Bitwarden introduced a non-free dependency to their clients. The Bitwarden CTO tried to frame this as a bug but his explanation does not really make it any less concerning.

Perhaps it is time for alternative Bitwarden-compatible clients. An open source client that’s not based on Electron would be nice. Or move to something else entirely? Are there any other client-server open source password managers?

  • CommanderShepard@lemmy.world
    link
    fedilink
    English
    arrow-up
    44
    ·
    edit-2
    15 days ago

    Bitwarden is a very convenient password manager for an average computer user. It’s very straightforward and easy to use.

    I can see some bias here of the people who say “o, just use KeePass and sync the database over some cloud provider”. What if there are conflicts? How do they deal with them? I can figure it our but most people I know, won’t.

    Even the password manager concept is a complicated concept to grasp for many people (that I know). And I can recommend them Bitwarden because it’s relatively easy, but KeePass with sync? Maybe, if I commit to actively help them with it.

    P.S. I’ve convinced several people to try out Linux, and they are willing to learn it, but even if they just need to use a browser, they struggle sometimes. I can’t imagine them syncing the KeePass database.

    • Daniel Quinn@lemmy.ca
      link
      fedilink
      English
      arrow-up
      16
      ·
      15 days ago

      This is a common problem with Free software, and honestly I think it’s our biggest one: we build stuff for ourselves and stop there. If we want our stuff to be adopted (which, for things that rely on network effects, we do) then we need to pay more attention to usability.

      Here’s a suggestion for anyone starting a project they think they might share. Before you start writing any code, write the documentation. Then rewrite it from the perspective of the least tech-literate person you know who you’d still want to use the project. Only after you’ve worked out how easy it should be for this person to get started, then you can start writing the thing.

      • CommanderShepard@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        15 days ago

        Ideally, the project should not require any documentation to read.

        Yep, I know, I think everyone should read to learn, but I’ve seen so many times peoples’ spark die once I tell them “I will send you the docs with clear instructions. If you have any questions, let me know :)”. The reply is often " Oh, but it should tell me where to click".

        Or maybe it’s because the docs are too difficult, I don’t know.

        • Daniel Quinn@lemmy.ca
          link
          fedilink
          English
          arrow-up
          5
          ·
          15 days ago

          Generally, I agree. I think what I meant by the above is “how would you tell someone how to use the thing”. My favourite example is email vs email-with-PGP.

          How do you send an email?

          1. Open client
          2. Click “send new email”
          3. Type your email
          4. Click send

          How do you send a PGP-encrypted email

          Let’s first talk about this thing called a “keyserver”. Once you know what that is, you’ll have to go out and find some keys to add to it. We’re not going to talk about styling your message 'cause that’s not something you should be able to do… etc. etc.

        • EssentialNPC@lemmy.world
          link
          fedilink
          English
          arrow-up
          4
          ·
          edit-2
          15 days ago

          Good documentation should, in part, tell people where to click. I have designed software documentation for high performing individuals at leading global companies, and I have designed software and hardware documentation for minimum wage fast food workers with limited English proficiency. In both extremes, I showed them exactly where to click on the screen at each step.

          You might not need that level of help, but many people do. Others do not strictly need it, but they prefer the simple instruction set. “Click here then here,” instructions ease the transition into a new system one needs to learn, or it removes the need entirely to learn a system one uses infrequently.

          The problem is that making good documentation is difficult and time consuming. It relies on a fundamentally different skill set than coding or even UI design.

          I agree that the ideal is for software to not need any documentation. In my experience, I have yet to see software that rises to that task and is used across a variety of experience levels and societal cross sections.

        • Allero@lemmy.today
          link
          fedilink
          English
          arrow-up
          2
          ·
          edit-2
          15 days ago

          The docs are not only often difficult for an inexperienced user, they commonly omit points of failure.

          Various prerequisites, problematic settings, possibility of the user choosing the wrong menu etc. etc. should always be considered.

    • overload@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      8
      ·
      15 days ago

      Have got two of my family members onto bitwarden and even that is a lot for the tech-illiterate. Couldn’t imagine Keepass+syncthing.

      Ultimately, bitwarden is better than using hunter12 for everything like how they were.