If you got the automatic updates on the bitwarden clients, they will show an empty vault if you are selfhosting vaultwarden.
It seems to be an accidental bug in the bitwarden clients that are assuming that they're talking with official servers
It's fixed with the latest release of the vaultwarden server that was published a few minutes ago
58 Comments
Wispy2891@lemmy.world · 129 pts · 39d
Do not update any bitwarden client until you can update vaultwarden
Lem453@lemmy.ca · 31 pts · 39d
If anyone's Firefox auto updated like mine you can uninstall the extension, go to the Bitwarden extension page on the Firefox website and manually install the old version. Only needed if you can't update vaultwarden right away.
Marthirial@lemmy.world · -33 pts · 39d
Switching to Passbolt right now. I have the feeling this is the beginning of the enshitification of Bitwarden.
cron@feddit.org · 45 pts · 39d
Such bugs have already appeared in the past. It's only logical that this happens from time to time, as the creators of bitwarden don't test the compatobility with 3rd party servers.
What is important is that they're not deliberately blocking vaultwarden.
ppb1701@ppb.social · 15 pts · 39d
Zarobi@aussie.zone · 4 pts · 38d
They still have a good export tool, that's a reliable canary for enshittification in my experience. See: how Google butchered their export tools to be as annoying as possible for "security" reasons. The harder it is to leave, the more they care about trapping you via friction rather than keeping you via good customer experience
ppb1701@ppb.social · 2 pts · 38d
@Zarobi this is true, that likely would be a good indicator.
hellmo_luciferrari@lemmy.zip · 11 pts · 39d
Passbolt pales in comparison. The fact I can only get the android app from google play. No thanks. That is a deal breaker right there. I am working towards moving 100% off from google play.
After quickly spinning up a container of it; it feels very unpolished and can't say it will replace Bitwarden/Vaultwarden for me.
Passerby6497@lemmy.world · 3 pts · 37d
The mark of a quality developer is not the lack of problems, but the way they respond to them. Any project in active development for a long time is going to run into breaking issues from time to time just because technical debt accrues and memories are short.
The ability to fix a problem, publicly own up to the cause/fix and work to prevent future issues like it are the best we can ask for.
SatyrSack@quokk.au · -6 pts · 39d
Bitwarden has been in decline for a while. This is definitely not the first sign.
SmoothLiquidation@lemmy.world · 90 pts · 39d
I found this comment on what happened by dani-garcia, one of the main devs:
Found here: https://github.com/dani-garcia/vaultwarden/discussions/7473
JordanZ@lemmy.world · 44 pts · 38d
eleijeep@piefed.social · 12 pts · 38d
I hadn't heard of this one before, thanks for posting.
Edit: this website is very strange. The article is dated 5th June 2019 and the other "case studies" are dated to look like they've been writing regularly since 2019 up until now. But the article reads like LLM output, and the waybackmachine has no record of this article before December 2025, and no record of the domain name henricodolfing.ch before April 2025. The whois database says that the domain was registered in January 2025. So are they really trying to launder slop by back-dating it to make it look like it was written before LLMs existed? Fuck.
Darkassassin07@lemmy.ca · 48 pts · 39d
I do love docker + a front end like dockge.
Saw this post, switched to my browser, clicked three buttons; vaultwarden is now updated. Didn't even move my lazy ass off the couch. (I'm on my phone)
Thanks for the PSA! :)
fozid@feddit.uk · 19 pts · 39d
I love podman quadlets, I didn't do anything and it updated itself ๐
Darkassassin07@lemmy.ca · 6 pts · 39d
I run watchtower on a cron schedule. It had already fired for today, so it wouldn't have run again until tomorrow. I could have waited, but manual is just as easy.
Appoxo@lemmy.dbzer0.com · 7 pts · 38d
Be aware that watchtowerr is not updated anymore and due to the nature of having access to the socket is a security risk.
Darkassassin07@lemmy.ca · 1 pts · 38d
That's one of the joys of FOSS, when the dev for a popular project can't continue; there's often someone willing to pick up the torch and carry it forward.
I switched to this fork when the one you're thinking of ended development.
https://github.com/nicholas-fedor/watchtower
Last update 3 days ago.
myrmidex@belgae.social · 11 pts · 39d
I can recommend Arcane as a front end. I switched over all my services this last week from multiple dockges to a single arcane (+agents). It's looking pretty sweet now. Cleans up a lot of bookmarks too ๐
Darkassassin07@lemmy.ca · 7 pts · 39d
Homepage is my main front end/landing page for reaching/monitoring all my services; but I've got both my dockge instances linked together as well, so all my services show up in both.
myrmidex@belgae.social · 5 pts · 39d
wow didn't know dockge could do that!
Grandwolf319@sh.itjust.works · 5 pts · 39d
I was looking for a simple solution like that, thank you kind stranger!
clif@lemmy.world · 41 pts · 39d
I've been leery about bitwarden client updates since the posts awhile back about the new(ish) PE/VC c suite person.
I'm not saying those are related in any way other than the fact that I intentionally haven't updated my clients to the latest yet and for once it worked out for me :)
mysticalone@lemmy.world · 12 pts · 39d
Its a lot of coincidences
other_cat@lemmy.zip · 2 pts · 38d
As soon as that news came down I immediately went to my extension and turned off auto-updates. Glad I did now!
ShadowZone@lemmy.world · 40 pts · 38d
Thanks so much for the PSA. I'm currently on vacation without any chance to update Vaultwarden but need access to it via the Bitwarden client. Just disabled the auto update in time. I wish I could vote this twice.
eneff@discuss.tchncs.de · 10 pts · 38d
Enjoy your vacation! ~
HeyThisIsntTheYMCA@lemmy.world · 5 pts · 37d
i'm in shadowzone's house right now and vaultwarden's working great :3
guynamedzero@piefed.zeromedia.vip · 23 pts · 39d
Wow! Thanks for the PSA!
melroy@kbin.melroy.org · 16 pts · 39d
Ps. I notice your msn avatar. I'm busy with https://retromessenger.com/. Coming soon for free!
helix@feddit.org · 8 pts · 39d
Would love this to work with Signal and Matrix!
melroy@kbin.melroy.org · 4 pts · 38d
Yah that's possible. I just implemented telegram for now. But depending on the open api like matrix should work for sure as well. Has signal also an open client api?
helix@feddit.org · 2 pts · 33d
The whole client is open source, but idk if you can simply call the API with a token for a linked device or something. Pretty sure Signal doesn't want "chatbots" on their networks and it might be against ToS.
melroy@kbin.melroy.org · 1 pts · 33d
uhm.. yeah I need to look into that. with Telegram, I needed to register a special "telegram app token" and on top of that you still need to login with your own credentials. But I'm just using the official tdlib for that.
Wispy2891@lemmy.world · 3 pts · 38d
Very nice, I even considered using escargot to patch the old clients but then realized it's not a great idea security wise
melroy@kbin.melroy.org · 2 pts · 38d
Yeah escargot just doesn't do it for me. I want to keep using the existing chat network I use daily. But just giving back the MSN vibes.
I created it using gtk4. So it's cross platform as well. Meaning Linux native. Which I also wanted.
mereo@piefed.ca · 13 pts · 39d
Thank you for the PSA good friend!
irotsoma@piefed.blahaj.zone · 10 pts · 39d
Thanks, probably saved me a lot of headache on my laptop browsers. Fortunately, I don't use the official Bitwarden client on android partly because this seems to keep happening.
Jakeroxs@sh.itjust.works · 1 pts · 38d
I've been using the bitwarden android app for about a year and a half with zero issue ๐คท
irotsoma@piefed.blahaj.zone · 1 pts · 37d
This would be the 3rd time since I've been using it that it has broken compatibility with Vaultwarden, but Vaultwarden always fixes it pretty quickly. But usually browser plugins end up updating before I get around to updating Vaultwarden.
pogmommy@lemmy.ml · 1 pts · 39d
which client do you use on android?
irotsoma@piefed.blahaj.zone · 4 pts · 39d
Keyguard. It's not perfect and makes money from the paid version for syncing changes back to the server as well as offline editing that will then sync when you're back online. But it was worth it back when I bought it, and it has never broken so far.
Wispy2891@lemmy.world · 2 pts · 38d
Nice that it has support for both KeePass and bitwarden, can use both at the same time?
What's the pricing (not specified in the play store page), it's a subscription (so it doesn't exist for me) or it's one time?
jjlinux@lemmy.zip · 2 pts · 38d
It seems like it's a subscription from what I can tell. I see some people buying 'lifetime' subscriptions in the play store reviews, so I'm guessing that's the case. Now, it also looks like it's from one lone developer with 27 contributors in GitHub. The app can be downloaded from GitHub (I would use obtainium for that), so that's a good thing. I think supporting developments like this via a subscription (assuming it's not crazy expensive) should be normalized if the product is good enough. On that factor, I can't really comment since I just KeePass the hell out of my credentials over Syncthing, but I do believe there's value in supporting developers like this guy.
https://github.com/AChep/keyguard-app
irotsoma@piefed.blahaj.zone · 2 pts · 37d
Yeah it has both onetime and subscription. I got the one time for around $15.
And yeah the app is available in multiple places. For Android, I get it from a custom Fdroid repo but Obtanium would work as well. I use that for a few apps.
irotsoma@piefed.blahaj.zone · 1 pts · 37d
Yes they can both be used at the same time, though KeyPass stuff is new and beta. I've never used it.
There is both a subscription model and a one time payment model. I bought it with the one-time payment. I believe it was $15. But don't quote me.
cultist@feddit.dk · 8 pts · 39d
Was wondering why it suddenly was stuck loading, thanks!
dditty@lemmy.dbzer0.com · 5 pts · 39d
Yeah I updated bitearden yesterday and my vault would not load any items. Glad this bug is already fixed!
Appoxo@lemmy.dbzer0.com · 8 pts · 38d
Noticed that as well with our selfhosted instance at work and wondered what the deal was.
Guess I now know why.
mik3dd0@lemmy.ml · 7 pts · 37d
Just did the update of vaultwarden. Had to log out and log back again in bitwarden on my browser. On the phone it seems to just have worked. Thank you for the PSA :)
riptide@lemmy.world · 5 pts · 39d
Thank you for this. I thought I was going insane. Time to turn auto updates off
Bazoogle@lemmy.world · 19 pts · 39d
Per the vault warden release notes:
With the vulnerabilities being patched these days, it seems ill asvised to disable automatic updates for something as critical as a password manager.
irmadlad@lemmy.world · 3 pts · 39d
I use the WatchTower fork for now, but I use it with the run once flag:
So, when an update is available, I'll delay updating until I am rather comfortable that all the early adopters have worked out all the bugs for me. LOL Thanks guys! You're an invaluable service.
Magnum@infosec.pub · 4 pts · 39d
The packaged Debian version did not get updated yet.
SatyrSack@quokk.au · 20 pts · 39d
Tale as old as time.
Magnum@infosec.pub · 1 pts · 34d
It did get already updated though ๐
Magnum@infosec.pub · 3 pts · 38d
Thanks for the PSA, I got hit before any of this was live
ramble81@lemmy.zip · 3 pts · 39d
โAccidentalโ โ you are far more trusting than I
Lem453@lemmy.ca · 14 pts · 39d
If you check the github discussion from the devs that patched the issue it doesn't seem intentional to me (not an expert). That being said I assumed the same thing.
My browser auto updated the extension at a very inopportune time and from some reason KDE connect from my phone to computer which is usually very reliable also wouldn't connect. Was quite annoying until I realized I can just log into the vaultwarden website directly. I don't think I've done that in years
jaksoy@shredderfood.net · -3 pts · 39d
lka1988@sh.itjust.works · -10 pts · 39d
Lmao there it is
Downvoters: You all know just as well as I do that this was no "accident". Private equity always pulls this shit. Learn how to recognize patterns.