Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Reminder: Dump your password manager database into cleartext backups regularly. Store them on encrypted media (eg. USB stick with FileVault, VeraCrypt, or similar)

Then you will not be totally screwed if your password manager does a rug pull against you such what Bitwarden is doing with this change.



How is this new policy a rug pull?


It's a password manager. It must never, under any circumstances, add any additional barriers to getting in that aren't explicitly configured by the user.

This is going to lock out many users. They will not realize this new arbitrary requirement to be able to access the email address. They will lose their existing device. They will get a new device, install Bitwarden, and try to login with their master password, only to find that Bitwarden has moved the goal posts. They will be locked out of everything.

Even if 99.99999% of users would benefit from this change, Bitwarden shouldn't do it because it'll unfairly lock out 0.00001%. If they really want to do this change, then they should have like 2 years of warnings displayed on existing clients, and also have an option to permanently disable any 2FA requirement.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: