13

I've been using BitWarden as my main password keeper, would like to ask if it's safe? I know that everything is not 100% safe but still want to know if they are worth it.

All my passwords are different beside some accounts password.

I know there is also keepass but can't really be annoyed to backup it each time because I also use a lot my mobile and BitWarden has a mobile application that is really helpful.

Benoit Esnard
  • 13,942
  • 7
  • 65
  • 65
osu
  • 131
  • 4
  • 2
    You might find some useful information in this question: [How safe are password managers like LastPass?](https://security.stackexchange.com/q/45170/129883) – Fire Quacker Jan 02 '20 at 16:36

1 Answers1

9

First as you said nothing is 100% safe. Having said that I think BitWarden is a trust worthy password manager for the following reasons,

  1. They are open source. All of their products including their desktop app, mobile app, browser extension, web application & server are all open source.
  2. The applications are developed in open too. The open source projects are not just code drops, the app is being developed in the open.
  3. If you are using BitWarden's cloud, you need to know that they use Microsoft Azure offerings. They only use service offerings and all the security updates to the server are handled by Microsoft which they claim is better for security.Ref
  4. If you are not satisfied with the security of BitWarden's server or have issues with MS Azure, you can host your own server. This way your data will be with you only and not stored in BitWarden's server. This is one of the biggest advantages as even if BitWarden's server gets taken down or hacked your data might be accessible and safe.
  5. Compared to KeePass they have a well maintained open-source applications on all platforms. Some forks of KeePass are not that up to date.
  6. They are audited by third partiesRef.
Kolappan N
  • 2,662
  • 14
  • 26
  • Thank you for the explanation. regarding " if BitWarden's server gets hacked your data might be safe" -> isn't it a zero-knowledge cloud? If so, isn't the data safe even if the server gets hacked? – João Matos Feb 21 '21 at 11:55
  • @JoãoMatos It is supposed to be. Updated the answer. – Kolappan N Feb 22 '21 at 05:02