Hacker News new | ask | show | jobs
by jopsen 2779 days ago
isn't there still a lot more hardening things to do, like moving payment out from vault.bitwarden.com, so that this domain can have a stronger CSP policy?

In other news: my todo list now features an item to migrate lastpass -> bitwarden.

(I really love the effort here)

2 comments

I mostly don't regret switching from LastPass to BitWarden. Migration of logins was pretty painless. My only issue is with Android/Firefox. (Desktop Firefox + BitWarden is excellent!) The current Firefox doesn't play well with the Android BitWarden app, so you have to use the Add-on. (At least, this has been my experience.) I've also frequently encountered an issue where the menu item in Firefox for BitWarden vanishes and I have to toggle the add-on to re-add it. Over the past four days, I haven't had the issue, so I'm hoping that it's resolved for good. I believe these issues will be resolved, and they are largely not the fault of the BitWarden team; more like the Android platform and the Firefox team getting caught up with the latest best practices. (I believe Firefox Nightly actually plays well with the app, and should not require the clunkier add-on.)
My only problem was ampersands. LastPass encoded them as & and I wasn't aware of this at first. After receiving errors for some passwords, I found out that was the problem. I had to find and replace all. Bitwarden was aware of this though, they have a warning for this on their migration guide.
The migration process is very painless [0]; it will take longer to switch your installed extensions on all your devices than to migrate your vault.

[0]: https://help.bitwarden.com/article/import-from-lastpass/