<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Bitwarden on Side Of Burritos</title>
  <link rel="alternate" href="https://staging.sideofburritos.com/tags/bitwarden/" />
  <link rel="self" href="https://staging.sideofburritos.com/tags/bitwarden/index.xml" />
  <subtitle>Recent content in Bitwarden on Side Of Burritos</subtitle>
  <id>https://staging.sideofburritos.com/tags/bitwarden/</id>
  <generator uri="http://gohugo.io" version="0.165.0">Hugo</generator>
  <language>en-us</language>
  <updated>2025-05-31T10:00:00Z</updated>
  <author>
    <name>Josh</name>
    
  </author>
  
      <entry>
        <title>Some thoughts on switching to KeePass</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/i-switched-to-keepass/" />
        <id>https://staging.sideofburritos.com/blog/i-switched-to-keepass/</id>
        <published>2025-05-31T10:00:00Z</published>
        <updated>2025-06-01T10:00:00Z</updated>
        <summary type="html">I switched to KeePass</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode93s0hbhb">🎥 


<a href="https://youtu.be/sRi66okPdFM" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://community.bitwarden.com/t/allow-attachments-to-be-exported-when-using-export-data/835/1" target="_blank" rel="noopener" class="text-break">https://community.bitwarden.com/t/allow-attachments-to-be-exported-when-using-export-data/835/1</a> - Allow Attachments to be exported when using Export Data Feature Request</li>
<li>


<a href="https://bitwarden.com/blog/upload-store-and-now-export-attached-files-in-your-secure-bitwarden-vault/" target="_blank" rel="noopener" class="text-break">https://bitwarden.com/blog/upload-store-and-now-export-attached-files-in-your-secure-bitwarden-vault/</a> - Bitwarden blog post announcing attachments export</li>
<li>


<a href="https://grapheneos.social/@GrapheneOS/114549099206535021" target="_blank" rel="noopener" class="text-break">https://grapheneos.social/@GrapheneOS/114549099206535021</a> - GrapheneOS post mentioned in intro</li>
<li>


<a href="https://keepassxc.org/" target="_blank" rel="noopener" class="text-break">https://keepassxc.org/</a> - KeePassXC (Desktop)</li>
<li>


<a href="https://www.keepassdx.com/" target="_blank" rel="noopener" class="text-break">https://www.keepassdx.com/</a> - KeePassDC (Android)</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>Just a few quick updates before we get into it.</p>
<p>I send out a monthly email newsletter — if you want to sign up for that, you can go to sidecideros.com, throw your email in the box, and hit subscribe. While you&rsquo;re there, you can also check out my podcast, which is called In the Shell. You can find out where to listen at intheshellpodcast.com.</p>
<p>Back on sidecideros.com, I added a small phone icon at the top. If you click on it, it takes you to a page with an up-to-date list of all the apps I use on my Google Pixel running GrapheneOS. So if you&rsquo;re just getting started or you&rsquo;re curious about what I use, you can check that out and use it as a reference.</p>
<p>About five months ago, I published a video called The Big Problem with Bitwarden Backups. TL;DR — I was migrating my self-hosted Bitwarden instance to a new server. I set it up, imported my backup (exported using the web interface), and everything seemed fine. But shortly after, I needed an attachment from my vault — I think it was a PDF — and realized that none of the attachments had been imported.</p>
<p>After digging into it and finding a forum post, I learned that Bitwarden backups didn’t export attachments at the time. Fast forward to now, and it looks like they’ve fixed that — they even published a blog post about it. Attachments are now included in backups, which is great!</p>
<p>That said, I still don’t use Bitwarden. As Bush once said (sort of):</p>
<p>“Fool me once… shame on — shame on you. Fool me… we can&rsquo;t get fooled again.”</p>
<p>(Yes, that was a joke.)</p>
<p>Even so, I still recommend Bitwarden for 99% of people. I think it’s the best option if you need a cloud-hosted, centralized vault — especially if you’re managing passwords for multiple people in your family and don’t want to be solely responsible for your data.</p>
<p>As for me, I’ve reached a point in my self-hosting journey where I’m trying to simplify my setup. Bitwarden running in Docker containers is fairly straightforward, but there were some backend elements I wasn’t entirely comfortable with. A few times during updates, the service wouldn&rsquo;t come back up right away. I had to troubleshoot, figure out what changed, make updates, and get it running again.</p>
<p>For something like a password manager, that kind of downtime can be stressful. That’s why I moved to KeePass.</p>
<p>One of the benefits of KeePass is that your vault is just a single file. That means you can back it up by literally copying it to a flash drive. If you ever need to restore it, you just open the file with KeePass — no need to set up a new instance, import a backup, and go through the login process. You can access your vault from any computer or phone with the app installed. That simple file structure is a big plus in my book.</p>
<p>Quick note before I continue: If you haven’t self-hosted anything before, your password manager shouldn’t be the first thing you self-host. Start with something less critical, get your backup plan in place, and then maybe consider self-hosting your password manager.</p>
<p>So back to KeePass — it’s simple. I use KeePassXC on desktop and KeePassDX on Android. One thing to keep in mind is that unlike Bitwarden (which provides a complete ecosystem from the same company), KeePass is more fragmented. But once everything is set up, you don’t really have to think about it.</p>
<p>The interface is straightforward. I really like the password generator — you can choose between passwords and passphrases, and it includes a default word list (you can add more if you want). I do wish it had a username generator, though — that’s one feature it lacks.</p>
<p>Creating new entries is simple. You can attach files, and since everything is stored in that one file, you don’t have to worry about exporting attachments separately.</p>
<p>KeePass also supports MFA. I use YubiKeys for this — specifically the 5C model. Every time you make a change, KeePass prompts you to touch the YubiKey for confirmation. I also have a Nano YubiKey that I leave plugged into my computer, which makes it more convenient. This adds a layer of protection against automated attacks since physical touch is required for authentication.</p>
<p>There’s a browser plugin for KeePass, but I found it a bit clunky and stopped using it. Instead, KeePass has a feature called Auto-Type. You select an entry, click Perform Auto-Type, and it types your credentials into the active window. I don’t personally use it — I just copy and paste.</p>
<p>On my phone, I also avoid keyboard integration — I just copy and paste there as well, and it works fine for me.</p>
<p>You might be wondering how I sync across devices now that I’m not using a centralized setup. I do 95% of my work on my laptop, so I only make changes there. Then every few days, I manually transfer the updated password database to my phone and tablet using LocalSend.</p>
<p>You could sync your KeePass database to a cloud service and install the client on each device — I actually have mine synced to Seafile, which I also self-host — but I still prefer the manual method. It keeps things simple, and I haven’t had any issues with it.</p>
<p>So while I still think Bitwarden is a fantastic choice for most people, if you&rsquo;re into self-hosting, KeePass is absolutely worth checking out.</p>
<p>If you have any questions or comments, feel free to leave them down below — and I’ll see you next time.</p>
]]></content>
      </entry>
      <entry>
        <title>The Big Problem with Bitwarden Backups</title>
        <link rel="alternate" href="https://staging.sideofburritos.com/blog/problems-with-bitwarden-backups/" />
        <id>https://staging.sideofburritos.com/blog/problems-with-bitwarden-backups/</id>
        <published>2025-01-11T10:00:00Z</published>
        <updated>2025-01-11T10:00:00Z</updated>
        <summary type="html">Bitwarden is a great password manager, but there’s a critical issue with backups that could catch you off guard.</summary>
          <content type="html"><![CDATA[<h2 id="-hahahugoshortcode109s0hbhb">🎥 


<a href="https://youtu.be/OI_mElYmQ7w" target="_blank" rel="noopener" class="text-break">Video Link</a></h2>
<hr>
<h2 id="links-referenced-for-video">Links referenced for video</h2>
<ul>
<li>


<a href="https://bitwarden.com/help/export-your-data/" target="_blank" rel="noopener" class="text-break">https://bitwarden.com/help/export-your-data/</a> - Bitwarden Export Vault Data Help Page</li>
<li>


<a href="https://community.bitwarden.com/t/allow-attachments-to-be-exported-when-using-export-data/835/1" target="_blank" rel="noopener" class="text-break">https://community.bitwarden.com/t/allow-attachments-to-be-exported-when-using-export-data/835/1</a> - Allow Attachments to be exported when using Export Data Feature Request</li>
<li>


<a href="https://news.ycombinator.com/item?id=31702594" target="_blank" rel="noopener" class="text-break">https://news.ycombinator.com/item?id=31702594</a> - Hacker News post about Bitwarden backups</li>
<li>


<a href="https://intheshellpodcast.com" target="_blank" rel="noopener" class="text-break">https://intheshellpodcast.com</a> - In the Shell Podcast</li>
<li>


<a href="https://yellowball.fm" target="_blank" rel="noopener" class="text-break">https://yellowball.fm</a> - 🟡 Yellowball, don&rsquo;t just host your podcast, own it</li>
</ul>
<hr>
<h3 id="transcript">Transcript</h3>
<p><strong>Please excuse any grammatical errors. I used a tool to generate the transcript and haven&rsquo;t had a chance to read through it yet.</strong></p>
<p>Today, I want to talk about Bitwarden. Let me start by saying that I think it&rsquo;s a great password manager and a solid option for many people. I&rsquo;ve been self-hosting it for the past two years, but there&rsquo;s one major feature missing that could potentially cause problems for users, just as it did for me.</p>
<p>For the past two years, I&rsquo;ve been hosting Bitwarden on a Raspberry Pi, along with a few other containers. Recently, I wanted to simplify and consolidate my setup, so I moved Bitwarden, along with the other containers, to an existing Mini PC I had. I got the containers up and running on the new host, and the next step was to restore the backups I had taken. Everything went smoothly—backups for the other containers restored perfectly. When I restored Bitwarden’s backup, everything seemed fine. I signed in on my other devices, ensured syncing was working, and verified all my passwords were intact. Perfect.</p>
<p>About a month later, everything still looked good. Confident in my setup, I decided to format the drive the Raspberry Pi was using and deleted the backups I had for it. Then, of course, Murphy’s Law struck. I logged into my new Bitwarden instance to check on some documents I had uploaded, and to my surprise, they were gone.</p>
<p>This leads to the major feature Bitwarden is missing: the ability to export attachments when you back up your vault.</p>
<p>Let me walk you through what happened. In my self-hosted instance, I had to use a cloud-hosted Bitwarden Vault to get a license for the self-hosted subscription. So, I decided to test this feature in the cloud-hosted vault. Here’s what I found:</p>
<p>When you try to export your vault, you have a few options—JSON, CSV, or encrypted JSON. I selected JSON, confirmed the format, typed in my master password, and exported the vault. When I looked at the exported file, it was clear something was off. The file size was only 636 bytes, even though the test entry I uploaded included a 40 MB attachment.</p>
<p>I’ll take some responsibility here—there were red flags I should have noticed. The file was too small, and JSON is unlikely to contain encoded attachments due to size limitations. There were no additional folders or files for attachments, just a single, tiny JSON file. I should have realized this, but I was working casually and didn’t double-check.</p>
<p>To make matters worse, there’s no warning in the Bitwarden interface about attachments not being included in exports. The only mention of this that I could find was in the &ldquo;Export Vault&rdquo; help document, which states: “Vault exports will not include file attachments, items in the trash, or sends.” While they do technically warn you, I think this information should be far more prominent.</p>
<p>Bitwarden has no problem including warnings in other parts of the app. For instance, the &ldquo;Security&rdquo; tab highlights warnings about changing your master password or enabling two-step login with yellow-highlighted alerts. A similar approach for export warnings could save users from losing critical data.</p>
<p>Needless to say, I lost backups of SSH keys, important documents, and even photos of identification that I had stored securely in Bitwarden. It’s a harsh lesson in the importance of keeping local backups, which is a topic I’ll cover in a future discussion.</p>
<p>After realizing this, I started searching to see if others had faced the same issue. I found a Hacker News thread discussing the exact problem: Bitwarden does not export attachments in backups. The thread linked to a community feature request for this functionality dating back to May 2018. That’s nearly six years, and the feature still hasn’t been implemented.</p>
<p>Some commenters suggested contributing to the open-source project by submitting a pull request to implement the feature. While that’s a fair point, it’s also worth noting that file attachments are a paid feature. If you’re paying for the product, you might reasonably expect such a basic feature to be included without needing to develop it yourself.</p>
<p>All this is to say: if you’re using attachments in Bitwarden or considering it, I’d recommend either avoiding them or ensuring you save local copies of any files you upload. Personally, I might use this as an opportunity to explore other options like KeePass and see if they better meet my needs.</p>
<p>I hope sharing this experience helps someone avoid losing their attachments in Bitwarden. If you have any questions or comments, feel free to leave them below, and I’ll see you next time.</p>
]]></content>
      </entry>

</feed>
