Bitwarden integrates with OneCLI agent vault (onecli.sh)

by sudo_chmod 43 comments 63 points
Read article View on HN

43 comments

[−] Uvix 46d ago
Reading the article, it sounds like this is the other way around? Bitwarden is offering a new API, and OneCLI Agent Vault is integrating with the new API.
[−] stronglikedan 46d ago
integration is a two-way street. it doesn't matter which is stated first
[−] jMyles 46d ago
I disagree that integration is commutative.

Often, we see a feature which is important to free use of a computer as a general-purpose tool locked behind an ever-changing and/or poorly documented API in a closed-source, centralized, de-facto-government-subsidized project.

The power dynamics of that situation are not symmetrical, so it does matter which project(s) are using which API(s) of the other(s).

[−] malfist 46d ago
I added "login with google" to my website. Should I go to the news media to brag about how google is launching an integration with me?
[−] SkyPuncher 46d ago
These tools are useful, but I can't help to feel like they're solving the wrong part of the problem. I really don't have much concern that an agent has access to one of my credentials. Outside of production, most of these credentials are going to be limited in privilege and self-rotatable.

What remains terrifying is the ability to exfil important data or run commands that are malicious.

[−] rvz 46d ago
OneCLI does not even have a security audit and a VC backed password manager believes that it is secure enough to integrate in their password manager.

I could not be anymore bearish on Bitwarden than before after looking at this and very glad that I don't use them.

[−] sneak 46d ago
How soon until those of us who are running Vaultwarden need to fork the Bitwarden clients, too?
[−] bundie 46d ago
EDIT: My bad. I saw "agent" and immediately thought of AI.
[−] lucideer 46d ago
I really don't understand the HN comments here.

Lots of assumptions that the article is AI-authored (it could be but I'm not seeing overtly obvious signs - it's quite readable) & a lot of ungrounded assumptions that this is somehow related to Bitwarden integrating AI into their product.

I really thought reading comprehension among HN users was better than this.

[−] gmerc 46d ago
Took VC money, here comes the AI enshittification.
[−] mergeshield 46d ago
[flagged]
[−] brumbelow 46d ago
[flagged]
[−] post-it 46d ago
[flagged]
[−] rcakebread 46d ago
Did you mean to post this on April 1st?
[−] AnonC 46d ago
Tangential: Where is Bitwarden on the below roadmap right now? It wasn’t even good to users, but was an alternative to 1Password and others that had long crossed this bridge.

‘Here is how platforms die: first, they are good to their users; then they abuse their users to make things better for their business customers; finally, they abuse those business customers to claw back all the value for themselves. Then, they die. I call this enshittification, and it is a seemingly inevitable consequence arising from the combination of the ease of changing how a platform allocates value, combined with the nature of a "two-sided market", where a platform sits between buyers and sellers, hold each hostage to the other, raking off an ever-larger share of the value that passes between them.’

- Cory Doctorow