's useful 🙂
@DavidLindes
@DavidLindes 7 ай бұрын
@@ProTechShow it really is. I was going to leave a top-level comment, but this pretty well sums it up. Thanks!
@ProTechShow
@ProTechShow 7 ай бұрын
@@DavidLindes thanks!
@TheLucario4ever
@TheLucario4ever 4 ай бұрын
Incredible comparison, thank you so much for being so thorough and not making it so technical that regular people won't understand it nor dumbing it down so much to the point it isn't useful. Awesome video, thank you so much
@ProTechShow
@ProTechShow 4 ай бұрын
Thanks!
@davelloyd-
@davelloyd- 2 жыл бұрын
I've been a longtime user of keepassxc with nextcloud as the sync. It works, but there's a few utility accounts that need to be shared with my better half and this is difficult - so was literally about to spin up a bitwarden to have a look at and came across you vid. Thank you for saving the time of discovering bitwarden self host doesn't have password sharing - being the raison d'etre that would have been a pain. So I'm spinning up my VaultWarden instead :)
@ProTechShow
@ProTechShow 2 жыл бұрын
That was exactly my reason for looking at it, too. KeePass + Nextcloud was my solution for a very long time as well. It works well for a single user, but beyond that it gets messy quickly.
@manfredbirkholz3832
@manfredbirkholz3832 Жыл бұрын
Well. I did set up Bitwarden (Families) selfhosted and I can share passwords with my wife. Not sure why this should not work?
@FusslDerEchte
@FusslDerEchte Жыл бұрын
also used keepass, but its slow and some login forms arent recognized within the keepassdx app, so I came to bitwarden and its so much better!
@MsTHEDARKK
@MsTHEDARKK 2 жыл бұрын
Thank you from France for your video.
@ProTechShow
@ProTechShow 2 жыл бұрын
You're welcome 🙂
@wildmanofborneo
@wildmanofborneo 10 ай бұрын
Hello Bitwarden won't recognize a login page that only asks for the username (once the username is entered, the NEXT page asks for the password). How to get Bitwarden to recognize this situation? It works ok if the page asks for both the username and password.
@azmo_
@azmo_ 5 ай бұрын
This was a great video!
@ProTechShow
@ProTechShow 5 ай бұрын
Thanks 🙂
@benf101
@benf101 2 жыл бұрын
In the US we don't use the phrase "muck about". It strikes me as pretty funny so I'm going to use it whenever possible. Like maybe: muck about, find out. (Instead of FAFO)
@ProTechShow
@ProTechShow 2 жыл бұрын
As a bonus: you can safely say it in front of the kids as well! 😄
@notreallyme425
@notreallyme425 2 жыл бұрын
Yes, I would like to hear what you have to say about storing 2FA codes in Bitwarden. For my threat model, I think it’s ok. But I’d like a 2nd opinion.
@ProTechShow
@ProTechShow 2 жыл бұрын
It might get around to making that video, but in the meantime my short version is that I think it's OK as long as you're protecting Bitwarden itself with multifactor authentication. In this case I view you logging into Bitwarden as the "real" authentication and Bitwarden is acting as something of an identity broker. It's a little analogous to logging in to KZbin - you don't actually log in to KZbin, you log in with 2FA to Google and then Google acts as a broker providing a single token to KZbin with your identity.
@notreallyme425
@notreallyme425 2 жыл бұрын
@@ProTechShow I agree, it’s just weird to have an OTP app to get a code to log into Bitwarden to get your OTP codes. I used LastPass as my OTP authenticator, and backed up to my account. So either way my eggs were in the same basket. That’s the reason I ask, because if someone cracks my Vault they have my passwords and OTP codes. I had a good password so I’m not too worried (i’m changing my codes anyway).
@ProTechShow
@ProTechShow 2 жыл бұрын
Yeah, I'd need to make a full video on it to explain my logic properly. Having it in a separate app could be considered more secure on the basis it's one more hurdle to slow an attacker down, but if that app is on the same phone as the Bitwarden app (which is usually the case) then it's a false sense of security because they're both using exactly the same authentication factor, regardless. My personal TOTP codes are currently separate, but that's mostly for historical reasons. If it's a an account shared between multiple people, though; keeping it in Bitwarden is much more secure than skipping the MFA to let your colleague or partner access it - something people often do!
@notreallyme425
@notreallyme425 2 жыл бұрын
@@ProTechShow in the case of the LastPass breach the hackers have my encrypted vault which includes my OTP seed codes. So they don’t need my phone to get both the OTP and the passwords (assuming they can crack my master password). If someone steals my phone and can get past FaceID, then they have access to my OTP codes and my passwords either way, because I use FaceID for my OTP app and Bitwarden. So, in that case I don’t think it matters if I put both in Bitwarden. Either way, I’m not I high profile person, so I’m not too worried.
@ProTechShow
@ProTechShow 2 жыл бұрын
The design of both LastPass and Bitwarden is such that stealing your vault shouldn't actually matter - stealing access to it does (so you should be fine). Or to think about it in MFA terms - your passwords are always protected by MFA: something you know (master password) plus something you have (either the physical database file, or a device generating TOTP codes to access the database remotely). Looked at that way; by breaching LastPass, they've only attained one factor. The biggest risk would be if the device (or software) you're using was compromised because that could potentially let a bad actor read the unlocked vault. In this case, having MFA separate would help; but again, if it's on the same compromised device, it may not help much. The best way to mitigate that risk is using strong authentication like a YubiKey that can't simply be copied (I have a video on that and use it for my important accounts). I wouldn't be too worried about your LastPass vault as long as the master password is good. I'd change the passwords stored in it as a precaution, but in theory we'd all be long dead anyway by the time someone could crack it.
@franktowers3
@franktowers3 Жыл бұрын
i appreciate the video! im going to look if you've done nginx vs traefik!
@ProTechShow
@ProTechShow Жыл бұрын
Thanks! I haven't, but that's a good idea for a future video.
@drew8704
@drew8704 Жыл бұрын
I would love to see the explanation on how integration of TOTP doesn't defeat the purpose.
@ProTechShow
@ProTechShow Жыл бұрын
I've just made a video about it: kzbin.info/www/bejne/bGWZlZ-nmciVg80
@anthonyf.2072
@anthonyf.2072 2 жыл бұрын
Great video. Subscribed. Curious, what Enterprise password manager do you recommend?
@ProTechShow
@ProTechShow 2 жыл бұрын
Thanks! I'm going to give the stereotypical consultant's answer of "it depends". In terms of capabilities and granularity, Delinea (formerly Thycotic) Secret Server is the best I've seen, but you do pay a premium for it. I can recommend it as a good enterprise solution but it's one of those where you can probably get 80% of the capabilities for 25% of the price with another solution, and if the extras don't matter for your use case then you might be better saving the money. Hence, "it depends"...
@anthonyf.2072
@anthonyf.2072 2 жыл бұрын
@@ProTechShow Gotcha. Much appreciated!
@TechFromYorkshire
@TechFromYorkshire 2 жыл бұрын
Good video. Our LastPass Enterprise subscription is due for renewal and we’re exploring the market again - especially after their data leak announcements! What password management solution are you recommending to your clients? We’re a 300 user business with 3 IT staff members.
@ProTechShow
@ProTechShow 2 жыл бұрын
Thanks. We've just been through a selection process for our own use, but I probably can't talk about it online. I can say we wrote off a number of otherwise good tools because our needs are quite different to a typical business. Most password managers that target MSPs are really just platforms for reselling the tool by letting the MSP create lots of instances for their customers to use. We don't tend to resell it, and having lots of instances would slow down our staff and hinder automation. We usually work collaboratively with in-house IT teams rather than full outsourcing, so we have a single platform that we add the IT teams of our customers to so we can share access directly with them. That makes our requirements pretty complex, because we need to share access with third parties but keep them completely isolated from each other without putting them on a separate instance. It goes beyond keeping them away from each other's passwords - if they click the share button they need to be able to see a list of their staff, and any of our staff they work with, but under no circumstances can they see the names of staff at other customers. It also means that where we deploy on-site components to support automation we need to essentially treat them as hostile, so if one customer were breached and their on-site components compromised there's no way to move laterally to anything that could affect another customer. Suffice to say, it narrowed the list of potential vendors pretty drastically!
@alphaneo9198
@alphaneo9198 2 жыл бұрын
Honestly, onepassword is probably best for simplicity and security.
@RexMk1
@RexMk1 2 жыл бұрын
Could you post said list of vendors? And if not, why so?
@ProTechShow
@ProTechShow 2 жыл бұрын
@@RexMk1 probably not. It was an exercise carried out on behalf of my employer so it isn't my information to share. I would need permission from them to do so.
@Tetrodatoxin
@Tetrodatoxin 10 ай бұрын
They are absolutely shipping windows apps on linux to solve the "it works on my pc probelm" nothing to troubleshoot if you ship the user the whole desktop to run in a container. Like you said they need it to be as dummy simple as to keep the support costs simple.
@ProTechShow
@ProTechShow 10 ай бұрын
As a user of software I don't like being forced to use a container because I don't trust devs to build it properly. I have seen (not talking about Bitwarden) too many containers with vulnerable libraries stuffed into them by devs who didn't want to update their code. That said, if the shoe was on the other foot I wouldn't trust the end-user to install it correctly so I'd be quite happy to give them a pre-validated container! It does make sense from their perspective.
@DanialKazemii
@DanialKazemii 17 күн бұрын
Nice!
@ProTechShow
@ProTechShow 16 күн бұрын
Thanks
@MarkSpasov
@MarkSpasov 29 күн бұрын
What password manager do you use as a business admin?
@ProTechShow
@ProTechShow 24 күн бұрын
At work we use Delinea Secret Server. It's the most comprehensive solution I've tested in terms of its automation capabilities, but you do pay a premium for it. For our use case the ability to automatically verify and change passwords across hundreds of client sites is a major benefit, but for less complex scenarios it might be overkill. It is a good fit for us, but cheaper options exist if automation isn't a big driver.
@CrynogarTM
@CrynogarTM Жыл бұрын
We removed Passwords from Company. We use certificates and secure tokens. No user needs a password anymore.
@ProTechShow
@ProTechShow Жыл бұрын
This is the future... I hope. Old habits can be hard to break!
@awesomecronk7183
@awesomecronk7183 8 ай бұрын
Well would you look at that, an actual review about a thing that provides good info on the thing it's about. Thank you!
@ProTechShow
@ProTechShow 8 ай бұрын
Thanks! Glad it was useful.
@FireWyvern870
@FireWyvern870 3 ай бұрын
Is passbolt better than vaultwarden?
@ProTechShow
@ProTechShow 3 ай бұрын
I wouldn't say one is better than the other, they're just different. Passbolt has more of a focus on security, Bit/Vaultwarden has more of a focus on usability. That's not to say Passbolt is hard to use or Bit/Vaultwarden is insecure - these are just areas of relative strength for them. Passbolt can be used as an individual but it is more aimed at team use. I wouldn't recommend deploying the community version to other people unless your users are technically-inclined. It could work for passwords within an IT department, but with "normal" end-users it's only a matter of time before they somehow lose their key, at which point if there isn't an admin somewhere with the escrow feature set up they're going to lose access to their passwords. The use of private keys makes it very secure, but as the escrow feature isn't available in the community version, users really need to look after those keys.
@FireWyvern870
@FireWyvern870 3 ай бұрын
@@ProTechShow thank you for the input. My team is not that big (below 10 people) I'm searching for password manager solution that support multiple user, offline, on premise, secure, can remove access all access for a user at will, easy to migrate if i change the PM server, integrate seamlessly with browser integration ( i can't install app on client device), easy sharing between user. Would you recommend vaultwarden? Personally i use bitwarden, but sharing password is a little bit of a hassle. Do you think passbolt is the way to go?
@ProTechShow
@ProTechShow 3 ай бұрын
Passbolt's sharing might be a bit more intuitive for you. You can test both for free, so I'd suggest giving them a spin to see which you prefer.
@bertivogts9368
@bertivogts9368 Жыл бұрын
@ursochurrasqueira
@ursochurrasqueira 2 жыл бұрын
nice video
@ProTechShow
@ProTechShow 2 жыл бұрын
Thanks!
@fram1111
@fram1111 Жыл бұрын
Make a video on 2FA Bitwarden, you forget Passbolt.
@ProTechShow
@ProTechShow Жыл бұрын
Bitwarden and Vaultwarden are alternative implementations of the same service. Passbolt works completely differently and doesn't fit into this video. I do have a video on Passbolt, though: kzbin.info/www/bejne/fqWWln6ijLqHoKc
@ProTechShow
@ProTechShow Жыл бұрын
I've uploaded a dedicated video about the 2FA aspect: kzbin.info/www/bejne/bGWZlZ-nmciVg80
@senpaisylnsr5253
@senpaisylnsr5253 2 ай бұрын
Bitwardens zero knowledge model was a bit of a lie the last time I checked.
@ProTechShow
@ProTechShow 2 ай бұрын
How so? The data is encrypted and decrypted on your device so BitWarden themselves have no visibility of it.
STOP Using Passwords!
17:19
Pro Tech Show
Рет қаралды 31 М.
Fake Open Source Is a Problem
19:19
Pro Tech Show
Рет қаралды 101 М.
Quando eu quero Sushi (sem desperdiçar) 🍣
00:26
Los Wagners
Рет қаралды 15 МЛН
How to treat Acne💉
00:31
ISSEI / いっせい
Рет қаралды 108 МЛН
Mom Hack for Cooking Solo with a Little One! 🍳👶
00:15
5-Minute Crafts HOUSE
Рет қаралды 23 МЛН
The Most Important Bitwarden Setting You Never Heard Of
12:20
Jason Rebholz - TeachMeCyber
Рет қаралды 67 М.
AI Is Making You An Illiterate Programmer
27:22
ThePrimeTime
Рет қаралды 216 М.
I Tested 7 Password Managers: the BEST of 2024 is…
5:48
All Things Secured
Рет қаралды 256 М.
Is Bitwarden's 2FA Code a Security Risk?
11:06
Pro Tech Show
Рет қаралды 16 М.
EDR, MDR & XDR Explained
10:33
Pro Tech Show
Рет қаралды 48 М.
NVIDIA CEO Jensen Huang's Vision for the Future
1:03:03
Cleo Abram
Рет қаралды 607 М.
I think I finally found a new password manager!
10:05
Techlore
Рет қаралды 59 М.
OPEN SOURCE alternatives to the MOST POPULAR productivity apps!
15:37
The Linux Experiment
Рет қаралды 1,4 МЛН
Quando eu quero Sushi (sem desperdiçar) 🍣
00:26
Los Wagners
Рет қаралды 15 МЛН