Hacker News new | ask | show | jobs
by Lcchy 400 days ago
They both do e2ee so they cannot read your secrets server-side, which is the standard.

Critically though, Bitwarden is open source, meaning that if the encryption is weakened, it would be noticed in the source.

With 1Password the clients are closed source: you have to trust the company to encrypt the secrets properly and an (malicious or accidental) change of the encryption cannot be detected by the user.

After Lastpass's fiasco around encryption, I don't feel like blindly trusting another company.