lastpass to bitwarden
Author:
Security mavens recommend that we use a password manager for our online activity.
Username/password pairs suck and we humans are horrible at doing the "right thing" with them. I know that I am.
Over the last few years several tools have been created that address the issue. I've used and supported many of them.
A few products are pretty mature now and easy enough for muggles and other mortals to be able to use.
I've been using lastpass as a personal password manager for a few years. I've loved it and have been pretty satisfied in general. But with the recent announcement that they will want a fee to use the same account on multiple devices I decided to explore my options.
Long story short, I decided to give bitwarden a try: https://bitwarden.com/
While I have not done a code audit on it myself. Nor would I trust the outcome of such an audit if I were to do one, the code is public. https://github.com/bitwarden/mobile
I have read several reviews and tech reports corroborating that it is a zero trust system. I guess that's good enough for me. I've gone a head and installed it. It has the normal browser interface, both flavors of phone app, and a plugin I'm using in firefox, and a cli if you swing that way.
So far so good. It was easy to export my details from last pass and import them into bitwarden. They are visible on the devices I've converted so far. The positive use case seems OK. I'm not sure how I will validate the negative use case. I'm not sure how I'd detect if things have gone bad till I next check my bank balance.
I'll report back if and when things go sour.