Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I 'mirror' my Bitwarden login entries in a KeepassXC database, so I have an offline carbon copy incase Bitwarden's servers are wiped or not accessible, or for whatever reason, I can't access my Bitwarden vault. I would suggest everyone do the same. The only pain point is remembering to make a carbon copy of each entry you add to Bitwarden, in the KeepassXC database.

I also make copies of my KeepassXC database in several cloud storage services incase of a house eating event which destroys my hard-drives (unlikely but still a possibility). I really don't like the idea of being locked out of my digital life.

Terence Eden has a good article about this potential scenario;

https://shkspr.mobi/blog/2022/06/ive-locked-myself-out-of-my...

For those wondering why I use Bitwarden as-well as KeepassXC:

1.) Redundancy. Can't get at my KeepassXC?, then I try Bitwarden. Can't get at my Bitwarden? Then I try KeepassXC. Can't get access to both? Then I'm screwed (but this is unlikely).

2.) Browser extension. I like to be able to login easily to sites using their extension.

3.) LOCKSS (Lots of copies keeps stuff safe). Having a cloud-based mirror of my login entries stored in Bitwarden is marginally better than solely relying on KeepassXC.

4.) Logging into KeepassXC is sometimes more complicated than logging into Bitwarden. I have a long seven word passphrase for KeepassXC, and use a keyfile which I have to 'hunt down' in the filesystem each time I go to access KeepassXC (I have disabled the ability to store the last used database & keyfile for security reasons). With Bitwarden I just open the app and if it's unlocked, I get quick access to everything.



What exactly is Bitwarden getting you if you're doing this copy process? I have only used Keepass and haven't read why Bitwarden would be superior for some scenarios over what I am already doing.


> haven't read why Bitwarden would be superior

1. Out-of-the-box integrated sync with a dedicated default host: keepass has 8 different sync plugins, all with different levels of maintenance & UX, each for separate sync backends, all requiring separate 3rd party backend account setup

2. Consistent cross-device features & UX: Keepass has 3 browser plugins with varying levels of browser support (not sure if any have mobile support?)

On top of the above, Bitwarden is open source and allows self-hosted sync


I didn't know KeePass(XC) had sync plugins, let alone eight, since I just sync the file myself as part of the same infrastructure that syncs everything else under my homedir.


Yeah I just have my KeePass file in my own Nextcloud and I can access it on any device. I have never needed to mess with a sync plugin.


Do you sync your homedir to your phone? I presume you're an android user?


Linux user. My phone runs postmarketOS.


3. Easy password sharing, free for 2 person organizations.


Yes! This too. My partner & I have used this for shared / family / household billing accounts / etc. for years.


> What exactly is Bitwarden getting you

1.) Redundancy. Can't get at my KeepassXC?, then I try Bitwarden. Can't get at my Bitwarden? Then I try KeepassXC. Can't get access to both? Then I'm screwed (but this is unlikely).

2.) Browser extension. I like to be able to login easily to sites using their extension.

3.) LOCKSS (Lots of copies keeps stuff safe). Having a cloud-based mirror of my login entries stored in Bitwarden is marginally better than solely relying on KeepassXC.

4.) Logging into KeepassXC is sometimes more complicated than logging into Bitwarden. I have a long seven word passphrase for KeepassXC, and use a keyfile which I have to 'hunt down' in the filesystem each time I go to access KeepassXC (I have disabled the ability to store the last used database & keyfile for security reasons). With Bitwarden I just open the app and if it's unlocked, I get quick access to everything.


What does the painful process of hunting for a keyfile offer in terms of security when bitwarden on the same machine doesn't have that protection?


Thanks! I will probably just stick with Keepass but this was a nice write-up to consider.

1) I have my database replicated several places already. Cloud storage, mobile, FTP server, etc.

2) I don't use a browser extension on desktop, but I know there is one. On mobile the accessibility permissions allow it to suggest login information both in third party apps and in the browser. I've found it works fairly well. If you aren't able to open your database quickly it might not be as convenient.

3) This sounds the same as what I was considering for (1). Historical backups would be important for recovering from possible corruption, but I have not run into this yet for Keepass.

4) Understood. Bitwarden doesn't support keyfiles?

I have been close to splitting my Keepass DB up into several, but haven't pulled the trigger on that effort.


4. is ... interesting :-) You made access to KeePass more obscure for "security reasons." But fear not: "With Bitwarden I just open the app." Okay cool.


I manually export my Bitwarden vault to KeePass from time to time as well. The benefit of still using Bitwarden for me is that I can access and update my main vault from any linked device (desktop PC, laptop, phone) without needing to synchronize data between devices. It's far from an ideal way, but you can have a little more confidence that you will have access to your data (although it might be a slightly outdated snapshot of the data) even if you can't access the Bitwarden server. That is exactly what happened today, and I was still able to retrieve my password from the local copy.


My understanding that BW have superior auto-fill features and wide support for different OS. Keepass don't have auto-fill for browsers, Keepass have to rely on third-party to provide the auto fill features and various apps for all variety of OS.

I'm a Keepass user since 2006 and never had a problem with them. My database is saved in OneDrive and always keep local copy in my system. If OneDrive is down, my local copy is always there for me.


KeePassXC does have auto-fill for browsers. And also Auto-Type which allows you to enter your credentials to _any_ application possible. All this works without any third party plugins.


When Bitwardens servers are inaccessible mobile and windows app continue to work just fine using a cached version.

In my case even sync new passwords once the seever/Internet comes back up.


Indeed, it worls online fine. Also there is a stand alone desktop version, no need for keypass.

I do use keypass to save things I don't want to expose in an online service, no matter how secure it is.


I just host my own Bitwarden. I try to self host as much as possible and be anti cloud


Using something like vaultwarden? I'm curious how do you keep it secure from intrusion? I'm looking to do the same


> Using something like vaultwarden? I'm curious how do you keep it secure from intrusion? I'm looking to do the same

The official bitwarden self hosted setup works flawlessly. Hosting it at home and access it through tailscale.


Anti public cloud here as well


I'm working on a product to solve this problem (i.e. where do you backup your seed, high value keys / secrets, 2FA codes). The approach is social recovery (threshold cryptography) for the root seed, and a digital agent component (i.e. DWN - distributed web noted) SaaS or self hosted. The digital agent is used for encrypted backups and to communicate with other parties (contacts). Does this sound interesting to you?


> I 'mirror' my Bitwarden login entries in a KeepassXC database

I do this manually and I want to know if you automate it and how.


Genuine question: why all the hassle when it’s so easy to reset passwords?


Password reset assumes two things:

A - the service doesn't encrypt your data (or has access to your private keys), and

B - that you have access to the second factor which is used to reset your password (e.g. a backup email address).

Secure password managers do not have access to your private key (i.e. the encryption key), as such if you lose the seed there is no recovery.

In the case with other services (i.e. they can reset your password) there is a chance you could lose access to your backup email or phone number used for resetting.

Edit: some services do allow reset by proving your "identity" (e.g. bank), in which case you have to go through customer service and provide requested information. (I put "identity" in quotes, because nefarious actors can sometimes prove this too).


Why not just periodically backup your bitwarden vault to external storage?


From GP:

> incase of a house eating event which destroys my hard-drives

I worry about this as well. Yes, a friend's house is an option, but not everybody has friends or family in the same city, and if they're further away, updating copies is a pain.


Ah, fair point. I should do something like that for my own setup then. My current setup may also be vulnerable to that failure mode.


How is Dropbox shared folder is a pain in updating copies across cities?


Syncing your password safe to Dropbox is a completely different scenario, with a corresponding different threat model.

It may work for some people, but on average, I'd say it's worse than relying on a dedicated/"native" password safe cloud syncing service.

In any case, it's certainly not an alternative to a physical offline copy.


On the contrary, it's very similar - you share a keyfile to your friends in a different city and then you encrypt your password safe with that extra keyfile that hasn't touched Dropbox. This solves the threat model issue while also relieving you of the pain of syncing the password safe (in this case syncing is even more convenient than your same-city-physical-visit model)


Assuming that the keyfile is only for emergencies: How do you unlock the password safe day to day?


In a manner much easier than a physical visit: with a double click?

(though you don't do it every day, you do it whenever you export bitwarden safe for backup purposes)


why not just self host at this point? this seems like security theater.


I've been considering this, but to be honest, I don't trust myself to keep up with updates and other aspects of opsec for something that I only use for myself and would have to do consistently and reliably at nights and weekends.

That would probably be balanced out with my self-hosted instance hopefully being less of a target, but the downside there is that I might not even know that my database was compromised and it's down to my passphrase strength now.

With Bitwarden's SaaS, I'd hope that I would hear about such a compromise before too long, giving me time to rotate passwords while GPUs gnaw at my (and everybody else's) passphrase.

Additionally, there are certain opportunities for account access recovery that are much harder or impossible when self-hosting, e.g. things like a cool-down period and a warning e-mail before allowing a less-secure 2FA method.


Why not just use KeePassXC ?


1.) Redundancy. Can't get at my KeepassXC?, then I try Bitwarden. Can't get at my Bitwarden? Then I try KeepassXC. Can't get access to both? Then I'm screwed (but this is unlikely!).

2.) Browser extension. I like to be able to login easily to sites using their extension.

3.) LOCKSS (Lots of copies keeps stuff safe). Having a cloud-based mirror of my login entries stored in Bitwarden is marginally better than solely relying on KeepassXC.

4.) Logging into KeepassXC is sometimes more complicated than logging into Bitwarden. I have a long seven word passphrase for KeepassXC, and use a keyfile which I have to 'hunt down' in the filesystem each time I go to access KeepassXC (I have disabled the ability to store the last used database & keyfile for security reasons). With Bitwarden I just open the app and if it's unlocked, I get quick access to everything.


1. You can store your encrypted KeepassXC kdbx file anywhere you wish.

2. KeepassXC has a browser extension.

3. Refer to point 1.

4. Using a keyfile is optional and IMO don't see how it adds any security benefits to the master passphrase.

The only reason Bitwarden "just opens" from the last session is because of the very features you have disabled in KeepassXC (remember last used kdbx).

Launching KeepassXC for me has exactly the same steps as Bitwarden has. Open program, put correct passphrase (or insecure PIN on Bitwarden for the lazy folks) and the password database unlocks.


> 4. Using a keyfile is optional and IMO don't see how it adds any security benefits to the master passphrase.

I believe it fulfills the same 2FA role as does the Secret Key in 1Password <https://support.1password.com/secret-key-security/>: combining something you know (passphrase) with something you have (keyfile/Secret Key), thus making a potential Dropbox breach (or wherever you store your .kdbx) not subject to offline dictionary attacks -- err, unless you also stored your keyfile in Dropbox in which case, yes, it wouldn't add any security benefits


A strong passphrase should be good enough to deter dictionary attacks, even if your kdbx file is leaked.

And even then the ciphers used to encrypt the kdbx file are highly configurable, you can future-proof the key derivation function as much as your hardware can reasonably afford to unlock the file.

Besides using a keyfile for daily use is impractical. For correct usage, you'd have to keep it in a separate drive from your kdbx (in a USB flash perhaps), as you very well mentioned. But then in the menu you'd have to go to the directory the keyfile is stored in every single time you want to unlock your database if am not mistaken about how the feature works on KeepassXC.


KeePassXC even had the advantage that I only have to unlock once for both desktop app and browser extension.

BitWarden requires separate unlocks.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: