1
00:00:00,020 --> 00:00:04,380
The file is encrypted before it gets sent to the cloud.

2
00:00:04,680 --> 00:00:07,620
There's nothing that gets sent that's not encrypted in your vault.

3
00:00:09,080 --> 00:00:11,220
Hello, everybody, and welcome to Techlore Talks.

4
00:00:11,340 --> 00:00:14,020
Today, I'm really excited to have on Bitwarden.

5
00:00:14,020 --> 00:00:16,660
We're going to talk about the origins of Bitwarden,

6
00:00:17,040 --> 00:00:20,020
how they're able to fund this open source password manager,

7
00:00:20,640 --> 00:00:23,640
community involvement, the security posture of Bitwarden,

8
00:00:23,760 --> 00:00:25,160
as well as the privacy posture,

9
00:00:25,780 --> 00:00:27,740
comparing Bitwarden to other password managers,

10
00:00:27,930 --> 00:00:29,600
why you should even use a password manager,

11
00:00:29,980 --> 00:00:33,360
best practices with your password manager, and so much more.

12
00:00:33,460 --> 00:00:37,900
If you've been looking for a deep dive on password managers and or Bitwarden, this is it.

13
00:00:38,340 --> 00:00:39,340
And now to the interview.

14
00:00:39,740 --> 00:00:40,120
All right.

15
00:00:40,300 --> 00:00:44,480
I would like to introduce Ryan from Bitwarden, if you want to say what you do.

16
00:00:45,560 --> 00:00:46,520
Hi, I'm Ryan.

17
00:00:46,720 --> 00:00:50,340
I work at Bitwarden as a senior PMM, that's product marketing manager.

18
00:00:51,460 --> 00:00:51,700
Nice.

19
00:00:52,480 --> 00:00:54,640
How did you get involved with a security company?

20
00:00:54,700 --> 00:00:58,140
Did you start with security and then, you know, get into the marketing for security?

21
00:00:58,220 --> 00:01:00,640
or did you start with marketing and then stumble on a security company?

22
00:01:00,670 --> 00:01:02,660
No, it's actually a really funny story how I started.

23
00:01:03,130 --> 00:01:04,860
I actually have a background in film and multimedia.

24
00:01:05,199 --> 00:01:07,740
I was a part of that industry for quite a few years.

25
00:01:07,910 --> 00:01:09,060
I didn't like where it was going.

26
00:01:09,380 --> 00:01:12,160
And after seeing a couple of bad business decisions be made

27
00:01:12,240 --> 00:01:13,720
by some of the studios I was working at,

28
00:01:13,750 --> 00:01:15,700
I decided to go get a business degree so I could do it better.

29
00:01:16,600 --> 00:01:20,040
And I found my passion really in marketing over there,

30
00:01:20,180 --> 00:01:21,600
just telling stories, connecting with audiences,

31
00:01:22,110 --> 00:01:25,620
which is basically what I did before when I was doing film editing and such.

32
00:01:25,920 --> 00:01:29,240
And right out of business school, I got hired by Dell.

33
00:01:29,590 --> 00:01:35,940
And I was at Dell Technologies for six years, selling laptops, Alienware products, monitors,

34
00:01:36,700 --> 00:01:39,920
other things like working on product messaging for all that, working with the engineers,

35
00:01:40,140 --> 00:01:40,820
seeing all the prototypes.

36
00:01:42,020 --> 00:01:43,860
It was a really, really fun type of gig.

37
00:01:43,970 --> 00:01:45,900
And then I found my way over to Bitwarden.

38
00:01:46,400 --> 00:01:49,480
I was really intrigued by the open source and security nature of it all.

39
00:01:49,880 --> 00:01:52,720
It's funny because at the time, I didn't actually use a password manager.

40
00:01:53,020 --> 00:01:55,140
So Bitwarden was my first exposure to password management.

41
00:01:55,520 --> 00:01:57,300
And, you know, I was interested to learn more.

42
00:01:57,500 --> 00:02:00,080
I had started trying a couple of different solutions out.

43
00:02:00,640 --> 00:02:05,620
And I ended up joining Bitwarden in two ways, personally and professionally.

44
00:02:06,720 --> 00:02:07,060
Very nice.

45
00:02:07,320 --> 00:02:10,580
And what's kind of the origin for Bitwarden?

46
00:02:10,740 --> 00:02:12,500
I mean, it's pretty prolific in our community.

47
00:02:12,640 --> 00:02:15,060
Everyone knows who Bitwarden is for the most part in our community.

48
00:02:15,340 --> 00:02:18,400
But I don't personally know the origins there.

49
00:02:18,740 --> 00:02:20,140
You can read all the stories online.

50
00:02:20,420 --> 00:02:30,960
Our founder, Kyle Spearin, he decided to develop Bitwarden on his own after being disenfranchised by another password management solution that he was working on.

51
00:02:30,960 --> 00:02:34,780
He realized, like, man, this password manager is really not great for business.

52
00:02:36,060 --> 00:02:38,560
What can I do to make a password manager that works for everyone?

53
00:02:39,440 --> 00:02:42,440
And that was basically the genesis of it.

54
00:02:42,440 --> 00:02:44,100
He started off as an open source project.

55
00:02:45,180 --> 00:02:59,860
You can go back and find the original post he made in 2017 on Reddit and on Hacker News announcing his project and, you know, built up a community support from there, just working with open source.

56
00:02:59,970 --> 00:03:01,220
He has plenty of interviews.

57
00:03:01,250 --> 00:03:02,680
I highly recommend you go listen.

58
00:03:02,690 --> 00:03:03,440
It's pretty enlightening.

59
00:03:04,780 --> 00:03:06,980
And have you guys been open source from day one?

60
00:03:07,540 --> 00:03:08,020
Yeah, absolutely.

61
00:03:08,740 --> 00:03:09,260
All right.

62
00:03:10,140 --> 00:03:12,700
So what's your overall team size as well?

63
00:03:13,220 --> 00:03:24,600
So we have, we've come a long way. We're up to about 250 employees now, employees and contractors. So, you know, really, really working hard to, you know, make Bitwarden the best product possible.

64
00:03:25,180 --> 00:03:47,340
Wow. And I guess the one thing before I get into the open source side of things, funding. So of course, you guys have free, you have paid for individuals, and then you have enterprise. And then I do know that there are like funding models as well with some VCs. So how does that all interplay? And what's kind of the relationship there for the company if people are curious about that?

65
00:03:47,940 --> 00:03:52,960
Yeah, so Bitwarden has a free plan, always has a free plan, always will have a free plan.

66
00:03:53,780 --> 00:03:55,960
We've made that promise many, many, many times.

67
00:03:56,280 --> 00:04:07,760
And Bitwarden, most of the income that we see, funded income, comes from the people who pay for premium plans on the individual side, but most importantly, business plans.

68
00:04:08,120 --> 00:04:13,880
So the business plans do make a large portion of the funding for Bitwarden.

69
00:04:14,500 --> 00:04:18,500
And it's actually thanks to the community that we even get those business plans in the first place.

70
00:04:18,720 --> 00:04:27,480
One of the things that we find is that most businesses started off looking at password managers and somebody who's using Bitwarden says, hey, Bitwarden's great.

71
00:04:28,040 --> 00:04:29,720
I'd love to bring Bitwarden into the office.

72
00:04:30,360 --> 00:04:37,580
And we always have some sort of champion who's helping us out and really touting the benefits of open source and bringing people along.

73
00:04:37,780 --> 00:04:43,720
So to us, it really comes all from the community who goes out and brings Bitwarden to work.

74
00:04:43,780 --> 00:04:46,540
We actually once ran a campaign called Bring It, Bring Bitwarden to Work.

75
00:04:46,560 --> 00:04:48,720
It just comes back to us through there.

76
00:04:48,860 --> 00:04:51,280
And then we also want to continue that engine.

77
00:04:51,840 --> 00:05:05,780
And so Bitwarden also gives free families plans to any enterprise user so they can take Bitwarden back home to more people and maybe, you know, get their brothers, get their sisters, anybody, their children using Bitwarden and used to it.

78
00:05:05,780 --> 00:05:10,060
So then when they go out into the workplace, they are also interested in bringing Bitwarden to work.

79
00:05:10,320 --> 00:05:11,640
It's a really great engine.

80
00:05:11,740 --> 00:05:15,100
And you had mentioned some VC funding as well.

81
00:05:15,900 --> 00:05:17,900
The growth announcement for that was made in 2022.

82
00:05:18,560 --> 00:05:21,620
You can find all the disclosures and stuff online.

83
00:05:22,300 --> 00:05:24,000
It really was a growth investment.

84
00:05:24,090 --> 00:05:26,140
You can read all the specific details about it.

85
00:05:26,580 --> 00:05:28,360
I would just recommend going and looking at that.

86
00:05:29,260 --> 00:05:33,460
Yeah, I mean, do you mind covering what a growth investment is?

87
00:05:34,280 --> 00:05:38,460
Because some people hear VC and they go, well, so are they still going to be open source?

88
00:05:38,830 --> 00:05:41,240
Do they still have decision-making authority, et cetera?

89
00:05:41,520 --> 00:05:43,480
So what does that mean for a regular person?

90
00:05:43,510 --> 00:05:44,760
Yeah, so a growth investing.

91
00:05:45,490 --> 00:05:47,340
So again, like I'm not on the board.

92
00:05:47,350 --> 00:05:49,780
I don't understand like all the inner workings about this.

93
00:05:49,790 --> 00:05:54,540
But a growth investment doesn't preclude any additional or any sort of control.

94
00:05:55,160 --> 00:05:57,840
It really is like, hey, here's money, make it better type of thing.

95
00:05:58,000 --> 00:06:04,360
So again, those details are posted online and is the right language to make sure I don't say anything that's not correct.

96
00:06:05,460 --> 00:06:09,540
Is the general idea that it's an investor that goes, hey, here's money.

97
00:06:09,620 --> 00:06:11,260
they're just expecting a return on investment

98
00:06:11,560 --> 00:06:14,420
while you just build the company the way you want it.

99
00:06:15,560 --> 00:06:17,440
That's probably a more accurate way to say it, yeah.

100
00:06:18,240 --> 00:06:20,340
So with the open source side of things,

101
00:06:21,340 --> 00:06:23,420
I want to start by just, you know,

102
00:06:23,460 --> 00:06:25,200
if someone's new and they're learning about Bitwarden,

103
00:06:25,260 --> 00:06:27,920
I know our community is very much into the open source world,

104
00:06:27,980 --> 00:06:30,460
so I don't need to really tout too much of the benefits there for them.

105
00:06:30,700 --> 00:06:32,640
But if someone's new and they're listening to this,

106
00:06:33,620 --> 00:06:34,940
especially in the password manager,

107
00:06:35,460 --> 00:06:37,360
what is the benefit of being open source

108
00:06:37,680 --> 00:06:39,260
compared to maybe not being open source?

109
00:06:39,280 --> 00:06:43,680
There's a plethora of non-open source password managers out there that are typically recommended.

110
00:06:43,880 --> 00:06:45,560
But what do you think that really provides?

111
00:06:45,960 --> 00:06:50,440
Yeah, let's talk about a closed source, proprietary source, whatever you want to call it.

112
00:06:50,760 --> 00:06:58,440
People who prefer or decide to go with a closed source model, they like the idea of security through obscurity.

113
00:06:59,140 --> 00:07:00,560
That is, there's like a veil.

114
00:07:00,800 --> 00:07:02,920
Nobody knows how things are working in the background.

115
00:07:03,040 --> 00:07:10,940
And so because of that, they believe that it's going to be more difficult for hackers to find any vulnerabilities to get in and break the product.

116
00:07:11,300 --> 00:07:14,720
We'd like to say like hope is not a strategy, but that's really what it comes down to.

117
00:07:14,800 --> 00:07:18,440
They're just hoping that somebody doesn't find a vulnerability and take advantage of it.

118
00:07:19,320 --> 00:07:24,920
With open source, we have the transparency of having all of the Bitwarden source code posted on GitHub.

119
00:07:25,480 --> 00:07:31,860
Any of your users right now can go to github.com slash Bitwarden and see the code that's currently in development.

120
00:07:32,070 --> 00:07:34,980
For one, if anyone wants to kind of scoop us on some of our product announcements.

121
00:07:36,040 --> 00:07:41,440
And two, like there's an entire huge security community that loves to go around and poke around the code and see stuff.

122
00:07:42,040 --> 00:07:48,400
And with 50,000 people or more, like with eyes on Bitwarden code, there is no obscurity.

123
00:07:48,870 --> 00:07:52,820
Any vulnerability is found and rapidly solved and fixed.

124
00:07:53,260 --> 00:07:54,960
People can submit PRs for it.

125
00:07:55,140 --> 00:07:56,980
We also do a third-party audits and everything.

126
00:07:57,260 --> 00:07:59,360
So what would you trust more?

127
00:07:59,560 --> 00:08:02,060
Somebody who's like, oh, trust us, we're good.

128
00:08:02,680 --> 00:08:05,840
Or another company that says, you don't have to trust us.

129
00:08:06,420 --> 00:08:07,760
Here's how everything works.

130
00:08:08,640 --> 00:08:12,760
And that's really like the gist of open source trust and open source security.

131
00:08:14,060 --> 00:08:14,220
Nice.

132
00:08:14,320 --> 00:08:18,660
And then I guess a typical follow-up question I have when people are open source is, you know,

133
00:08:18,680 --> 00:08:23,860
I'm not going through and personally diving into the code myself for all the open source software that I use back here.

134
00:08:24,400 --> 00:08:30,220
So do you guys do maybe audits, consistent audits that will audit the code and make sure there's no obvious issues?

135
00:08:31,000 --> 00:08:31,580
Yeah, absolutely.

136
00:08:31,800 --> 00:08:34,840
Like not only do we do our internal audits, we have the community audits.

137
00:08:35,260 --> 00:08:37,200
We also have third party audits as well.

138
00:08:37,719 --> 00:08:38,240
Cure 53.

139
00:08:39,080 --> 00:08:42,240
We also have bug bounties as well through Hacker 1 too.

140
00:08:42,530 --> 00:08:45,220
So we always have those reports coming in.

141
00:08:45,460 --> 00:08:48,560
You can actually see everything disclosed on our website.

142
00:08:49,140 --> 00:08:51,160
Bitwarren.com slash compliance has a bunch.

143
00:08:52,000 --> 00:08:54,520
Then if you do a search for audits or secure reports,

144
00:08:54,860 --> 00:08:57,560
you'll see every year's report that comes through.

145
00:08:58,110 --> 00:09:00,280
All the testing, all the work that's been done to solve

146
00:09:01,240 --> 00:09:03,080
anything that's been flagged as a potential issue.

147
00:09:03,800 --> 00:09:07,260
And are those your, you said there's internal audits,

148
00:09:07,560 --> 00:09:09,460
there's community audits, and external audits.

149
00:09:09,580 --> 00:09:12,060
So I think the most familiar one to a lot of people

150
00:09:12,150 --> 00:09:13,840
might be the external ones like Cure53.

151
00:09:14,240 --> 00:09:15,220
Mulvad VPN does those.

152
00:09:15,260 --> 00:09:18,320
A lot of other security and privacy organizations do these audits.

153
00:09:19,200 --> 00:09:21,820
But can you explain the community and the internal ones that you guys do?

154
00:09:22,160 --> 00:09:24,040
And if people can kind of see those?

155
00:09:24,680 --> 00:09:29,680
Yeah, so the community audits, again, those are just people going through on the GitHub and looking at code.

156
00:09:30,000 --> 00:09:37,180
And just hobbyists, security enthusiasts who are trying to make sure that they can trust the solution that they're using.

157
00:09:37,500 --> 00:09:40,300
And then we also have our bug bounty program through HackerOne.

158
00:09:40,760 --> 00:09:44,120
We actually recently wrote a blog post about that program.

159
00:09:44,760 --> 00:09:48,460
And you can see more details there, including links to the HackerOne program.

160
00:09:49,140 --> 00:09:53,260
And these are people who will try to attempt to find bugs inside of Bitward and inside the code.

161
00:09:54,580 --> 00:10:08,620
When somebody is putting together a group of people that put together, I don't know, some sort of community pen test or group like that, we're happy to oblige by providing subscriptions, test subscriptions, so they can try and see what they can find.

162
00:10:08,840 --> 00:10:09,100
Cool.

163
00:10:09,520 --> 00:10:14,800
And the other kind of layer to this is forking the code.

164
00:10:15,260 --> 00:10:17,380
I think another foreign concept is, you know,

165
00:10:17,500 --> 00:10:19,700
someone can just take your code and duplicate it

166
00:10:19,720 --> 00:10:21,300
and then spin up a similar service.

167
00:10:21,500 --> 00:10:23,440
Is this something that you guys are concerned about,

168
00:10:23,660 --> 00:10:24,300
Bitwarden clones,

169
00:10:25,620 --> 00:10:28,260
or something that could be a threat to a business or an individual?

170
00:10:28,620 --> 00:10:31,600
Or do you see that as just kind of a natural part of the open source world?

171
00:10:32,140 --> 00:10:33,780
Yeah, that's just something that comes with open source.

172
00:10:34,320 --> 00:10:35,920
We support the open source community.

173
00:10:37,080 --> 00:10:45,160
There is a community tool that a lot of folks use right now for self-hosting that is built in Rust from some forked Bitwarden code.

174
00:10:46,940 --> 00:10:49,120
And it's compatible with the Bitwarden clients.

175
00:10:49,380 --> 00:10:52,120
And we're friends with those folks.

176
00:10:52,440 --> 00:10:55,640
We made a couple of requests that they change their branding and all that.

177
00:10:55,800 --> 00:11:00,200
But we support the open source community in what they do.

178
00:11:00,300 --> 00:11:07,260
And it's also a really good, you know, some people will say like, well, what happens if like a meteor strikes and Bitwarden is wiped off the face of the earth?

179
00:11:07,380 --> 00:11:07,860
What's going to happen?

180
00:11:08,500 --> 00:11:15,100
Well, hopefully it doesn't take off all the GitHub servers at the same time, too, because then people could just, you know, grab the code and like continue on the service as it goes on.

181
00:11:15,960 --> 00:11:16,440
Yeah, nice.

182
00:11:17,020 --> 00:11:19,640
And I guess another question, you guys have a pretty large team.

183
00:11:19,830 --> 00:11:22,680
So my assumption here is that it's mostly internal.

184
00:11:23,360 --> 00:11:28,680
But do you have a general idea or percentage of community driven versus internal development?

185
00:11:29,080 --> 00:11:33,160
Like, do you get any massive work ever done by a community member on your source code?

186
00:11:33,660 --> 00:11:39,440
Sometimes community members will put together something really amazing that will bring in that has a huge impact.

187
00:11:40,100 --> 00:11:43,380
One of the ones that came in from a community that is off the top of my head that I know.

188
00:11:43,440 --> 00:11:44,720
So I don't deal with the code every day.

189
00:11:44,760 --> 00:11:51,220
But I remember one was a new KDF algorithm called Argon2ID or Argon2.

190
00:11:51,460 --> 00:11:52,760
People might be familiar with that.

191
00:11:52,880 --> 00:12:02,160
Until this community member created this PR, this code commit for Argon2, we didn't really have it on our roadmap.

192
00:12:02,340 --> 00:12:04,760
And now it becomes like a big touted thing.

193
00:12:04,820 --> 00:12:05,880
Like, hey, look at this.

194
00:12:06,100 --> 00:12:14,020
Bitwarren supports Argon2, which is a memory-hardened version of the KDF algorithm that people can choose as an option if they like.

195
00:12:15,000 --> 00:12:15,100
Great.

196
00:12:15,500 --> 00:12:19,240
And then I'm going to talk a little bit more soon about the privacy and security architecture.

197
00:12:19,260 --> 00:12:21,420
We can dive a little more into the weeds there.

198
00:12:21,640 --> 00:12:29,400
But on the topic of self-hosting, before we get there, do you generally recommend people stick with the hosted version of Bitwarden?

199
00:12:29,630 --> 00:12:32,080
Are there pros and cons to people who want to self-host?

200
00:12:32,190 --> 00:12:34,060
Who do you typically recommend that option to?

201
00:12:34,600 --> 00:12:42,740
Yeah, so mostly for self-hosting, we recommend it to enthusiasts who really want to self-host and have concerns about data sovereignty.

202
00:12:43,800 --> 00:12:48,880
Maybe people who want to put some extra security on it that they control, such as a reverse proxy, firewalls,

203
00:12:49,600 --> 00:12:51,480
VPN requirements for their servers.

204
00:12:52,060 --> 00:12:55,260
This sort of thing is usually for people who have like advanced technical knowledge.

205
00:12:55,940 --> 00:12:59,940
And in particular, they also understand what it takes to back up a server.

206
00:13:00,460 --> 00:13:06,700
Because if you have everything on your own, say NAS or even some of the less complex folks

207
00:13:06,780 --> 00:13:13,380
might have, you know, just like running on a Raspberry Pi or on their home computer,

208
00:13:13,660 --> 00:13:19,160
you know, sometimes there's uptime is your responsibility at that point, right?

209
00:13:19,360 --> 00:13:20,920
Backup is your responsibility.

210
00:13:21,880 --> 00:13:32,160
So for the people who are really interested in self-hosting Bitwarden, especially for some of our business customers, one of the first questions we ask to qualify them is, have you ever self-hosted anything else?

211
00:13:33,480 --> 00:13:40,520
That's usually a really good clue of whether or not somebody might actually have the technical know-how or capabilities to do such a thing.

212
00:13:41,180 --> 00:13:47,320
I have some friends personally who's like, oh, I have my NAS server, my own photo upload system set up.

213
00:13:47,400 --> 00:13:50,020
and the NAS is hooked up to a UPS

214
00:13:50,320 --> 00:13:52,720
and got extra failover with another buddy's NAS.

215
00:13:53,240 --> 00:13:55,320
Yeah, okay, self-hosting might be for you.

216
00:13:55,510 --> 00:13:58,500
But we include the cloud hosting for free.

217
00:13:59,060 --> 00:14:00,720
That's kind of the best way to think about it.

218
00:14:00,750 --> 00:14:02,580
It's like Bitwarden self-host is free

219
00:14:02,650 --> 00:14:03,880
and so is the cloud hosting, right?

220
00:14:04,340 --> 00:14:07,640
So the cloud hosting is probably best for most people.

221
00:14:09,120 --> 00:14:09,300
Got it.

222
00:14:09,310 --> 00:14:11,340
And then the last question before we dive

223
00:14:11,720 --> 00:14:13,260
a little more into the privacy and security here,

224
00:14:13,560 --> 00:14:14,120
the UI UX.

225
00:14:14,720 --> 00:14:17,360
So my understanding is that you guys used

226
00:14:17,380 --> 00:14:20,140
some kind of cross-platform code base,

227
00:14:21,140 --> 00:14:23,720
and you've been slowly migrating to more native apps.

228
00:14:23,960 --> 00:14:26,500
If not, you already have migrated to some more native apps.

229
00:14:26,720 --> 00:14:28,860
So what's kind of the thought process behind that,

230
00:14:28,930 --> 00:14:30,320
and where are you in that journey?

231
00:14:30,960 --> 00:14:32,960
It might be something that might be worth getting our architect on for.

232
00:14:33,420 --> 00:14:35,220
I do know a couple of things about this.

233
00:14:35,300 --> 00:14:37,640
So first, we did recently, and by recently,

234
00:14:37,650 --> 00:14:39,640
I mean in the last year and a half or so,

235
00:14:39,820 --> 00:14:42,700
migrate all of our mobile applications to native code.

236
00:14:42,810 --> 00:14:46,400
That would be Swift for iOS, and that'd be Kotlin for Android.

237
00:14:46,660 --> 00:14:49,660
And that was a big adjustment that we had to do internally

238
00:14:49,680 --> 00:14:52,260
because we were moving everybody off of Maui,

239
00:14:52,480 --> 00:14:54,160
which was the language that we were using before that.

240
00:14:54,920 --> 00:14:57,800
And then there's also been some additional movement

241
00:14:58,080 --> 00:14:59,480
on updating our desktop application.

242
00:15:00,460 --> 00:15:03,380
But that sort of thing is still in progress and being investigated.

243
00:15:04,660 --> 00:15:04,720
Cool.

244
00:15:04,960 --> 00:15:09,120
Have you guys been able to roll out any new features as a result of this?

245
00:15:09,440 --> 00:15:11,340
Have you been able to do more system integrations

246
00:15:11,400 --> 00:15:12,660
as a result of the native rewrite?

247
00:15:13,280 --> 00:15:13,900
Yeah, actually.

248
00:15:14,380 --> 00:15:15,600
We had a fun one come out.

249
00:15:16,040 --> 00:15:19,580
Actually, both in the same month towards the middle of last year.

250
00:15:20,540 --> 00:15:25,800
On Android now, you can do what's called responsive colors or reactive colors.

251
00:15:26,380 --> 00:15:28,960
It's part of the Google Material You thing.

252
00:15:29,560 --> 00:15:36,900
So if you wanted to set it up, you can have your entire vault be recolored to match your background on your phone, which is fun for some things.

253
00:15:37,020 --> 00:15:40,020
And then we also have on iOS, we have some Siri integration.

254
00:15:40,760 --> 00:15:44,580
So you could ask Siri to do things like Siri lock my vault or Siri log me out.

255
00:15:45,980 --> 00:15:48,360
You know, just fun little things like that.

256
00:15:49,000 --> 00:15:49,300
Nice.

257
00:15:49,620 --> 00:15:50,580
Yeah, no, it's always nice.

258
00:15:50,760 --> 00:15:52,820
That's like the benefit, I think, of moving to native apps.

259
00:15:53,060 --> 00:15:53,960
I'm personally excited.

260
00:15:54,100 --> 00:15:57,760
When I tried Bitwarden a couple years ago, you guys didn't have native apps yet.

261
00:15:57,820 --> 00:15:59,020
And that was one of my big things.

262
00:15:59,120 --> 00:16:01,560
I'm like, oh, it'd be really cool to have a native app for Bitwarden.

263
00:16:01,720 --> 00:16:03,940
So I should go ahead and download it again to try out the app now.

264
00:16:03,940 --> 00:16:04,880
Yeah, give us another shot.

265
00:16:04,980 --> 00:16:07,000
I think you'll like what you see.

266
00:16:07,060 --> 00:16:12,020
There's also been a few redesigns since then of our extension as well, the web app.

267
00:16:12,120 --> 00:16:18,340
And then also we have a design team who's working really hard to get some really good unification going.

268
00:16:18,920 --> 00:16:25,080
I think you're going to see some pretty big improvements to UI and UX in the next little bit too.

269
00:16:25,720 --> 00:16:25,900
Nice.

270
00:16:26,200 --> 00:16:26,660
That's exciting.

271
00:16:26,920 --> 00:16:28,060
So privacy and security.

272
00:16:28,230 --> 00:16:30,620
I kind of want to start with the general concept first here.

273
00:16:31,200 --> 00:16:36,080
Because anytime I cover password managers on this channel, I think we have our audience.

274
00:16:36,210 --> 00:16:37,460
We have the intermediate users.

275
00:16:37,620 --> 00:16:41,880
but I feel like true beginners, people who have never heard of this concept before,

276
00:16:43,000 --> 00:16:45,280
their first fear is, oh, this sounds scary.

277
00:16:45,470 --> 00:16:46,300
This doesn't sound safe.

278
00:16:46,740 --> 00:16:48,460
I'm putting all of my eggs in one basket.

279
00:16:48,960 --> 00:16:55,020
So can you just kind of start off by talking about why is a password manager more secure?

280
00:16:55,350 --> 00:16:58,040
And when it's maybe not more secure for a regular user,

281
00:16:58,240 --> 00:17:01,540
so people just understand why this is a useful tool in the first place.

282
00:17:03,120 --> 00:17:07,439
Oh boy, let me give you the whole pitch here for why people even need a password manager.

283
00:17:07,540 --> 00:17:12,760
So I think the first thing, let's think about, I mean, shoot, I don't even know.

284
00:17:12,920 --> 00:17:14,520
What was the latest breach we've heard about?

285
00:17:14,640 --> 00:17:15,839
There's so many, right?

286
00:17:16,480 --> 00:17:18,699
I can pull up my RSS feed if you want.

287
00:17:19,560 --> 00:17:19,920
Let's see.

288
00:17:21,060 --> 00:17:26,420
We had PayPal to breach exposed user data for six months, social security numbers, and unauthorized charges.

289
00:17:26,920 --> 00:17:27,400
That's a big one.

290
00:17:28,079 --> 00:17:28,840
That's a big one.

291
00:17:29,340 --> 00:17:29,560
Yeah.

292
00:17:30,080 --> 00:17:30,220
Yeah.

293
00:17:30,840 --> 00:17:31,060
Anyway.

294
00:17:31,120 --> 00:17:34,420
French Bank Registry, 1.2 million accounts.

295
00:17:36,320 --> 00:17:37,380
Mississippi Medical Center.

296
00:17:38,460 --> 00:17:38,580
Yeah.

297
00:17:39,300 --> 00:17:39,520
Anyway.

298
00:17:40,559 --> 00:17:42,960
Anyway, all these sites have had breaches, right?

299
00:17:43,740 --> 00:17:50,020
And so there's a lot of people out there, like myself included, before I even first joined Bitwarden, where I was like, oh, I have my own system for a password.

300
00:17:50,700 --> 00:17:54,040
I use my same email address that I use or username for everywhere else.

301
00:17:54,380 --> 00:17:58,480
Shoot, sometimes I use like my AIM screen name that I created like in the late 90s, right?

302
00:17:58,560 --> 00:18:06,440
And then I would, you know, have some prefix, whatever I was logging into, what was about, say, insurance, and then a suffix.

303
00:18:06,720 --> 00:18:07,660
Like, okay, I got it.

304
00:18:07,710 --> 00:18:09,520
I can guess my password if I ever need to.

305
00:18:09,820 --> 00:18:11,340
And that worked for a certain amount of time.

306
00:18:11,430 --> 00:18:15,860
But, you know, you start getting a lot of breaches, breach here, breach there, breach there.

307
00:18:15,990 --> 00:18:18,840
And then suddenly people are able to, like, cross-reference databases.

308
00:18:19,210 --> 00:18:23,140
Like, hey, look, this username and this password was breached here.

309
00:18:23,420 --> 00:18:25,360
This username had this password here.

310
00:18:25,450 --> 00:18:26,460
Oh, look, there's a pattern.

311
00:18:26,840 --> 00:18:29,300
Let me see if I can try and log it everywhere else.

312
00:18:29,350 --> 00:18:37,280
And there's also such things called, they're called rainbow tables or compilations of the most commonly used or known passwords that have been created by humans.

313
00:18:37,940 --> 00:18:49,320
And what some people will do, especially if they can get an offline copy of some data, is that they will just try your username and then millions and millions and millions and millions of passwords that exist out there.

314
00:18:49,430 --> 00:18:50,640
And then maybe they'll get a hit.

315
00:18:50,820 --> 00:18:53,780
Like maybe, oh, shoot, maybe you used admin Minda.

316
00:18:54,240 --> 00:18:58,020
Like that's a very common combination or password one, two, three.

317
00:18:58,420 --> 00:19:03,480
Or if something gets leaked, like, you know, people always have to rotate passwords commonly.

318
00:19:04,120 --> 00:19:06,260
They might have their password, whatever password.

319
00:19:06,650 --> 00:19:09,160
And then we'll say one at the end of it.

320
00:19:09,250 --> 00:19:11,100
Oh, I have to rotate it after so many months.

321
00:19:11,280 --> 00:19:11,920
It'll be two.

322
00:19:12,230 --> 00:19:13,360
And then they have to rotate it again.

323
00:19:13,780 --> 00:19:20,380
So what happens is that, well, the hackers will start going like, okay, well, I'll set this algorithm up that will attempt to log in with this breached password.

324
00:19:20,900 --> 00:19:22,500
And then, oh, it ended with a one.

325
00:19:22,880 --> 00:19:25,520
Well, let me try logging in with a two at the end.

326
00:19:25,780 --> 00:19:26,340
Oh, guess what?

327
00:19:26,420 --> 00:19:27,080
We just got in.

328
00:19:27,500 --> 00:19:29,840
And so these are called credential stuffing attacks.

329
00:19:30,320 --> 00:19:33,360
And they're probably the biggest threat that you see out there.

330
00:19:33,480 --> 00:19:38,640
Basically, people will have botnets that can just attempt to log into your account.

331
00:19:38,640 --> 00:19:44,920
And they are attempting to log into your account hundreds and hundreds of times a second with passwords that have leaked out on the Internet,

332
00:19:45,960 --> 00:19:50,580
including ones that you might have already, if you're especially bad, if you're someone who reused a password anywhere.

333
00:19:50,820 --> 00:19:56,020
So if you reused a password, say, I don't know, like even let's go back in the day if you wanted to break something out.

334
00:19:56,050 --> 00:19:58,760
Let's say you had a Neopets password that was like really strong.

335
00:19:59,200 --> 00:20:02,340
Right. And then that got leaked, which I think happened like several times.

336
00:20:02,460 --> 00:20:04,900
But you use the same password on your bank account.

337
00:20:05,480 --> 00:20:07,280
Right. Like they're going to try that.

338
00:20:07,700 --> 00:20:08,960
These people are going to do that.

339
00:20:08,970 --> 00:20:11,480
And they're just they just have algorithms and programs that are doing that.

340
00:20:11,620 --> 00:20:14,420
So why is a password manager important?

341
00:20:16,100 --> 00:20:20,280
I don't know any of my passwords because they're all machine generated.

342
00:20:20,400 --> 00:20:23,580
They're all 18, 20 digits long of just random strings.

343
00:20:23,830 --> 00:20:27,000
I have no idea how to log into my investment accounts.

344
00:20:27,100 --> 00:20:29,180
I have no idea how to log into my bank account.

345
00:20:29,250 --> 00:20:33,640
I can't even log into my insurance account, like I had mentioned before, because I don't

346
00:20:33,640 --> 00:20:34,240
know those passwords.

347
00:20:34,410 --> 00:20:35,700
I don't need to know those passwords.

348
00:20:35,860 --> 00:20:37,540
The password manager takes care of all of that for me.

349
00:20:37,720 --> 00:20:40,460
All I need to know is the master password for logging in.

350
00:20:41,980 --> 00:20:42,200
Got it.

351
00:20:42,400 --> 00:20:50,360
And later, I have a whole section dedicated to the eggs in one basket argument, because

352
00:20:51,000 --> 00:20:55,740
what you suggest users do, how you can maybe make Bitwarden even more secure to help protect

353
00:20:55,800 --> 00:20:59,900
against these things. So I want to touch on that later. But before we get there, so I think that's

354
00:20:59,900 --> 00:21:04,200
a pretty understandable use case because a lot of people either like forget their passwords and it's

355
00:21:04,220 --> 00:21:07,580
annoying to have to reset your password every time you lock into a service you created three years

356
00:21:07,640 --> 00:21:12,480
ago. So it makes a lot of sense. But nowadays, you know, you have a browser password managers built

357
00:21:12,540 --> 00:21:19,120
in to browsers. And also some people just keep local notes. So can you maybe speak to why still

358
00:21:19,140 --> 00:21:23,880
a dedicated password manager might be useful compared to those tools or where maybe some of

359
00:21:23,880 --> 00:21:29,880
those other tools might be okay for a user? Yeah. So a dedicated password manager, especially one

360
00:21:29,940 --> 00:21:35,960
that's cloud-based like Bitwarden, pretty much you can gain access to your password from any device

361
00:21:36,180 --> 00:21:41,200
that you need to. So this is especially handy if you're traveling or if you lose your phone and you

362
00:21:41,260 --> 00:21:46,340
need to log in on a friend's phone. This way you can just like have cross-device syncing. I mean,

363
00:21:46,460 --> 00:21:47,620
You seem to be a techie.

364
00:21:47,620 --> 00:21:48,920
How many devices do you own?

365
00:21:49,300 --> 00:21:52,780
It's complicated because there's like review devices for the channel.

366
00:21:53,080 --> 00:21:53,820
There's my devices.

367
00:21:54,280 --> 00:21:56,700
There's there's like the NAS that sits behind me.

368
00:21:56,840 --> 00:21:58,460
So it's pretty all over the place.

369
00:21:58,580 --> 00:22:02,240
You have a lot of devices, probably all running different operating systems.

370
00:22:02,560 --> 00:22:02,700
Right.

371
00:22:03,080 --> 00:22:04,580
So it's especially handy.

372
00:22:04,580 --> 00:22:06,080
I actually just recently replaced my phone.

373
00:22:06,080 --> 00:22:11,800
I was using a really old, an older Samsung like S21 and then FE like fan edition.

374
00:22:12,140 --> 00:22:15,700
I don't really prioritizing having like the newest and the greatest phones.

375
00:22:16,040 --> 00:22:20,420
Samsung released an over-the-air update that broke my SIM card.

376
00:22:21,240 --> 00:22:24,180
My phone could not connect to anything at all.

377
00:22:24,640 --> 00:22:27,180
And so I had to run out that day to go and buy a new phone.

378
00:22:27,400 --> 00:22:28,860
First thing I install, Bitwarden.

379
00:22:29,160 --> 00:22:31,100
Like I can just log into every service, no problem.

380
00:22:31,280 --> 00:22:37,660
It's so, so, so easy, especially if you're ever like reformatting computers, getting a new computer.

381
00:22:38,080 --> 00:22:42,120
It's very handy that way to have something that's cross-platform and cloud-synced.

382
00:22:43,360 --> 00:23:08,040
Yeah, what I like to do in my password manager is I have a folder label tag, you know, whatever the system the password manager uses for a new device setup. So there's probably like, you know, your email client, whatever you use to sync browser bookmarks, etc. There's probably like a set list of accounts that you want to set up consistently anytime you update a device or you get a new device in your workflow. And for me, that was a big help for this exact thing.

383
00:23:08,320 --> 00:23:12,120
So kind of the next question I have here is the cloud.

384
00:23:12,330 --> 00:23:15,160
I feel like people are rightfully skeptical of the cloud.

385
00:23:16,620 --> 00:23:20,240
It's not your computer is kind of what it is.

386
00:23:20,300 --> 00:23:21,160
It's not a cloud either.

387
00:23:21,360 --> 00:23:22,320
It's someone else's computer.

388
00:23:22,790 --> 00:23:24,460
Like all of these kind of phrases exist.

389
00:23:24,650 --> 00:23:29,180
And so when you think of storing your passwords on somebody else's computer, that's a pretty intimidating concept.

390
00:23:29,640 --> 00:23:35,100
When you put it this way, even I get a little creeped out, even though I understand fundamentally what's going on.

391
00:23:35,440 --> 00:23:44,900
So can you maybe speak to zero knowledge and then encryption, what that looks like, what it guarantees, what it doesn't, kind of the threat modeling process behind that?

392
00:23:45,760 --> 00:23:52,980
Yeah, absolutely. And, you know, this is also something that I was first nervous about when I had first learned about password managers at all.

393
00:23:53,200 --> 00:23:58,380
I remember hearing about one that had taken the market by storm back in 2009.

394
00:23:59,580 --> 00:24:04,280
And I was like, why would you trust something like this? This doesn't make any sense for that.

395
00:24:05,000 --> 00:24:07,980
This is before you had hundreds and hundreds and hundreds of accounts, right?

396
00:24:07,990 --> 00:24:09,060
It was like, oh, I have five.

397
00:24:09,130 --> 00:24:10,500
I can just remember everything I need.

398
00:24:10,860 --> 00:24:12,840
So the really important part about this process

399
00:24:13,210 --> 00:24:14,900
was what's called end-to-end encryption.

400
00:24:15,260 --> 00:24:17,340
For people who aren't very familiar with cryptography,

401
00:24:17,690 --> 00:24:18,320
you actually are.

402
00:24:18,480 --> 00:24:21,300
You're just not familiar with the modern term of it.

403
00:24:21,460 --> 00:24:24,900
So A equals 1, B equals 2, C equals 3,

404
00:24:25,190 --> 00:24:28,080
and then you just write a code as you pass as a note to somebody.

405
00:24:28,520 --> 00:24:29,140
That's encryption.

406
00:24:29,480 --> 00:24:31,100
It's way more complicated than that these days

407
00:24:31,370 --> 00:24:33,320
because A equals 1, B equals 2 is something

408
00:24:33,340 --> 00:24:35,020
that someone could crack in half a nanosecond.

409
00:24:35,170 --> 00:24:37,700
And instead, there's a lot of mathematical cryptography

410
00:24:37,980 --> 00:24:41,080
that goes into making sure that something is encrypted

411
00:24:41,490 --> 00:24:43,360
in a way that nobody else can read it

412
00:24:43,600 --> 00:24:45,180
except for the person who has the key.

413
00:24:46,200 --> 00:24:49,360
And when you work with an application

414
00:24:49,520 --> 00:24:50,380
that's end-to-end encrypted,

415
00:24:50,780 --> 00:24:52,640
and you can confirm that Bitware is end-to-end encrypted

416
00:24:52,740 --> 00:24:53,540
because it's open source,

417
00:24:53,660 --> 00:24:54,940
you can see how all the clients work.

418
00:24:55,200 --> 00:24:58,520
The file that has all of your passwords in it

419
00:24:59,220 --> 00:25:01,900
is encrypted on your device.

420
00:25:02,320 --> 00:25:06,980
So on your computer or on your phone before it gets sent to the cloud.

421
00:25:08,000 --> 00:25:09,780
And that's where it stays in storage.

422
00:25:10,000 --> 00:25:11,040
It goes in the cloud storage.

423
00:25:11,280 --> 00:25:15,380
There's extra layers of encryption that goes on top of it to make sure that it's absolutely 100% secure.

424
00:25:16,420 --> 00:25:25,260
And then when you log in later, that encrypted thing comes out of storage and gets sent to your phone or your laptop or your computer.

425
00:25:25,420 --> 00:25:29,580
And then you enter in the key to unlock it.

426
00:25:30,000 --> 00:25:33,700
And then it unlocks and decrypts again on your device.

427
00:25:34,320 --> 00:25:38,480
And there's nothing that gets sent back and forth that's not encrypted in your vault.

428
00:25:38,860 --> 00:25:39,200
Perfect.

429
00:25:39,580 --> 00:25:41,020
So you mentioned earlier Argon2.

430
00:25:41,660 --> 00:25:48,020
Do you mind expanding where that fits into this picture and how and where that gives people a bit more protection?

431
00:25:48,740 --> 00:25:48,940
Yeah.

432
00:25:49,200 --> 00:25:52,000
So this is where things get a little complicated.

433
00:25:52,300 --> 00:25:53,400
Thinking about how deep to go.

434
00:25:55,000 --> 00:25:55,140
Okay.

435
00:25:55,660 --> 00:25:56,940
Let's go all the way down.

436
00:25:57,140 --> 00:25:58,100
We're going to go all the way down.

437
00:25:58,720 --> 00:26:04,280
So when you enter in your master password, that's not actually the key that unlocks your vault.

438
00:26:05,380 --> 00:26:07,080
And you can read all this in the Bitwarden white paper.

439
00:26:07,340 --> 00:26:08,160
It's all posted online.

440
00:26:08,530 --> 00:26:10,360
You can just check everything on the security white paper.

441
00:26:10,780 --> 00:26:23,760
But when you enter in your master password, it gets seeded with an account seed that's also based off of your username and then becomes stretched out into a really long random code.

442
00:26:24,320 --> 00:26:29,340
But it's not completely random because it's determinant, right?

443
00:26:29,900 --> 00:26:33,040
So it just gets stretched out into a really long code that's suitable for using encryption.

444
00:26:33,690 --> 00:26:42,400
And then that is used to unlock an even bigger code that's actually what's used for decrypting your vault.

445
00:26:42,570 --> 00:26:46,680
And so your vault is actually stored with this really, really big key.

446
00:26:47,100 --> 00:26:50,000
Now, the way to get to the key that unlocks the bigger key,

447
00:26:50,340 --> 00:26:53,480
first you have to go through what's called the KDF algorithm,

448
00:26:54,200 --> 00:27:00,360
That's key derivation function. And what happens is that it's imagine like a giant,

449
00:27:01,220 --> 00:27:06,860
long mathematical formula, right? You enter in the first number, and then it goes through the

450
00:27:07,120 --> 00:27:12,020
formula, and then it spits out a different number. That's considered one iteration. So when you enter

451
00:27:12,080 --> 00:27:16,440
your master password, and then it gets rushed out into a key, then into the first key, and then it

452
00:27:16,480 --> 00:27:22,600
goes through the KDF algorithm, it spits out a different key. By default, we use pbkdf2. And by

453
00:27:22,620 --> 00:27:27,480
default, that's set to 600,000 times. So I said, you have to put it, you grab it, it goes through,

454
00:27:27,790 --> 00:27:32,520
and then you take that result, you feed it back into the algorithm, and you do it again, and then

455
00:27:32,520 --> 00:27:38,920
you do it again, and then you do it again, 600,000 times. And the point of that is to be a speed bump

456
00:27:39,180 --> 00:27:43,760
for people who are trying to just guess your password, right? So it's intentional slowdown.

457
00:27:44,200 --> 00:27:48,680
That's an intentional slowdown. So it takes a lot of resources to do it. And if you think about how

458
00:27:48,820 --> 00:27:52,580
many guesses somebody would have to do to get to your correct password, if they don't know anything

459
00:27:52,580 --> 00:27:58,560
is a lot, right? So after 600,000 times running through this on the default key derivation function,

460
00:27:59,070 --> 00:28:04,200
then you get at what's called the master key that can then unlock your vault.

461
00:28:05,180 --> 00:28:12,940
Now, Argon2ID uses things in a different way. Instead of going from taking the result and

462
00:28:13,260 --> 00:28:21,679
dropping it back, taking the result again, that's a very processor intensive function and could be a

463
00:28:21,700 --> 00:28:27,300
little bit weaker to GPU attacks. So that'd be somebody who's using like, imagine like Bitcoin

464
00:28:27,560 --> 00:28:32,020
miners, right, who have hundreds and hundreds and hundreds of graphics cards that are just running

465
00:28:32,400 --> 00:28:36,580
because they have a lot of cores. And so they're able to run this process a lot more efficiently,

466
00:28:36,760 --> 00:28:43,740
a lot more quickly. Now, Argon2ID, the way that works is that it requires basically filling up

467
00:28:43,840 --> 00:28:51,120
memory every time that it runs an algorithm. And so it really slows things down because

468
00:28:52,100 --> 00:28:57,260
these days your graphics cards are probably more constrained by the available VRAM

469
00:28:57,720 --> 00:29:04,120
than they are by processing cores. And so that just, somebody who is trying to guess rapidly

470
00:29:04,980 --> 00:29:11,259
would quickly fill up all their VRAM and then crash your system. So it constrains how quickly

471
00:29:11,280 --> 00:29:13,640
they can make guesses significantly that way.

472
00:29:14,460 --> 00:29:14,920
Does that make sense?

473
00:29:15,400 --> 00:29:15,960
Perfect, yeah.

474
00:29:17,040 --> 00:29:21,640
You mentioned earlier on that there was some kind of key generation

475
00:29:21,910 --> 00:29:22,560
based on the username.

476
00:29:23,440 --> 00:29:23,900
Is that?

477
00:29:24,680 --> 00:29:26,640
Yes, so that's currently how it is.

478
00:29:26,720 --> 00:29:29,000
There is some work being done so that username can be changed

479
00:29:29,240 --> 00:29:31,320
without affecting the encryption.

480
00:29:32,580 --> 00:29:35,300
So anybody looking at the code right now would be able to see that

481
00:29:35,500 --> 00:29:36,820
that work is being done.

482
00:29:37,260 --> 00:29:39,660
So right now if you can't change your username or if you do,

483
00:29:39,750 --> 00:29:40,680
then something changes?

484
00:29:41,080 --> 00:29:46,260
If you were to change your username in a way that we do it right now, it would generate a new key.

485
00:29:47,020 --> 00:29:48,220
You do that through the security tab.

486
00:29:48,600 --> 00:29:49,300
No problem.

487
00:29:49,420 --> 00:29:50,200
You can still change it.

488
00:29:50,460 --> 00:29:57,620
It becomes a little bit more complicated in businesses when they're using SSO login and then somebody needs to change their email address.

489
00:29:57,760 --> 00:30:00,200
For example, they got married and they want to change their last name.

490
00:30:00,980 --> 00:30:02,640
It becomes a little bit more complicated that way.

491
00:30:02,760 --> 00:30:04,340
So I'm trying to make it a little bit more modular.

492
00:30:05,240 --> 00:30:05,460
Got it.

493
00:30:05,620 --> 00:30:11,900
And does that mean that, I know this is so like not really a part of it, but technically,

494
00:30:12,160 --> 00:30:17,200
does that mean that the username you choose has like the most tiny difference in the security

495
00:30:17,320 --> 00:30:18,160
of the rest of the system?

496
00:30:18,340 --> 00:30:23,880
Or does the rest of the system kind of supersede any kind of tiny benefit there?

497
00:30:24,440 --> 00:30:26,320
Right now, it's just basically used a little bit as a salt.

498
00:30:27,600 --> 00:30:27,700
Okay.

499
00:30:27,880 --> 00:30:30,700
You can, again, you can look up to see exactly how it works.

500
00:30:31,360 --> 00:30:33,340
We're a little bit over my head here.

501
00:30:33,880 --> 00:30:50,360
But yes, so that's also why, too, if somebody were to do a vault export, if they choose like what's called an account-specific export, and then you try to import again later under a different email address, that won't work because it requires the way the seeding works.

502
00:30:50,640 --> 00:30:59,080
So if you were to ever need to restart everything and you did an account-specific export, a backup won't work into a new account because that's account-specific.

503
00:31:00,060 --> 00:31:00,620
Got it. Interesting.

504
00:31:00,940 --> 00:31:02,960
Now, I want to talk about them.

505
00:31:03,220 --> 00:31:04,780
This is going to be a whole section as well.

506
00:31:05,240 --> 00:31:07,160
But for now, it's relevant here.

507
00:31:07,250 --> 00:31:11,080
In the last pass data breach that happened where vaults were leaked,

508
00:31:11,680 --> 00:31:12,760
something that was interesting to me,

509
00:31:12,760 --> 00:31:14,700
and I never quite got a good answer about this,

510
00:31:15,020 --> 00:31:19,540
it sounded like some fields in the last pass vaults weren't encrypted at all.

511
00:31:21,540 --> 00:31:23,000
So what happened there,

512
00:31:24,670 --> 00:31:28,760
because to me, when I first started getting the password management,

513
00:31:28,880 --> 00:31:30,820
I'm also going to ask you about keypass in a second here.

514
00:31:31,180 --> 00:31:33,320
KeePass is quite literally the way you define it.

515
00:31:33,320 --> 00:31:35,520
Like you have a KeePass database vault.

516
00:31:36,070 --> 00:31:41,320
And theoretically, it's easy for me to understand this single file is encrypted and then uploaded.

517
00:31:42,240 --> 00:31:54,860
But based on the LastPass data breach, it sounds like it's not as much of a single file that's encrypted and more of like a dynamic, very complicated vault with various types of encryption, unless LastPass does something weird.

518
00:31:55,010 --> 00:32:00,140
So can you maybe speak to Bitwarden and how it might differ from what LastPass does?

519
00:32:00,320 --> 00:32:06,020
Is everything in Bitward encrypted completely or are there specific things that are not end-to-end encrypted?

520
00:32:06,420 --> 00:32:07,380
Yeah, you can see this.

521
00:32:07,380 --> 00:32:08,460
We have this documented on our website.

522
00:32:08,680 --> 00:32:14,240
So first, let's start by talking about the LastPass breach and what happened there.

523
00:32:14,440 --> 00:32:25,380
So that was a very complex attack that was not a result of any encryption-based breaches.

524
00:32:25,710 --> 00:32:26,160
Does that make sense?

525
00:32:26,500 --> 00:32:28,780
It was an operational breach.

526
00:32:29,560 --> 00:32:35,160
So there was something that was not secured properly in their day-to-day operations.

527
00:32:36,030 --> 00:32:42,580
And a very targeted attack was able to breach that and get this set of encrypted data out.

528
00:32:43,520 --> 00:32:46,420
Now, there was a couple of problems with this encrypted data.

529
00:32:46,950 --> 00:32:51,700
The first one is what you mentioned, that not everything in the vaults was encrypted.

530
00:32:52,400 --> 00:32:57,200
And this was something that, you know, here at Bitwarden, we had kind of raised as flags for a long time.

531
00:32:57,360 --> 00:33:00,480
is, you know, they actually actually had a link.

532
00:33:00,560 --> 00:33:01,700
It doesn't exist any longer,

533
00:33:01,740 --> 00:33:04,440
but there was a link to the help documentation that said,

534
00:33:05,020 --> 00:33:08,320
yes, URLs for items are not encrypted.

535
00:33:08,800 --> 00:33:13,400
And we do this to ensure that we can provide you a better service

536
00:33:13,780 --> 00:33:18,040
and also serve icons to your fault.

537
00:33:18,340 --> 00:33:22,519
But what ended up happening is that hackers who had all of this data

538
00:33:23,020 --> 00:33:30,500
we're able to find like the the login like the URIs universal resource indicator which is a

539
00:33:30,510 --> 00:33:34,460
little bit more than just a link right which is like a URL and we're able to find like really

540
00:33:34,750 --> 00:33:40,220
specific ones and then target all of their cracking capabilities into those and this would be

541
00:33:41,180 --> 00:33:45,160
crypto wallets for example somebody could be like oh this is the address for a crypto wallet

542
00:33:45,890 --> 00:33:51,199
let me dedicate all of my time to cracking this and like sucking up the eight or nine bitcoin that

543
00:33:51,220 --> 00:33:55,340
was in that wallet. It's still happening too. There's articles that they're still draining

544
00:33:55,640 --> 00:34:00,720
wallets to this day probably due to that. As people are, yeah, as people, yeah, it's crazy

545
00:34:00,790 --> 00:34:04,720
because it's still taking a while, which is also like a testament to some of the encryption because

546
00:34:04,750 --> 00:34:09,220
it's been years now and it's still going through and they're targeting very specific, very specific

547
00:34:09,419 --> 00:34:14,860
accounts to do so. Additionally too, LastPass had a little bit of a failure in the KDF algorithm

548
00:34:15,159 --> 00:34:20,820
that I had mentioned. I said Bitwarden's default is 600,000, right? Back when LastPass first started,

549
00:34:20,879 --> 00:34:29,840
their default was one. And then they upgraded it to 10. And then 100. And any account that was over

550
00:34:30,040 --> 00:34:36,159
10 years, they didn't do any forced upgrade to the new KDF algorithm, because some of that requires,

551
00:34:36,679 --> 00:34:40,560
you know, manual intervention, depending on how the system works. And, you know, because you have

552
00:34:40,560 --> 00:34:46,679
to enter your password to like undo everything and redo everything all over again. So some people were

553
00:34:46,740 --> 00:34:52,460
having all these crypto wallets that were exposed and only protected by a hundred cycles of this KDF

554
00:34:52,679 --> 00:34:59,440
algorithm. So it was just trivial for someone just to set like a cracking machine onto some of these

555
00:34:59,660 --> 00:35:05,460
vaults just to crack them open and get what they wanted. So this KDF algo, first off, has it always

556
00:35:05,620 --> 00:35:09,560
been 600,000 for you guys or has it upgraded over time as well? It's upgraded over time.

557
00:35:10,320 --> 00:35:16,660
And we're actually implementing some work to allow people to make adjustments without having

558
00:35:16,680 --> 00:35:19,700
any additional inputs to, or logouts.

559
00:35:19,960 --> 00:35:21,540
So it's still being hardened.

560
00:35:22,220 --> 00:35:24,420
- Got it, and I assume for a regular end user,

561
00:35:24,940 --> 00:35:27,520
someone might go, "Why not just blast it to the max?"

562
00:35:27,540 --> 00:35:29,180
And I assume it's because it's gonna take a lot longer

563
00:35:29,760 --> 00:35:31,280
for your system to unlock the vault

564
00:35:31,440 --> 00:35:32,520
each time you type in the password.

565
00:35:32,800 --> 00:35:33,360
- That's right.

566
00:35:34,099 --> 00:35:36,780
People have tried on modern devices to go up to a million.

567
00:35:36,920 --> 00:35:37,860
We'll let you do whatever you want.

568
00:35:37,860 --> 00:35:40,380
You can go to the settings to do a million iterations

569
00:35:40,730 --> 00:35:42,800
or whatever, and some people would report,

570
00:35:43,080 --> 00:35:44,760
"Oh yeah, it took six seconds to log in."

571
00:35:44,780 --> 00:35:49,420
You know, it's like, whatever, that's fine to get some additional security on it.

572
00:35:49,590 --> 00:35:57,080
But 600,000 right now is the recommended amount of iterations based on NIST, which is the National Institute for Security and Technology.

573
00:35:57,300 --> 00:35:58,840
So that's where that is.

574
00:35:59,780 --> 00:36:03,600
And is the reason why this is adaptive over time is because computers get more powerful.

575
00:36:03,810 --> 00:36:11,460
And so that your local device becomes more capable and has an easier time with a larger amount as well as an attacker.

576
00:36:11,690 --> 00:36:13,040
So you need to keep bumping it up.

577
00:36:13,140 --> 00:36:15,800
And it's overall going to always take the same amount of time to unlock.

578
00:36:16,520 --> 00:36:16,900
That's right.

579
00:36:16,910 --> 00:36:18,360
Yeah, it's a constant arms race.

580
00:36:19,100 --> 00:36:19,340
Got it.

581
00:36:19,700 --> 00:36:19,800
Perfect.

582
00:36:20,660 --> 00:36:27,000
And we always have to balance, you know, like usability with the likelihood of there being issues.

583
00:36:27,820 --> 00:36:28,460
Is it adaptive?

584
00:36:28,690 --> 00:36:34,680
Do you do like a test when someone opens Bitwarden for the first time to test how powerful their machine is and then pick an algorithm based on that?

585
00:36:35,060 --> 00:36:35,740
No, we don't do that.

586
00:36:35,990 --> 00:36:39,140
Some people might not like it if we're tracking their machine, right?

587
00:36:39,580 --> 00:36:39,780
Yeah.

588
00:36:40,880 --> 00:36:42,760
I feel like it could be done locally somehow.

589
00:36:43,280 --> 00:36:49,640
like if someone opens it and it just does a quick CPU stress test for like five seconds and sees how

590
00:36:49,640 --> 00:36:55,720
the CPU responds and then automatically sets like a recommended algo that is that's a very interesting

591
00:36:55,910 --> 00:37:00,920
idea I like the idea there's only one challenge here and that is the KDF algorithm is universal

592
00:37:01,030 --> 00:37:06,720
across every machine so you could be running on your like super powerful gaming rig right

593
00:37:07,280 --> 00:37:12,000
or you could be running on your dinky little laptop from 10 years ago or raspberry pi it would have to

594
00:37:12,020 --> 00:37:14,180
have to go through the same level of algorithms.

595
00:37:14,480 --> 00:37:15,820
So probably not.

596
00:37:16,460 --> 00:37:16,700
Got it.

597
00:37:17,020 --> 00:37:17,360
Interesting, though.

598
00:37:17,530 --> 00:37:19,140
Just to clarify, what can Bitwarden see?

599
00:37:19,330 --> 00:37:23,540
If I register for a Bitwarden account right now, I move all my passwords to it.

600
00:37:24,160 --> 00:37:27,700
Can you see my email to log in?

601
00:37:28,120 --> 00:37:29,860
Can you see anything inside the vault?

602
00:37:30,320 --> 00:37:31,300
What can you see on your end?

603
00:37:31,880 --> 00:37:34,340
Let's say you just wanted to leave the company.

604
00:37:34,560 --> 00:37:35,860
You're mad and it's an insider threat.

605
00:37:36,060 --> 00:37:38,980
And your goal is to find my vault before you leave.

606
00:37:39,500 --> 00:37:41,600
What could you find if you really wanted to find me?

607
00:37:41,880 --> 00:38:04,560
All right. So there's a couple of couple of things here is going to get into some fun stuff. So first, you can see whatever is collected and necessary on bitwarden.com slash privacy. Like everything is clearly stated, what's encrypted and what isn't. What's not encrypted is your login email address, right? Because we need to be able to see who we're giving the vault to, right?

608
00:38:05,080 --> 00:38:11,720
So that's something that is kind of important to bring up here is that security and privacy often go hand in hand.

609
00:38:12,480 --> 00:38:17,300
But it's important to remember that Bitwarden is a security company, and that's what we focus on is security.

610
00:38:18,000 --> 00:38:24,280
And our services require that we have some data about you, like how to deliver you your vault from the cloud.

611
00:38:25,000 --> 00:38:29,800
That's a little bit difficult to do if we don't know who or what it's going to, if that makes sense.

612
00:38:30,160 --> 00:38:30,460
Got it.

613
00:38:30,510 --> 00:38:32,420
And so other than that, because the email makes sense.

614
00:38:32,640 --> 00:38:34,180
Yeah, so there are a couple of things.

615
00:38:34,620 --> 00:38:37,040
So here's a really fun experiment you can do.

616
00:38:37,880 --> 00:38:40,400
If you download the Bitwarden desktop application,

617
00:38:40,660 --> 00:38:45,480
you can log into your vault, right, and download it and get it on your machine.

618
00:38:46,380 --> 00:38:51,400
And then you can lock your vault without a pin code, right?

619
00:38:51,560 --> 00:38:53,060
But if you lock your vault with the master password,

620
00:38:53,700 --> 00:38:55,320
you can then actually go onto your computer,

621
00:38:55,760 --> 00:38:59,840
find the vault blob in the data folder, and just open it up in Notepad.

622
00:39:00,480 --> 00:39:03,780
And everything you see there is, that's it.

623
00:39:03,880 --> 00:39:06,620
That's all that Bitwarden could see if we opened up your vault in the cloud too.

624
00:39:07,720 --> 00:39:08,640
So that's it.

625
00:39:08,820 --> 00:39:10,960
Yeah, it's pretty straightforward that way.

626
00:39:12,080 --> 00:39:12,320
Got it.

627
00:39:12,360 --> 00:39:14,080
And then how about, I assume, billing?

628
00:39:14,700 --> 00:39:16,020
There is some visibility there as well.

629
00:39:16,460 --> 00:39:16,760
Absolutely.

630
00:39:17,620 --> 00:39:18,620
And subprocessors too.

631
00:39:18,760 --> 00:39:19,760
So Bitwarden uses Stripe.

632
00:39:20,440 --> 00:39:21,840
So there will be some pass-through for there.

633
00:39:21,880 --> 00:39:26,460
And again, all that's available at bitwarden.com slash privacy for all the extreme finer details.

634
00:39:27,620 --> 00:39:27,780
Yeah.

635
00:39:27,860 --> 00:39:31,540
Do you guys support any cryptocurrency payments if someone wants to avoid fiat?

636
00:39:31,940 --> 00:39:32,080
Yeah.

637
00:39:32,240 --> 00:39:37,140
For people who want to pay with Bitcoin, we offer services through BitPay as our processor for that.

638
00:39:37,500 --> 00:39:37,900
Very nice.

639
00:39:38,130 --> 00:39:39,800
And then I guess kind of a final question.

640
00:39:39,960 --> 00:39:43,780
I mean, it's not as relevant if it's end-end encrypted and you're working with small files.

641
00:39:44,600 --> 00:39:46,220
But where do you guys host your data?

642
00:39:47,240 --> 00:39:50,880
So BitWord data is hosted on Microsoft Azure servers in the United States.

643
00:39:51,050 --> 00:39:53,160
It's hosted on the East Coast, on the East Coast servers.

644
00:39:54,100 --> 00:39:58,600
And then we also have a EU option that's hosted in Ireland and the Netherlands.

645
00:39:59,960 --> 00:40:00,180
Got it.

646
00:40:00,320 --> 00:40:03,840
And then if one of those servers comes down, you guys lose access to data,

647
00:40:04,600 --> 00:40:07,180
DF backups, is data stored across multiple?

648
00:40:07,720 --> 00:40:12,600
Yeah, everything is stored by Azure and the Azure point in time processes for those.

649
00:40:13,640 --> 00:40:13,880
Got it.

650
00:40:14,310 --> 00:40:16,180
Okay, and then kind of the last privacy and security question,

651
00:40:16,360 --> 00:40:18,060
this section was a lot longer than I expected.

652
00:40:18,340 --> 00:40:22,700
But in a really critical situation, let's say you get a government subpoena

653
00:40:23,320 --> 00:40:26,520
and it's like, hey, we have this email address for a user

654
00:40:27,030 --> 00:40:28,560
and we want to investigate this user.

655
00:40:28,850 --> 00:40:30,100
I guess what can you hand over?

656
00:40:30,380 --> 00:40:34,480
as Bitwarden and what kind of ways are you forced to have to comply and what can you do?

657
00:40:35,460 --> 00:40:39,180
And also, what kind of policies do you have on like challenging these court orders when they

658
00:40:39,220 --> 00:40:42,020
come up? And do you guys have any kind of like transparency around this?

659
00:40:43,540 --> 00:40:48,060
This is something that, interestingly, I haven't been asked about before, so I'm not exactly the

660
00:40:48,180 --> 00:40:53,200
most knowledgeable on it. I'm sure it's somewhere in our privacy policy, but I do know that no one

661
00:40:53,200 --> 00:41:00,140
will get anything useful besides like the administrative data that I talked about. Like

662
00:41:00,660 --> 00:41:05,120
the strength of at minimum your master password. So like there's, there's, there's, there's that,

663
00:41:05,320 --> 00:41:11,020
like that's not going to be of any use to anyone. Got it. The eggs in one basket argument is

664
00:41:11,120 --> 00:41:16,140
something I want to dive into a little bit because I can make the same arguments to people that you

665
00:41:16,280 --> 00:41:20,700
did. I think a lot of people understand the whole idea of having a central place that generates

666
00:41:20,820 --> 00:41:24,680
unique, strong passwords for you. But then now you're stuck with the situation where, oh my gosh,

667
00:41:24,740 --> 00:41:27,300
if I lose access to this one thing

668
00:41:27,660 --> 00:41:29,960
or if someone I know breaks into this one thing.

669
00:41:29,990 --> 00:41:31,920
Now they have access to all of my passwords

670
00:41:32,560 --> 00:41:35,200
instead of maybe they'd have to guess each one

671
00:41:35,310 --> 00:41:36,120
for all of my accounts

672
00:41:36,230 --> 00:41:38,800
if I was using these semi-random passwords

673
00:41:38,950 --> 00:41:40,700
that added a one or two at the end of them.

674
00:41:41,620 --> 00:41:44,300
So what do you guys kind of suggest to users

675
00:41:44,530 --> 00:41:45,720
who are thinking about this?

676
00:41:45,960 --> 00:41:48,200
And do you think it's a valid concern?

677
00:41:48,860 --> 00:41:50,500
Yeah, it's absolutely a valid concern.

678
00:41:50,650 --> 00:41:51,540
And it really just comes down

679
00:41:51,700 --> 00:41:53,300
to what somebody's preferences are

680
00:41:53,340 --> 00:41:56,100
when you're trying to balance security and convenience, right?

681
00:41:56,760 --> 00:42:02,380
So, for example, our first recommendation to anyone about password managers at all is use a password manager.

682
00:42:02,520 --> 00:42:03,780
We don't care which, just use one.

683
00:42:03,900 --> 00:42:06,140
Like that's going to be way more secure than not using one at all.

684
00:42:06,800 --> 00:42:09,320
That you have random generated passwords for every account.

685
00:42:10,200 --> 00:42:15,840
Now, obviously, like it's best to store all that in easiest to store everything in one place at a password management service.

686
00:42:16,220 --> 00:42:20,000
But then you also want to make sure that any website that supports two-factor authentication,

687
00:42:20,660 --> 00:42:25,520
multi-factor authentication, anything like that, you want to make sure that you have that enabled

688
00:42:25,680 --> 00:42:29,740
too. Now, there's a lot of debate in the community about like, well, should I have my two-factor

689
00:42:29,860 --> 00:42:34,580
authentication be integrated into BitWord? Yeah, I know that's what you're going to ask.

690
00:42:34,580 --> 00:42:39,720
We get this all the time. Yeah, people ask it all the time. And I absolutely get it. What's nice

691
00:42:39,900 --> 00:42:43,940
about having the two-factor authentication in your account, in your BitWord account, for example,

692
00:42:44,040 --> 00:42:49,319
is that it just makes it really convenient for people to, you know, enter the password and then

693
00:42:49,340 --> 00:42:54,500
paste the TOTP code. And we find that if something is convenient, people are more likely to use it

694
00:42:54,620 --> 00:42:59,740
and therefore increase their security. And when you're using something like that, that improves

695
00:42:59,760 --> 00:43:04,120
your security against, like I mentioned before, a rainbow table attack, credential stuffing attack.

696
00:43:04,820 --> 00:43:08,740
It basically acts like a second password. You know, that's essentially not guessable,

697
00:43:09,540 --> 00:43:14,040
which is, you know, very handy. But then some people will say, well, what if somebody got

698
00:43:14,100 --> 00:43:18,360
into my Bitwarden account? Then I wouldn't have any way to prevent that. Well, the answer is make

699
00:43:18,380 --> 00:43:21,620
Make sure you have two-factor authentication on your Bitwarden account too and practice

700
00:43:21,840 --> 00:43:24,540
good operational security.

701
00:43:25,280 --> 00:43:30,360
Make sure your vault locks or logs out at the right time.

702
00:43:31,260 --> 00:43:32,340
Use a strong master password.

703
00:43:32,820 --> 00:43:34,220
Use two-factor authentication.

704
00:43:35,480 --> 00:43:38,560
Be sure that you're not in a logout loop.

705
00:43:38,940 --> 00:43:44,080
For example, if you get logged out of your email address and then you have email 2FA set

706
00:43:44,100 --> 00:43:49,340
up that you won't be able to get into your Bitwarden account because we can't turn it off.

707
00:43:49,620 --> 00:43:54,540
There's no way to turn it off. So yeah, it really just comes down to how you want to do it and what

708
00:43:54,680 --> 00:44:00,500
makes the most sense for you. Yeah. You guys released Bitwarden's own TOTP app, but it's

709
00:44:00,720 --> 00:44:06,120
offline only. It doesn't sync via the cloud still, or did you? No, you can set it up to sync if you

710
00:44:06,300 --> 00:44:11,220
choose. Some people just want it to be easier. For example, you can sync things over and then

711
00:44:11,240 --> 00:44:15,940
disconnect the sync and then delete your seeds if you wanted to, just to just to make things a little

712
00:44:15,960 --> 00:44:21,560
bit easier and separate. But yeah, the Tootp app is created, you know, as an alternative to the

713
00:44:21,600 --> 00:44:26,480
built in authenticator and it's free. So I don't know if you're aware, but like the the integrated

714
00:44:26,700 --> 00:44:31,500
authenticator is a premium feature, right? And if you don't have or pay for premium because Bitwarden

715
00:44:31,500 --> 00:44:35,080
offers a fully feature free plan, then you don't need to use the integrated authenticator because

716
00:44:35,100 --> 00:44:38,520
is you can also use the also free Bitward and TOTP app.

717
00:44:38,940 --> 00:44:41,400
So you have all your options,

718
00:44:41,680 --> 00:44:43,320
everything you need to be secure online right there.

719
00:44:43,700 --> 00:44:47,400
Yeah, the one thing that I kind of also say,

720
00:44:48,020 --> 00:44:49,880
because again, I get asked about this TOTP thing

721
00:44:49,900 --> 00:44:50,640
all the time as well.

722
00:44:50,980 --> 00:44:53,560
And for me, the TOTP, the main issue,

723
00:44:53,580 --> 00:44:56,060
I feel like it prevents is a situation

724
00:44:56,460 --> 00:44:58,920
where your data gets leaked without your knowledge

725
00:44:59,240 --> 00:45:00,080
or something like this.

726
00:45:00,220 --> 00:45:03,100
Like an account login, username, password gets leaked.

727
00:45:03,280 --> 00:45:05,140
on some dark web forum.

728
00:45:05,420 --> 00:45:07,260
They find it, they try to log in with it.

729
00:45:07,420 --> 00:45:10,560
And no matter where your TOTP keys are stored,

730
00:45:10,860 --> 00:45:11,580
you're safe.

731
00:45:11,920 --> 00:45:13,940
Like that's ultimately, to me,

732
00:45:13,980 --> 00:45:15,760
the best thing that TOTP offers users

733
00:45:15,960 --> 00:45:18,120
is that second source of protection.

734
00:45:18,580 --> 00:45:20,580
And then I feel like it's more of a high level threat

735
00:45:20,780 --> 00:45:22,380
to be considering what if someone hacks

736
00:45:22,440 --> 00:45:23,720
into my password manager database,

737
00:45:23,880 --> 00:45:25,160
which would be incredibly hard to do.

738
00:45:25,580 --> 00:45:27,960
So that's typically what I've kind of defaulted to

739
00:45:28,120 --> 00:45:29,220
as a general option.

740
00:45:29,280 --> 00:45:32,120
I don't know if you have any feelings about that.

741
00:45:33,140 --> 00:45:34,860
No. Again, it all comes down to personal preference.

742
00:45:35,640 --> 00:45:36,600
Some people like to have the convenience.

743
00:45:36,780 --> 00:45:38,320
Other people, you know, they don't.

744
00:45:39,140 --> 00:45:39,240
Yeah.

745
00:45:39,660 --> 00:45:41,980
I have some that are half and half, personally.

746
00:45:42,460 --> 00:45:43,980
You know, some inside Bitward and some not.

747
00:45:44,780 --> 00:45:47,840
But it's really convenient for sharing things, right?

748
00:45:48,300 --> 00:45:51,160
So, for example, like I share passwords with my partner.

749
00:45:52,119 --> 00:45:54,580
And, you know, you want to have that two-factor authentication,

750
00:45:55,779 --> 00:45:57,940
but it makes it really difficult, you know,

751
00:45:58,160 --> 00:45:59,800
like you don't want to get a text message and be like,

752
00:45:59,900 --> 00:46:02,180
hey, can you send me the code in the next 30 seconds?

753
00:46:02,480 --> 00:46:03,400
But at least this way you can share.

754
00:46:03,520 --> 00:46:05,680
It's also important for business applications too

755
00:46:05,880 --> 00:46:06,940
that might require TOTP.

756
00:46:07,620 --> 00:46:09,940
And you don't want to try and get a hold of Bob

757
00:46:10,160 --> 00:46:12,540
who's on vacation and try to get into his email address

758
00:46:13,019 --> 00:46:15,640
to get the actual authentication code to log in.

759
00:46:15,860 --> 00:46:18,580
So that's another aspect of it too

760
00:46:18,700 --> 00:46:20,640
is that you can share the TOTP codes.

761
00:46:21,220 --> 00:46:22,140
Yeah, very good point.

762
00:46:22,220 --> 00:46:23,840
And I have a hybrid solution as well.

763
00:46:24,200 --> 00:46:26,080
I guess I haven't really shared that publicly at all

764
00:46:26,270 --> 00:46:27,380
because no one's really asked about it

765
00:46:27,480 --> 00:46:29,100
because it's always an all or nothing, should I do it?

766
00:46:29,220 --> 00:46:33,500
But lately, I've always had a dedicated TOTP app,

767
00:46:33,500 --> 00:46:35,220
and I never really stored them in the password manager.

768
00:46:35,580 --> 00:46:37,860
But I've been getting really frustrated with the whole,

769
00:46:38,010 --> 00:46:40,080
like, oh, I'm just trying to log into a service and get something done.

770
00:46:40,600 --> 00:46:43,140
But my phone is in the other room because my phone is rarely on me.

771
00:46:43,490 --> 00:46:47,200
And so I have to go grab my phone, log into it, get my TOTP stuff.

772
00:46:47,430 --> 00:46:50,760
But anyway, I've set up a hybrid situation as well,

773
00:46:50,960 --> 00:46:53,940
where for me, it's based on high security accounts.

774
00:46:54,160 --> 00:46:56,360
So things like my email, my bank accounts, etc.

775
00:46:56,620 --> 00:46:59,060
are still stored on a separate app.

776
00:46:59,440 --> 00:47:02,320
And then I have just kind of like, okay, this is fine.

777
00:47:02,660 --> 00:47:06,380
If someone ever got into this, it's not a huge deal inside of the password manager.

778
00:47:06,440 --> 00:47:08,700
So that's been a good hybrid for me to balance the two.

779
00:47:09,460 --> 00:47:09,760
That's great.

780
00:47:10,020 --> 00:47:12,640
TOTP is also just one form of two-factor authentication.

781
00:47:12,920 --> 00:47:17,680
So for Bitwarden, you can have email, TOTP code, but also passkey.

782
00:47:18,600 --> 00:47:22,300
So you can use the WebAuthn FIDO2 passkey,

783
00:47:22,440 --> 00:47:25,120
and in particular hardware security keys like a YubiKey.

784
00:47:25,980 --> 00:47:27,200
That's personally what I have too.

785
00:47:27,280 --> 00:47:30,580
I've got one in my wallet that I keep around with me all the time that's also protected by a pin.

786
00:47:31,280 --> 00:47:33,400
So there's a lot of ways you can stay secure.

787
00:47:34,400 --> 00:47:34,600
Got it.

788
00:47:34,870 --> 00:47:36,240
Yeah, no, I love my YubiKey too.

789
00:47:36,500 --> 00:47:38,500
That's my password manager access as well.

790
00:47:38,620 --> 00:47:44,240
Do you guys use it as only a passkey or can you enable it to be your 2FA method?

791
00:47:45,600 --> 00:47:46,080
So both.

792
00:47:46,270 --> 00:47:50,480
You can use it to log in with a passkey or you could also use the passkey as a 2FA method.

793
00:47:51,140 --> 00:47:51,340
Perfect.

794
00:47:51,760 --> 00:47:55,380
And logging in with the passkey is pretty handy for a lot of people.

795
00:47:55,480 --> 00:47:59,860
So passkey is still in development in terms of the standard.

796
00:47:59,940 --> 00:48:07,560
The standard is out there, but sometimes you'll find that your browser might argue with you on who should be managing the passkey first,

797
00:48:07,680 --> 00:48:09,660
and then your operating system will pop into you.

798
00:48:10,640 --> 00:48:12,300
Yeah, I deal with this.

799
00:48:12,700 --> 00:48:13,340
You see it happen.

800
00:48:14,000 --> 00:48:21,260
Yeah, I try to log in, and I didn't mean to click log in with passkey, so then it prompts my extension password manager.

801
00:48:21,320 --> 00:48:22,100
I say no.

802
00:48:22,620 --> 00:48:23,580
It prompts my browser.

803
00:48:23,680 --> 00:48:24,360
I say no.

804
00:48:24,600 --> 00:48:26,680
but then it prompts my operating system, I say no.

805
00:48:26,900 --> 00:48:28,800
And then it gives like the weird errors.

806
00:48:29,220 --> 00:48:30,420
And then it like, ah.

807
00:48:30,980 --> 00:48:31,700
- Yeah, don't worry.

808
00:48:31,840 --> 00:48:34,360
Like we're actually, we're working with Microsoft,

809
00:48:34,640 --> 00:48:35,300
we're working with Apple.

810
00:48:36,180 --> 00:48:37,340
You know, you might've heard about

811
00:48:37,340 --> 00:48:38,580
the credential exchange protocol,

812
00:48:38,900 --> 00:48:40,420
which is something that an industry group

813
00:48:40,440 --> 00:48:41,640
that Bitwarden has been a part of

814
00:48:41,720 --> 00:48:43,800
that makes it easy to transfer pass keys

815
00:48:43,860 --> 00:48:44,640
from service to service.

816
00:48:44,980 --> 00:48:48,660
It's still an evolving and a very promising form of security.

817
00:48:49,000 --> 00:48:51,400
Just need to work on making it a little bit more user-friendly

818
00:48:51,940 --> 00:48:53,940
and have people agree on the best way

819
00:48:53,960 --> 00:48:56,400
that things should work and what it should look like.

820
00:48:56,660 --> 00:48:57,020
Cool.

821
00:48:57,540 --> 00:48:59,140
I'm kind of down to the last few things here.

822
00:48:59,900 --> 00:49:01,540
So first, I want to ask you,

823
00:49:02,040 --> 00:49:02,820
well, actually before that,

824
00:49:02,860 --> 00:49:03,860
I want to ask you about your setup.

825
00:49:04,000 --> 00:49:05,560
But before, I did want to quickly just ask,

826
00:49:05,640 --> 00:49:06,860
this is something I like to ask,

827
00:49:07,760 --> 00:49:10,080
the open source projects that have enterprise and community.

828
00:49:10,720 --> 00:49:14,020
Do you guys ever stumble on kind of a conflict

829
00:49:14,860 --> 00:49:17,680
of which customer base to prioritize

830
00:49:17,960 --> 00:49:18,880
when you're rolling out a feature?

831
00:49:19,040 --> 00:49:21,020
Are you like, hey, we want to roll out this feature,

832
00:49:21,240 --> 00:49:23,400
but it would be really bad for the enterprise,

833
00:49:23,900 --> 00:49:27,720
enterprise customers, but it'll be really good for our community and vice versa. And like,

834
00:49:27,720 --> 00:49:29,700
how do you guys grapple with that and decide who to prioritize?

835
00:49:30,100 --> 00:49:35,820
It's always a balance. But, you know, some of our best features for administrators came from

836
00:49:35,940 --> 00:49:40,060
the community. Like one of the big community requests that we had early on was emergency access.

837
00:49:40,530 --> 00:49:44,920
And that was setting up a way for someone to access your account if you're incapacitated.

838
00:49:45,340 --> 00:49:50,299
Right. I just, you know, as long as you have the premium feature enabled, any other Bitwarden user

839
00:49:50,320 --> 00:49:52,160
you could set up as your emergency access.

840
00:49:52,460 --> 00:49:55,640
And from that code came a level of key exchange

841
00:49:56,040 --> 00:49:56,640
with another user.

842
00:49:57,460 --> 00:50:00,540
And that blossomed into basically

843
00:50:00,880 --> 00:50:03,120
our account recovery process for enterprise.

844
00:50:04,220 --> 00:50:06,400
So there's all these features that are actually,

845
00:50:06,860 --> 00:50:08,340
you know, maybe under the hood.

846
00:50:08,740 --> 00:50:10,780
I mean, maybe on the surface, not related,

847
00:50:10,920 --> 00:50:11,800
but under the hood, they are.

848
00:50:11,860 --> 00:50:13,100
Like you get that code together.

849
00:50:13,180 --> 00:50:15,120
So one can absolutely benefit the other.

850
00:50:16,840 --> 00:50:17,240
Very nice.

851
00:50:17,620 --> 00:50:19,620
And then what's kind of your personal setup

852
00:50:19,640 --> 00:50:21,160
with your password managers?

853
00:50:21,920 --> 00:50:24,060
If, you know, you only have to share as much as you want.

854
00:50:24,320 --> 00:50:26,120
Yeah, I'll share some information.

855
00:50:26,420 --> 00:50:29,280
So one of the things that a lot of people aren't aware of

856
00:50:29,300 --> 00:50:30,580
is what's called plus address email.

857
00:50:31,040 --> 00:50:32,640
So when you create your Bitwarden account

858
00:50:33,240 --> 00:50:35,080
or any other password manager account

859
00:50:35,460 --> 00:50:37,980
and you have a email provider that supports plus address,

860
00:50:38,260 --> 00:50:40,280
that is your email address,

861
00:50:40,660 --> 00:50:42,660
then plus, like the literal plus sign,

862
00:50:43,120 --> 00:50:46,040
and then anything else at whatever.com,

863
00:50:47,000 --> 00:50:47,980
it just still goes to your inbox.

864
00:50:48,860 --> 00:50:54,940
So I would highly recommend that people create a plus address, a unique plus address email

865
00:50:55,720 --> 00:51:01,020
for your login password for your login account and then set up a strong master password and all that.

866
00:51:01,160 --> 00:51:06,460
And what's nice about that is that, you know, like if you're sure your email got leaked,

867
00:51:06,800 --> 00:51:09,980
but not your plus address email. Right. And it's still going to the same account.

868
00:51:09,980 --> 00:51:14,960
You don't have to worry about it. And then I would make sure that you absolutely make sure

869
00:51:14,980 --> 00:51:19,140
that you maintain strong access to your email account if necessary.

870
00:51:19,560 --> 00:51:22,180
So especially if you have like email T-O-2-P codes,

871
00:51:22,500 --> 00:51:24,720
my email provider I secure with my YubiKey

872
00:51:24,980 --> 00:51:26,100
and I remember the password.

873
00:51:26,560 --> 00:51:29,280
So that's like one of the two passwords I remember, right,

874
00:51:29,480 --> 00:51:32,700
is my password for Bitwarden and my password for my email,

875
00:51:33,280 --> 00:51:35,100
and both of which are secured by the YubiKey

876
00:51:35,150 --> 00:51:36,560
and the YubiKey secured with a PIN.

877
00:51:37,280 --> 00:51:40,900
So you have to know a couple of things to get into my account.

878
00:51:41,260 --> 00:51:41,700
Does that make sense?

879
00:51:42,240 --> 00:51:42,940
Yeah, it's very nice.

880
00:51:43,140 --> 00:51:50,860
I assume, I mean, I doubt that you're doing any kind of like large scale analysis here, but a lot of our audience is probably using simple login or like Addy IO.

881
00:51:51,260 --> 00:51:55,580
So I assume the aliasing registration is going to offer a pretty similar thing.

882
00:51:56,380 --> 00:51:57,460
Yeah, I do.

883
00:51:57,670 --> 00:52:07,800
I would recommend, though, that if you ever lose access to your to your aliasing service, like might also be good to have that secured separately as well.

884
00:52:08,540 --> 00:52:15,160
But perhaps the most important thing, and a lot of people forget about this, is making sure that you have everything in a security preparedness kit.

885
00:52:15,410 --> 00:52:22,060
Like write down all the information you need, including a recovery code when you create your two-factor authentication to log into Bitward.

886
00:52:22,180 --> 00:52:25,160
You'll be presented with a recovery code that will disable 2FA.

887
00:52:25,490 --> 00:52:27,000
Write that down. Print it out.

888
00:52:27,270 --> 00:52:29,180
Like put that on a physical piece of paper.

889
00:52:29,720 --> 00:52:32,700
We have a security readiness kit on our website.

890
00:52:33,140 --> 00:52:34,280
It's a template that I put together.

891
00:52:34,720 --> 00:52:35,600
A lot of people love it.

892
00:52:35,960 --> 00:52:36,740
I use it myself.

893
00:52:36,940 --> 00:52:41,640
I've got my stuff written down, like handwritten and put into a safe.

894
00:52:42,200 --> 00:52:48,040
So like that's if you ever find yourself in a situation in which you did lose memory or

895
00:52:48,270 --> 00:52:51,460
access to something or someone else needs to access something for you, they can still

896
00:52:51,620 --> 00:52:54,300
get that piece of paper and log in.

897
00:52:54,580 --> 00:52:57,800
And someone would have to break into my house, go through my vault and know what they're

898
00:52:57,900 --> 00:53:01,700
looking at to, you know, actually compromise that, if that makes sense.

899
00:53:02,540 --> 00:53:03,660
Yeah, no, it very much does.

900
00:53:03,840 --> 00:53:09,740
And it's not something people think about, but I had a family member passing, you know, like three to six months ago.

901
00:53:10,460 --> 00:53:11,560
And I wasn't.

902
00:53:11,860 --> 00:53:12,980
Yeah, it's thank you.

903
00:53:13,380 --> 00:53:22,180
But it wasn't like, you know, I'm not their like go-to family member, but their go-to family member really struggled to get into their accounts.

904
00:53:22,360 --> 00:53:26,780
It's not something people think about until it happens and then you go, ah, crap, I should actually think about this.

905
00:53:27,200 --> 00:53:31,040
Especially, I'm sure, in our community because people really are pretty hardcore about their security and privacy.

906
00:53:31,260 --> 00:53:35,400
So it's always important to build in those backup plans for the people around you.

907
00:53:35,740 --> 00:53:36,880
Because what's the point of good security?

908
00:53:37,820 --> 00:53:40,740
To me, security is about keeping good people in and bad people out.

909
00:53:40,880 --> 00:53:42,580
It's not about keeping everyone out, period.

910
00:53:43,560 --> 00:53:44,800
So, yeah.

911
00:53:45,180 --> 00:53:47,520
Third-party integrations, I'm down to the last couple things here.

912
00:53:47,640 --> 00:53:50,720
I know you guys do integrate with those alias services.

913
00:53:50,920 --> 00:53:54,100
So do you have any other third-party integrations that people should know about?

914
00:53:55,080 --> 00:53:58,780
Some of our two-factor authentication also includes Duo, YubiKey, OTP.

915
00:53:59,200 --> 00:54:00,160
That's for individuals.

916
00:54:01,100 --> 00:54:05,560
And then we also offer a lot of integrations for enterprise, lots of integrations for enterprise.

917
00:54:06,020 --> 00:54:13,300
And if there's something that you don't have an integration for that we don't have, we have two API keys that you can create your own integrations with.

918
00:54:14,160 --> 00:54:14,860
It's actually really cool.

919
00:54:15,120 --> 00:54:18,740
I highly recommend you check out the documentation on that, but you can pretty much do anything you need to.

920
00:54:19,720 --> 00:54:19,980
Nice.

921
00:54:21,100 --> 00:54:22,760
AI, company stances on that?

922
00:54:23,000 --> 00:54:34,980
We did recently release a MCP server for people who want to use AI, you know, a self-hosted MCP server to use with other self-hosted installations for people who are experimenting with that sort of thing.

923
00:54:35,520 --> 00:54:39,480
So like NAN, then people could like automate things with Bitwarden?

924
00:54:39,620 --> 00:54:51,380
Yeah, you could do, you could do auto, you know, you just be able to like, you know, say like, hey, send a Bitwarden send, which is an encrypted communication to my friend that contains this password.

925
00:54:51,940 --> 00:54:53,360
And it could do that for you and send it out.

926
00:54:54,340 --> 00:54:57,380
But, you know, this is mostly for the advanced people who know what they're doing.

927
00:54:58,540 --> 00:55:01,180
And so we've had that, we have, we have that documentation online.

928
00:55:01,400 --> 00:55:02,580
So you can, you can see that.

929
00:55:03,160 --> 00:55:04,340
I didn't know you guys had an MCP server.

930
00:55:04,520 --> 00:55:10,080
So we're not doing, you know, putting AI into the products.

931
00:55:10,380 --> 00:55:10,480
Right.

932
00:55:10,660 --> 00:55:10,800
Yeah.

933
00:55:11,140 --> 00:55:14,120
That's a lot of people are very uncomfortable about that idea.

934
00:55:14,660 --> 00:55:15,600
I think it's the right middle ground.

935
00:55:15,720 --> 00:55:18,900
I think the problem right now and why so many people have this.

936
00:55:19,160 --> 00:55:21,400
Well, there's a lot of reasons why people have a visceral reaction to AI.

937
00:55:21,580 --> 00:55:28,160
But I think one of the core ones is because it's just kind of shoved into the product without much thought into like what it's actually doing for the user.

938
00:55:28,380 --> 00:55:33,940
But I feel like in a lot of those situations, an MCP server would actually solve most of the use case there.

939
00:55:34,340 --> 00:55:36,600
because then you're actually doing something useful potentially with the data.

940
00:55:36,620 --> 00:55:38,720
And I feel like the example you gave is a really good one.

941
00:55:38,980 --> 00:55:42,280
And that'd be far more useful than some like, oh, summarize my vault for me.

942
00:55:43,040 --> 00:55:43,720
AI feature.

943
00:55:45,040 --> 00:55:49,720
I think if you're really comfortable about and you have everything on-prem, right,

944
00:55:49,920 --> 00:55:52,540
which is an air-gapped, which is also a possible thing too.

945
00:55:53,380 --> 00:55:55,960
Somebody could be like, hey, here is, you know,

946
00:55:56,220 --> 00:55:58,900
they get set an agent that connects to like their Slack or something.

947
00:55:59,020 --> 00:56:03,440
And Slack say, hey, give this person access to this item for 25 minutes.

948
00:56:03,800 --> 00:56:05,900
And then, you know, there's a lot of options.

949
00:56:06,220 --> 00:56:09,420
And, you know, when people are working on this, like, we love to hear feedback from the community.

950
00:56:10,500 --> 00:56:10,820
Nice.

951
00:56:11,110 --> 00:56:15,100
A few hours before recording, I have a signal group with some community members in it.

952
00:56:15,600 --> 00:56:22,180
And there is a little bit of outrage because they got an email from 1Password that they just raised their prices quite substantially.

953
00:56:22,540 --> 00:56:24,040
So I did want to just quickly check in.

954
00:56:24,040 --> 00:56:26,160
You said there's always a free plan and that's been a promise.

955
00:56:27,280 --> 00:56:31,880
How do you guys handle price increases and how do you do that, you know, transparently?

956
00:56:32,280 --> 00:56:35,580
And is that something users should expect at some point as well?

957
00:56:35,860 --> 00:56:37,200
So it's funny, this is actually pretty timely.

958
00:56:38,040 --> 00:56:42,680
Bitwarden, we did update our pricing for our plans last month.

959
00:56:43,440 --> 00:56:48,080
And so it was our first time updating pricing since the inception of Bitwarden.

960
00:56:48,700 --> 00:56:55,940
So it was $1.65 a month now charged annually for the individual plan.

961
00:56:56,200 --> 00:56:59,020
But we always have the free plan and the free plan will always be there.

962
00:56:59,540 --> 00:57:01,380
And it already has everything everybody needs.

963
00:57:01,680 --> 00:57:03,460
So you can see the communication.

964
00:57:03,520 --> 00:57:04,820
You can see what the community says.

965
00:57:05,280 --> 00:57:08,320
Most are fully supportive of that sort of thing.

966
00:57:09,280 --> 00:57:13,860
Yeah, I mean, it's still just pennies for good security.

967
00:57:13,900 --> 00:57:14,940
I think it's good.

968
00:57:15,400 --> 00:57:16,560
And then FDroid.

969
00:57:16,680 --> 00:57:17,600
Do you guys have an FDroid app?

970
00:57:17,720 --> 00:57:18,000
We do.

971
00:57:18,800 --> 00:57:24,040
There actually was some chatter about it recently because we had an issue with it publishing.

972
00:57:24,640 --> 00:57:25,760
I need to double check on that.

973
00:57:25,940 --> 00:57:27,300
But it is there.

974
00:57:27,340 --> 00:57:37,020
And people who are like really big into like looking for looking at trackers and stuff, they might notice on our Android app, some tracking applications will say, oh, your Android app has two trackers in it.

975
00:57:37,140 --> 00:57:40,440
Well, it's it's it's Firebase and, you know, crash analytics.

976
00:57:40,700 --> 00:57:41,020
It's nothing.

977
00:57:41,460 --> 00:57:42,280
We're not tracking your data.

978
00:57:42,800 --> 00:57:46,420
But if you want a version of the app that doesn't have those analytics, you can get the FDroid app.

979
00:57:46,680 --> 00:57:47,820
And that is that's out there.

980
00:57:48,660 --> 00:57:48,860
Got it.

981
00:57:49,000 --> 00:57:51,680
And then is that on the official repo or do you guys host your own repo?

982
00:57:51,720 --> 00:57:52,400
It's on the official repo.

983
00:57:53,140 --> 00:57:53,740
OK, very nice.

984
00:57:54,520 --> 00:57:54,680
Linux.

985
00:57:55,200 --> 00:57:56,160
You guys are on Linux, too?

986
00:57:56,300 --> 00:57:56,720
Yeah, of course.

987
00:57:56,880 --> 00:57:57,420
Yeah, we support links.

988
00:57:57,540 --> 00:57:59,080
Yeah, well, so many different kinds.

989
00:57:59,100 --> 00:58:00,400
You can go to bitwarden.com slash downloads

990
00:58:00,500 --> 00:58:01,640
and see all the different options that are there.

991
00:58:02,520 --> 00:58:03,720
Perfect, just making sure I cover my bases

992
00:58:04,120 --> 00:58:04,900
before I get comments about it.

993
00:58:05,660 --> 00:58:07,220
So that is all I have.

994
00:58:07,420 --> 00:58:08,820
Do you have kind of like a final takeaway

995
00:58:09,040 --> 00:58:09,800
for all our viewers?

996
00:58:11,100 --> 00:58:11,740
Yeah, I do.

997
00:58:11,900 --> 00:58:13,740
So first, I do want to add one more thing.

998
00:58:13,780 --> 00:58:14,680
We didn't talk about it before.

999
00:58:14,800 --> 00:58:15,960
We were talking about security on the cloud.

1000
00:58:16,380 --> 00:58:17,600
And that is, you know,

1001
00:58:17,920 --> 00:58:19,860
when your encrypted vault is uploaded

1002
00:58:20,020 --> 00:58:20,940
to the Bitwarden cloud server,

1003
00:58:21,740 --> 00:58:22,680
it doesn't just sit there

1004
00:58:22,880 --> 00:58:24,180
only protected by your master password.

1005
00:58:24,580 --> 00:58:27,100
there are, well, we call it multi-factor encryption.

1006
00:58:27,550 --> 00:58:30,420
There are at least three different other layers of encryption

1007
00:58:30,530 --> 00:58:34,880
that go onto the cloud server with keys in different locations

1008
00:58:35,360 --> 00:58:38,920
that are all protected significantly through key management software

1009
00:58:39,220 --> 00:58:43,800
that makes it so that even if there were like some sort of cloud breach

1010
00:58:44,120 --> 00:58:48,280
and somebody was just able to grab the blob of the entire Bitwarden server

1011
00:58:48,370 --> 00:58:51,080
and take it down, there's nothing there for them, right?

1012
00:58:51,360 --> 00:58:53,580
So that's another important thing to talk about.

1013
00:58:53,740 --> 00:59:02,940
Like there's no way that anybody will ever get anything into a state that would not have more than three levels of encryption on the cloud server plus your master password encryption.

1014
00:59:03,680 --> 00:59:08,200
So something to think about if you're ever worried about security of the cloud server.

1015
00:59:09,380 --> 00:59:09,620
Nice.

1016
00:59:10,300 --> 00:59:18,040
And then the final message to anybody out there who's interested about security, use any password manager.

1017
00:59:19,190 --> 00:59:20,280
Choose whatever works for you.

1018
00:59:20,310 --> 00:59:21,620
It doesn't have to be Bitwarden.

1019
00:59:22,080 --> 00:59:26,760
Just anything that works for you that you will use is going to make you vastly more secure.

1020
00:59:27,650 --> 00:59:31,320
We would like for you to use Bitwarden because, you know, we think we have one of the best

1021
00:59:31,450 --> 00:59:36,340
products on the market and it's free with unlimited passwords, unlimited devices.

1022
00:59:36,680 --> 00:59:38,740
There's no strange limitations on that.

1023
00:59:39,230 --> 00:59:41,580
So absolutely, you know, check us out.

1024
00:59:41,930 --> 00:59:43,320
Get any password manager at all.

1025
00:59:43,370 --> 00:59:47,420
Get your friends in a password manager because passwords are very stubborn.

1026
00:59:47,490 --> 00:59:48,140
They're not going away.

1027
00:59:48,800 --> 00:59:54,280
And, you know, you need to absolutely make sure that you are secure in this crazy cybersecurity world.

1028
00:59:54,880 --> 01:00:00,660
Perfect. And is there anything on the pipeline that you're able to share that you guys are working on with the audience?

1029
01:00:01,460 --> 01:00:05,880
Yeah, there's one thing, especially for Linux users that are interested in this sort of thing, although not out for Linux yet.

1030
01:00:06,060 --> 01:00:13,960
One thing that people have been kind of waiting for with bated breath for as they're seeing some of the code be developed is what's called autotype, desktop autotype.

1031
01:00:14,900 --> 01:00:20,020
And that is a very, especially handy for people who use virtual machines all the time and they're logging in remotely connections.

1032
01:00:20,820 --> 01:00:29,600
And that is just being able to have the desktop app essentially type for you the password out into an application that's local on your machine.

1033
01:00:29,930 --> 01:00:34,820
So very handy where you, you know, for example, need to put something into a window that might not be a browser.

1034
01:00:35,150 --> 01:00:37,520
Right. And so people are definitely excited for that.

1035
01:00:37,940 --> 01:00:41,580
It's going to initially come out as a Windows only feature for the desktop application.

1036
01:00:41,960 --> 01:00:45,960
But we're still pursuing going full platform with that.

1037
01:00:46,580 --> 01:00:46,980
Awesome.

1038
01:00:47,540 --> 01:00:48,580
Well, thank you so much, Ryan.

1039
01:00:48,840 --> 01:00:50,940
I know this is very thorough,

1040
01:00:51,260 --> 01:00:54,260
and I hope that we were able to at least get some people

1041
01:00:54,380 --> 01:00:55,620
using some more secure passwords out there.

1042
01:00:56,160 --> 01:00:57,400
Awesome. Yeah, thank you for your time.

1043
01:00:58,100 --> 01:01:00,680
I want to thank Bitwarden for coming on this podcast.

1044
01:01:01,180 --> 01:01:02,740
It has been a complete honor.

1045
01:01:02,900 --> 01:01:05,320
They are a community favorite service,

1046
01:01:05,560 --> 01:01:07,820
and so to actually have them on here and talk to them directly

1047
01:01:08,020 --> 01:01:09,980
has been an absolute pleasure.

1048
01:01:10,200 --> 01:01:11,860
If you have any questions, definitely leave them.

1049
01:01:11,900 --> 01:01:16,520
down in the comments on YouTube or I suppose on Spotify too. And if you want to support this

1050
01:01:16,700 --> 01:01:21,260
podcast and keep it going, you can also consider becoming a TechLaurian. You get access to a private

1051
01:01:21,460 --> 01:01:26,580
signal group. You also get access to my own private RSS feed that I curate with news on a daily basis

1052
01:01:27,100 --> 01:01:31,260
and many other fun perks while still contributing to our content. Thank you all so much for being

1053
01:01:31,400 --> 01:01:36,520
here, for listening and keeping yourself and the people around you a little bit safer. Until next time.

1054
01:02:05,680 --> 01:02:05,700
Субтитры сделал DimaTorzok