this post was submitted on 02 Feb 2025
34 points (94.7% liked)

Bitwarden

862 readers
2 users here now

Discuss the Paswordmanager Bitwarden.

founded 2 years ago
MODERATORS
all 26 comments
sorted by: hot top controversial new old
[–] [email protected] 19 points 4 days ago (1 children)

correct horse battery staple

[–] [email protected] 7 points 4 days ago (1 children)

How did you steal my password??

[–] UndulyUnruly 3 points 4 days ago

Witchcraft! Get them!

[–] [email protected] 6 points 4 days ago (1 children)

For passwords i have to remember i use passphrases.

But for stored passwords? i like 35 characters. Most services accept it and doesn't seem to have a con.

[–] [email protected] 6 points 4 days ago (2 children)

And then there are those services that let you enter arbitrarily long passwords in the registration form but only save something like 16 characters.

[–] [email protected] 4 points 4 days ago

I hate this situation. What horrible design choices in their code!

[–] [email protected] 2 points 4 days ago (2 children)

I know about them but I haven't experienced it yet. Hope I never will though.

[–] amorpheus 2 points 4 days ago (1 children)
[–] [email protected] 1 points 4 days ago (1 children)

You wouldn't. You'd have to find out yourself after not being able to log in despite you being 100% sure that your password is correct :/

[–] amorpheus 2 points 4 days ago* (last edited 4 days ago) (1 children)

No, that's the point, you'd never know whether they only validate a subset of the password. Only by testing different variations you would know that less than the whole string still works.

[–] [email protected] 1 points 4 days ago (1 children)

It's a common enough to safely assume i'd guess. I've heard many users complain about it despite not me experiencing it myself. They probably didn't try every single variation of the password but maybe it's an infamous bug for many services?

[–] amorpheus 2 points 4 days ago (1 children)

I wouldn't speculate on how common it is but limiting passwords seems to happen more than it should. So maybe many are taking the stealth approach.

One site I know where this happens (at least I experienced it some years ago) was Blizzard. Found out by sheer luck after I clearly fumbled the end of my password and was logged in regardless.

[–] [email protected] 1 points 4 days ago

Jesus, worth $60 billion, and can't even store passwords properly? lmao

I wouldn't know whether to feel relieved after the panic of realizing not being able to log in, or being disappointed of how shit the code is lol

[–] [email protected] 2 points 4 days ago
[–] [email protected] 6 points 4 days ago (4 children)

People gotta stop doing QkFEcEEkJFcwUkQ=

aQuickBrownFoxJumpedOverALazyDog$nuggle9 is far easier to remember and secure.

[–] [email protected] 10 points 4 days ago (1 children)

The article is from Bitwarden, which is a password manager - using them you don't need to remember individual passwords (or type them, normally).

Bitwarden does have an option to use passphrases, I just tried it and it gave me washtub-moocher-dominoes.

[–] cynar 2 points 4 days ago

I use auto generated passphrases. It's mostly for the occasions where I need to give the password to someone, without logging into my bitwarden account, on the device. It's a lot easier, for comparable levels of security.

[–] [email protected] 5 points 4 days ago* (last edited 4 days ago) (1 children)

aQuickBrownFoxJumpedOverALazyDog$nuggle9 is far easier to remember and secure.

Not really, you have a better chance if you use a completely random set of words. I remember hearing of someone getting their bitcoin stolen from their wallet despite their password being from an obscure Afrikaans poem.

Diceware's a really good tool for this. https://www.eff.org/dice. There are also websites to generate one for you instead of rolling actual dice.

But it's only good for passphrases. You're better off generating a complex password since you can store it in bitwarden.

[–] [email protected] 4 points 4 days ago (1 children)

Not really, you have a better chance if you use a completely random set of words. I remember hearing of someone getting their bitcoin stolen from their wallet despite their password being from an obscure Afrikaans poem.

Precisely why I salted it.

[–] [email protected] 1 points 4 days ago (1 children)

I have to look into password salting. I don't use it but it's interesting. Do you use a unique salt for each password or the same one for all?

[–] [email protected] 1 points 4 days ago

Always something a bit unique, can't make it predictable if someone managed to dump a list of em. This also isn't the formula I used just an example. Random words is also better if your memory is decent, they can even be your salt.

[–] [email protected] 3 points 4 days ago

I'm more of a SphinxOfBlackQuartz,JudgeMyVow:3 kinda guy

[–] [email protected] 2 points 4 days ago* (last edited 4 days ago)

I switched to using word phrases after having to type in these Qjdu37hYdu4sjdh&) |] >[vry monstrosities or communicate them to someone else one too many times.

[–] [email protected] 3 points 4 days ago
[–] [email protected] 2 points 4 days ago