Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Does anyone happen to know how pricing works with Bitwarden and a self-hosted Vaultwarden server? Some of the critical features like storing 2fa seeds seem to be locked behind the paywall, but Vaultwarden lists "support" for it and it's unclear whether it's the server software that locks this functionality (and therefore it can be used for free with the Vaultwarden backend) or if it's the client apps.


Vaultwarden is a free, OSS implementation of the Bitwarden server, and has no licensing costs. It's API compatible with the official Bitwarden client, which also has no cost. If the client supports the functionality, and server supports the functionality, you're in the clear. Bitwarden's documentation on features and licensing are only applicable to their backend products.


Can confirm that the self-hosted version does indeed have 2fa seeds behind a paywall -- that being said though, storing both passwords AND your 2fa seeds in the same app feels like a security antipattern.


Storing my 2FA seeds on Bitwarden (or any other password manager that itself supports 2FA) is still something I have because I need to have a device that's been approved or the security token that 2FA's Bitwarden itself.

Whether it's as secure as using a separate TOTP generation app is slightly beside the point, because it's so much more usable. And I don't need to re-bootstrap access to all my accounts when my phone gets run over by a car.


I know some people are more sensitive to that, but the annoyance of managing 2fa seeds via some other app (that I have previously had difficulties recovering...) outweighs my actual perceived risk. Thanks for confirming

Edit: Based on the other reply to my comment-- are you using the Bitwarden self-hosted solution? I was primarily interested in Vaultwarden, the OSS alternative




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: