Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You give in trust your company’s passwords to a random dude’s open source project that was never audited professionally. Seems a very risky thing to do.


The only thing you have to trust on a BitWarden server is the Javascript client that it serves you, and using that is entirely optional as you can just use other clients. The server could be explicitly malicious and still safe to use.

bitwarden_rs bundles the upstream JS in its default containers, so it's the same code that you'd be running from bitwarden.com


Both server impls end up with a bunch of binary crap in the end.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: