Open Source Password Manager?! | The IT Guy Show 026 Guest: Kasey Babcock, Senior Product Marketing Manager at Bitwarden Hold on, if you're watching this, do you have a password manager? If not, this episode's for you. And not just any password manager. I've used Bitwarden for the past five years, and most password managers that I've seen ask you to just trust them blindly. Bitwarden decided to do things just a little bit different. Instead, they actually open up the hood and show you the code. Today, we'll see all about Bitwarden, what they've been working on, and why passkeys aren't the evil thing you think they are. Hey there, and welcome to the IT Guy Show. I'm your host, Eric the IT Guy, Hendricks. This is episode number 26. We're plugging right along, coming up on 30 here, which is my age. Oh wait, no, no, I'm not 30 anymore? Oh, okay, all right, so I'm not 30 anymore. But, you know, we've got a lot of episodes lined up. In fact, next episode, I've got 45 home labs coming on. We're gonna talk hardware because, you know, new space, new place, new, that means I need new devices, right? So, you know, but I've got a whole pile of guests lined up for the summer and into the fall. But today is a really special episode. I'd say that about every other time. But I've actually been a customer of Bitwarden for probably five to six years now. Actually closer to seven now that I think about it. I switched from LastPass to Bitwarden when I moved to, when I started working for GitLab. And I've loved the product. I've used it ever since. And in fact, my previous show, the Sudo Show, Bitwarden was actually a sponsor of the Sudo Show. So I'm excited to be connected back with Bitwarden and get to know some of the folks that are working there today. But it wouldn't be the IT Guy Show unless I had someone to badger with questions. And I did warn her that I'm very, very aggressive in my question asking, she didn't believe me. But without further ado, I would like to welcome Kasey Babcock to the IT show, or it's the IT Guy Show. Kasey, welcome. Thank you, excited to be here. Yeah, so when it's always a string of three questions when I start, who are you? Tell us a little bit about yourself. What do you do? And what's one thing you do for fun? Yeah, great question. Okay, so I'm Kasey Babcock. I'm a senior product marketing manager at Bitwarden. Product marketing is this really interesting kind of intersection between technical product specifics, right? And like what we're actually delivering in terms of features and value that we bring to customers and the actual communication of that. So I live in this kind of weird world of communication, but then also like more specific product details. In terms of what I do for fun, I am obviously very in depth in terms of the tech world and the market at play, but I kind of balance that a lot with outdoor activities. So I'm a big rock climber, skier, backpacker. I kind of have to balance that time at my computer with stuff that's actually outside. That's awesome. Most of us nerds just hang out indoors and don't ever go outside. There's this giant ball of burning gas that just hates everyone right now. But yeah, glad to have you on the show. And I wouldn't know anything about the crazy world of product marketing. It's fun because you kind of sit in the middle and you translate all day. You talk to the product team about what they're building and you go talk to the sales team and go, now this doesn't do your laundry yet, so don't tell anybody that. But yeah, this is what it does. And then you go to conferences and whatnot, which is actually how I came to be in touch with you as well, was I ran into the Bitwarden booth at a couple of events this year. And it's like, you know what? Password management is something that doesn't get talked about enough. So I really appreciate you jumping on. And I kind of wanted to talk about Bitwarden's approach because it's a little bit different. It seems like about seven or so years ago when I switched to Bitwarden, LastPass just had a huge breach. I was a 1Password user, probably started with the spreadsheet that everybody had, and then that spreadsheet moved into KeePass. KeePass turned into LastPass. LastPass turned into 1Password that I used for about a year, and then came across Bitwarden. And not just because they were a sponsor of the Sudo Show, but just because Bitwarden does things a little bit different. And I'd like you to, I could tell our audience, but I'd rather hear it directly from you, Kasey. What makes Bitwarden's approach different to password management? Yeah, so I think everything is always evolving at lightning speed in our kind of market, in our tech world, and specifically in the security industry. And I think it's increasingly more important to actually validate that your security solutions are doing what they say they are. There's a lot of buzzwords out in the market that people sometimes take at face value, and you can't actually validate that, right? So Bitwarden is fully open sourced, right? So that means that anyone at any point in time can review the code, inspect it, audit it. This also opens the door for third-party reviews. So we do annual security audits, much more frequent than other password managers in the space. We also have a HackerOne bug bounty program. So we're able to identify any potential bugs much quicker than a closed source proprietary solution. So it's all really about building trust, right? You need to trust the security solutions you use, because especially for password management, right? Like that's where all your most important things live. And so we really want to make sure that there's a secure solution for that. Well, the initial reaction I always get when I'm promoting Bitwarden to somebody is, wait, if it's open source, then don't people know how to get to my passwords? Yeah, I mean, I hear that pretty often too. I have a lot of friends that are not in the security industry, not in the tech world. And I think it's really easy to jump to that conclusion if you're not fully in that kind of space. I think how I like to think about it is closed source is very much a black box. You don't know what's happening. Your passwords are stored, but you don't know exactly how that's happening. Whereas open source, it's always gonna be following those encryption standards, but you're not actually seeing what's happening. You're not actually seeing those passwords that are being stored, but you understand how they are secured. So it's more about understanding the process as opposed to understanding the contents. So not only is Bitwarden open source, and so anyone can go read the code, but as I understand it every so often, a third party does come in and review the code, does a full audit. Can you tell us about that process a little bit? Yeah, so that happens on an annual basis for all of our different clients. So whether that's server, mobile, desktop, CLI, every single kind of aspect of the product goes through this annual audit. And what this actually does is just giving you peace of mind. We can tell you what's happening, but it's so much more trustworthy if it also comes from a third party, right? And that's all what open source community is about, right? Is working together to make things more secure. And Bitwarden does that really well, I will say. We have a huge community of security enthusiasts, is what we often like to call them. People who are just really excited about password management, whether that's for their own workflows, but also just really excited about getting into the nitty gritty of how that works and because we have this really impassioned community, we are able to provide a product, provide a secure solution for everyone that we know has been reviewed by multiple different points, multiple different parties. Love it. So from open source to regular audits, to bug bounty programs, to even the clients. I mean, everything is encrypted on the client side before it's sent up to the server side, which I know is a huge concern with a lot of security minded folks. So if you're on an iPhone or an Android or a laptop, or even using the web interface, everything is encrypted at the source before it's transmitted anywhere. So I mean, it is one of the most robust systems. I won't say secure. You don't ever say anything secure because then that's when the curse descends and all of a sudden huge vulnerability is found. But it is one of the most robust security tools I've ever used. In fact, I was kind of curious as I was prepping for today's recording and I looked at my vault and I have 418 passwords, about a dozen or so are now passkeys and six identities. But I'm really excited because I am using the barest fraction of Bitwarden's capabilities. I was looking at some of the releases over the last few months. It's like, I have not been keeping up on this tool. In fact, having 418 different vault entries, I realized there's a feature I haven't been using. And that's this new archive ability. So why don't we talk a little bit about an archive and what you can do because clearly it's an avid Bitwarden user. I didn't even start using this yet. Yeah, well, it is fairly new. So I'll give you that. It was released earlier this year. And so the archive feature is also born out of the minds of our community, right? This is something that our community has been asking for. And so what their needs are, right? Regularly influences the product roadmap, whether that's for kind of end user use cases or for larger organizations. So yes, the archive feature, very exciting. This was a big, big excitement in the community, but it's really just a quality of life kind of improvement. Essentially what you're able to do is for people with really long vaults, lots of items stored. I know I have about 500, probably even more passwords stored in my Bitwarden account. You're able to archive, right? These passwords or items that you don't use as often. So that way they don't clutter up your search and you aren't necessarily auto-filling them, but you can always unarchive them later, right? So they're still stored in your Bitwarden account, but you don't have to look at them all the time. For example, wanted, I don't know, I still have things from my undergrad program and my Bitwarden vaults that I know I don't have access to anymore. You can just archive that and get it out of your Bitwarden view. That's awesome. So about every January or so, it seems like the proper New Year's thing to do. So every January or so I go through and I break it up a letter a day because otherwise it would take forever. So I take one letter per day, A, B, C, and go down the list and purge all of these items. And I go as far as to reach out to the vendor and request account deletions for things that I'm not using. And I always worry that, did they actually delete my data or not? And so I'm always paranoid about deleting an item. So now when I do that password audit every January, now I can just archive those. That way I've got it just in case, just in case that they didn't actually delete my data. So they've deleted my data, but I've got my foot in the door just in case. So this really makes me excited for the new year. Here we are in July, but. Hey, spring cleaning, that's also a great time to do it. I'd say probably even a great best practice is to back up your vault as well, right? Things always happen. And so it's a great time while you're already going through cleaning everything out, just export an encrypted export of your vault as well and store that in a secure place just to have for later. Yeah, that's great advice for any application that you're using, but especially something that holds all of your keys. Yeah. So tell me, what are some other new features we should be excited about? Yeah, so lots have happened both on that end user experience, right? But also focusing on experiences for larger organizations, making things easier for IT admins that are in Bitwarden every single day. So archive, right? Definitely a huge quality of life improvement. Fill Assist is also a big release that was recently introduced into the market. This essentially enables custom rules for specific websites that have very odd, I guess, coding, right? So it makes Autofill a lot easier whenever you're interacting with these websites. So an example would be maybe a website that just every single time, no matter what password manager you use, your passwords just won't Autofill. It's just becoming a total headache, a total pain in your side, right? And so Bitwarden has a specific custom rules that we've implemented on the backend to ensure that every time people go to these popular websites that just don't have these standard Autofill practices in place, we have adapted our Autofill to meet those particular websites. So essentially just making things a lot easier whenever you're interacting with these kind of odd websites to Autofill your passwords every time. Well, that sounds great because there's a tool I'm thinking about. It's a third-party tool that I use at the college that I teach at. And there's something weird about their password field. First of all, they have the email box on the sign-in screen, but no password field. So I have to click the Autofill to Autofill my email address, and then it refreshes and then the password box appears. So usually I have to click Autofill again in order to get it to fill that password. And depending on the day and depending on the mood that this tool is in, doesn't always acknowledge my Autofill. And so I have to go up to the extension, click the dropdown, click copy, and then physically paste, I know, first-world problems. But this is ridiculous. This is a problem we've had solved for decades. So it sounds like this custom rule may be able to help you go in and fix that problem, especially with classes getting ready to start it in a few weeks. That'll save me a few clicks and a few seconds every time that I log in to do school-related things. Yeah, absolutely. I would say education portals are a common challenge, right? They always are somewhat implemented in an odd way. And so this custom Autofill will help support that, right? I will also say, you know, if you're running into that challenge on a regular basis, I always love the Control-Shift-L command on your keyboard. That is, instead of having to use your mouse, it's more ergonomically friendly. That's usually my go-to for Autofill, just to make sure you don't have to go clicking around. I would say that's more of a bitward and power user kind of a hack, but definitely recommend it. So Control-Shift-L obviously for Windows and Command-Shift-L for Mac. That's great to know. I actually didn't know about that keyboard shortcut and that would save me a ton of time. I mean, I work in the industry on Linux, so I'm used to being on the keyboard. So anytime I can learn a new keyboard shortcut, it just makes my life easier. I use the mouse trackpad actually, but it's just so much easier when I can keep my keys, when I can keep my fingers on the keyboard. So that's a good one. So free pro tip from Kasey at Bitwarden on this episode. Gotta love it. Are there some other features that you're excited to talk about? Probably one of the biggest ones is we have a UI redesign and process. For those who are already on the Bitwarden community or already on the forums, already on our subreddit, you've seen this announcement, right? This is a pretty big improvement to Bitwarden. Kind of familiarity, especially for those who are starting to use Bitwarden for the first time, we wanna make it as easy as possible, which is what the UI redesign is really intended to do. This is all informed by our customer feedback, our community feedback, and beta testing. So that will be released in the coming year, and you can interact with the prototype on our community as well. So I recommend checking that out. I don't know if we can include a link to that in your show notes, but I highly recommend it if you wanna see exactly where Bitwarden is headed for that user experience and user interface. Yeah, and that's a great segue into any links or topics that we talk about will be in the show notes. And how about this? If you're watching the video version, if you have a keyboard shortcut or a particular new feature you're excited about, put those in the comments. I know, it's ridiculous, but YouTube tells me, I have to say this every episode. And while you're at it, just hit like and subscribe. Really appreciate that. My YouTube numbers have finally started growing again. So really excited that you all are tuning in. So there's our mid-show commercial for you. But yeah, if you've got any keyboard shortcuts or any features you're excited about, throw them in the comments below. If you're on the audio side, just hit me up on social media. I don't have comment section on the audio side, but you know how. So Bitwarden, I've known Bitwarden from the consumer side, from the individual user. I've had shared vaults between family members. I've had shared vaults at work, but that's not where, I don't want to be unfair. That's not the bigger money maker, as it were, for Bitwarden really is. The big focus, the big drive for Bitwarden is to focus on the business side. And so one of the things that I found kind of interesting that if I were to run my own business is this new access intelligence reporting tool that was just released. You want to talk a little bit about what that looks like? Yeah, and just to maybe address your comment earlier, yes, Bitwarden, our revenue does primarily come from business, and that is an area of focus, but that does not distract from the personal users, right? For sure. Ultimately, well, business plans are where we make our revenue. That's how we're able to support the free plan forever, and making sure that everyone has access to password management, no matter what their income level is, no matter where they live in the world, right? So I just want to make sure that that's extra clear, because we do love our personal users and really believe in the mission of helping everyone be secure online. So it's adorable that you mentioned the free plan, because I think within about 15 minutes of trying Bitwarden, I'd already paid my money. It's like, here, here, thank you. So yeah, I couldn't find better wording for that, but definitely there is so much love for the Bitwarden community and the Bitwarden individuals, and it's like, is it $9 in change or $19 in change a year or something? I mean, even the paid plan is incredibly cheap. So I point to the business users as the reason why Bitwarden can include professional level password management for all of us individuals. But yeah, so going to your comment about access intelligence, right? This is a completely new kind of feature set that is available for Bitwarden enterprise plans. And essentially what it offers is the ability to see all of the at-risk passwords. So all of the exposed, all of the reused, and all of the weak passwords in the organization, organize those based on applications that are being used and see exactly who is creating and accessing these at-risk passwords and make sure that those are fixed, right? And so the idea is to make this as easy as possible for all the IT admins out there. So instead of trying to hunt down employees with a reused password, whenever you're working in a really large organization, that sounds like an absolute nightmare of a project, right? What you can do is actually rank these at-risk passwords based on the application that is most important, right? So you're really prioritizing, let's say a Microsoft Office 365 login, as opposed to a random Reddit login or Netflix login that someone was storing on the organization vault when it's really a personal one, right? That's not worth the IT team's effort. What really is worth it, right? Is like these really high, highly critical applications that really impact the organization and store really sensitive information. What's cool is once you kind of prioritize which applications you want to target first is that Bitwarden actually alerts those end users to change that at-risk password instead of the IT manager having to manually do that. I've seen in other organizations, right? That process is just so lengthy. It takes ages. People don't pay attention, but Bitwarden actually guides that end user through that step-by-step process of how to update their password with something securely generated from Bitwarden that actually meets the organization's password policies. So Access Intelligence, I believe it was released last year, but we did actually just get a new, really cool update to this feature is the ability to track risks over time, right? So I know a lot of IT folks being able to report on their improvements, being able to report on their changes in the organization as it relates to security and it relates to how end users are actually managing their passwords is really important. And so Bitwarden provides that in an easy to see graph. You can also export it as a PNG for just showing during leadership reviews, but tracks that risk over time, right? So maybe when you start off with Bitwarden, you see a really high number of at-risk passwords and they're all associated with really critical applications. But as the IT team starts prioritizing those and starts alerting those end users, you start to see that graph go down. And that's a really important graph to be able to show in these larger organizations and really show off all the amazing work that you've done. So that was a really cool improvement to Access Intelligence that we're excited to have to offer to our customers. That's awesome. Yeah, I mean, a lot of those features are included in the consumer version. I can get notifications when a particular application that I'm using has a reported breach or if a password's been reused. So to be able to see those same metrics, but from an organization level really makes a lot of sense. For me as an IT administrator to go, Joe, you can't use the same password on all 50 of your apps. You've got to change these. And definitely having that upward mobility of being able to report those up the chain. I know C-suite love graphs and love pretty charts. So making that really easy to just download that PNG and drop it into a slide deck really helps justify the efforts that a security team's putting in. And speaking of IT teams and making progress, there's a particular feature that I really want to dive into because it kind of impacts some of the projects I have here in my home lab. And that's this new Hermes project. Love to hear all about Hermes. Yeah, so this is actually something that the Hermes team put together. Bitwarden has been interacting with them and learning a lot. We're so excited to have this in market, but yeah, the Hermes team put together an integration with Bitwarden Secrets Manager. So specifically to ensure that whenever you're working on a project that Hermes is interacting with, you can securely store or securely share your credentials and use them within your project without specifically sharing them in plain text with Hermes. AI agents are incredibly powerful tools. They can do incredibly powerful things. You just don't want to share your credentials with them in plain text. They aren't set up to secure that kind of information. And so it's really important to think about how to securely share those. There's many different ways to do this, but this direct integration with Hermes makes it a lot more streamlined. So right now, a lot of my listeners know that I'm in the middle of a migration from standard RPM-based transactional operating systems to the bootc method. And so as part of that, I am building out CICD pipelines in my home lab that can deploy Podman containers, driver updates, the operating system itself using bootc. And so one of the things I've been having to manage is I'm using Forgejo or Forge, some people call it, to run my CICD pipelines. They've got a built-in password manager, but then I'm also using Ansible for the infrastructure's code piece. And so I'm using Ansible Vault, which usually means that I've got to do an encryption on the Ansible Vault password before I submit it up to my Git repository, because let's face it, publishing all your production passwords in Git is a common problem these days. And so it's been kind of frustrating because it's several manual steps ahead of time. But if I were to just point Forge at the Bitwarden Secrets Manager, I could bypass that whole problem. Instead, I can set up a token between Forgejo and Bitwarden, and that way I can store all my secrets in Bitwarden and just pass the hash over to the CICD runner. So this is really, really timely. But the one thing that I noticed, and not really gotcha, but just something to know is if you're considering using Bitwarden for this process, just know that the Bitwarden Password Vault and the Bitwarden Secrets Manager are actually two separate products. Do I have that right? Yep. But what's cool is that you can actually access them from the same web app. So it's not like you're managing multiple different vendors. You can switch easily between the Password Manager and the Secrets Manager. But yeah, they are different apps, different solutions, because they solve different kinds of problems. Yeah, and that makes a lot of sense. It was just like, wait, I don't see any of this in the Bitwarden, like in the web UI or anything. But knowing that really changed things. So I'm really considering standing this up. And it's only, it's a little bit more expensive than the Bitwarden Password Vault. But for someone who uses a lot of CICD integration in his home lab now, really kind of makes a lot of sense, for no other reason than to just try it out for myself. And one of the things that caught my attention was I run Proxmox as my virtual machine host. So I've got a bunch of VMs. They're running all sorts of different Linux distributions eventually to be standardized on Fedora, Linux server. But what's really cool is that because I'm running on top of Proxmox, I need to be able to provision those virtual machines. Or if I were to use Linode or DigitalOcean or something, I would need to be able to provision those virtual machines. And you can pull that off with Ansible, but that's not what Ansible is designed to do. But Terraform is. And what's really, really nice is the Bitwarden Secrets Manager actually has Terraform functionality built in. This was so cool. Yeah, exactly. That's what I was going to mention. Bitwarden integrates with both Ansible and Terraform. So really great for those infrastructure as code workflows. But because Bitwarden is open source, we are so big on flexibility that if there are any other kinds of infrastructure as code solutions that you're using, you can easily build integrations yourself with our out-of-the-box SDKs. So those are written in all the popular languages you would expect. And so it's much easier to kind of build those custom workflows as well whenever you are using Bitwarden Secrets Manager. Definitely, so that immediately covers Terraform, OpenTofu, sounds like with an SDK, you could run Ansible, maybe even SaltStack back, I ran SaltStack back in the day before I found how glorious Ansible is. The Terraform integration also supports OpenTofu. So we do have an out-of-the-box integration for that as well. Perfect, that sounds so cool. And might save me a lot of Ansible backdoor work that I was trying to do beforehand. But if I can integrate my secrets management and do my provisioning with Terraform or probably OpenTofu, it just really, really makes a lot of sense. Yeah, and kind of that challenge that you were describing earlier, right? Of having these secrets stored in many different locations across different infrastructure, across different ecosystems, different clouds, different CI CD pipelines. This is one of the reasons why Secrets Manager was built in the first place, right? It's to centralize that, have some sort of source of truth of all of your secrets and protect that with the same end-to-end encryption that's trusted with Password Manager, right? So it's extra kind of secure solution to store all those secrets and securely inject them within your pipelines, but using integrations to do that as well. Especially for business contexts, right? It is so, it would be basically impossible to track what machines have access to what and how they're used in different contexts if they're scattered across different secrets management solutions. So centralizing that secret sprawl was a big reason that Bitwarden Secrets Manager was developed. Yeah, that sounds like the perfect solution to my use case right now. Yeah. So let's kind of zoom out. I wanna talk about the bigger picture because I got into a spirited debate with a couple of folks at, I think it was Southeast Linux Fest. And we were discussing passwords versus passkeys. And I wanna get an industry experts opinion on why is passkeys such a big thing? Why are all these apps now asking me to create passkeys and replacing my password with them? What's going on with this? Yeah, okay. So passkeys, they are phishing resistant. So one of the big reasons why so many people are really excited about passkeys is because you can't phish them. Especially with the increase of phishing kits and phishing as code opportunities that malicious actors are constantly leveraging. Fishing campaigns are becoming more frequent. They're becoming more realistic and they're becoming a lot more complex. So they're able to target you specifically, it's called spear phishing, right? Based on all the information that they have online. And they're able to do this really quickly. So with passkeys, they're completely phishing resistant. Pass keys are essentially like a public and a private cryptographic keys that fit together. And so one without the other doesn't necessarily mean anything. So you can't necessarily share that even if they are being phished by someone who seems really credible. So it really helps you stay more secure online. And it's also being adopted by a lot of larger organizations and a lot of larger kind of industry movers and industry drivers. So Microsoft Entra actually announced in September of this year that passkeys will become the default authentication for Microsoft Entra. And Salesforce already made similar announcements to this as well. So this is where the industry is definitely headed. Passwords are not going away by any sense of the word, right? Everyone will always still need to use passwords. It's just, there's more secure options out there in the wild. So we're able to do away with some of those more insecure 2FA methods like messaging, right? SMS or, you know, TOTP is still really great but there's just some other like email 2FA is not that secure, that's easily phished. I mean, what we're really doing is trying to prevent that. Well, and my bigger issue with SMS or email is it's inevitable that I need to log into that one application to do that one really quick thing. And I'm in a hurry to do it. And that's when their 2FA servers are running really slow and it takes 15 to 20 minutes to get my 2FA key. And by then I've forgotten what I was doing. Oh yeah, and then it's also secure. So from your position, what is it that has gotten people so up in arms about not wanting to move to passkeys? I think it's just change, right? People are worried about having a completely different workflow than what they're used to. I will say, you know, early on too there wasn't as many applications that supported passkeys and that is rapidly changing. A lot of different applications are now really amping up their passkey support and making it a lot easier for end users to adopt. I think people are just scared of doing something new, right? Passwords have been around for ages and I think it's kind of scary to give that up, right? But much more scarier is having that credential phished, right, and taken advantage of. And that's becoming much more realistic in today's space. Well, and what's ironic is usually the people that are complaining about the move to passkeys are the same people that have spent the last two decades complaining about having to remember a password and then having to rotate that password. And then we went from passwords to pass phrases and they've complained about this this whole time. And so moving to a passkey is actually one less thing you have to remember. It's something you have instead of something you know, which makes the process a whole lot easier. Especially if you've got, go ahead. I was just gonna say, I will also say the process is even a lot easier due to the credential exchange protocol which has been around for a while, right? That's been developed in partnership with the FIDO Alliance and quite a few password managers, including Bitwarden. But what you're able to actually do there is take a passkey that is stored on a device, like a mobile device, right? And actually transfer that to a cloud-synced passkey. So making that available across any device that you have, right? And so that's much easier to actually adopt passkeys if you can access that across anywhere. So like take it if you store it in Bitwarden, for example, you can store passkeys in Bitwarden, which is really cool. You can access that passkey across any device that you're logged into Bitwarden on instead of just a Microsoft or macOS infrastructure. Cause that's a very different experience. And so I think if anyone's going to be adopting passkeys, now is the time. Definitely. Yeah, and Bitwarden actually makes it incredibly easy. It might've been a Microsoft product I logged into one day and Bitwarden pops up and goes, Oh, Hey, I see it's asking you about a passkey. You want to save that in Bitwarden? I was like, when was this? When did this become a thing? Yeah, yeah, store my passkey for me. This is great. And it really speeds up the login process for sure. And like you said, it's not something that you can fish. And in case anybody was wondering, I won that argument at Southeast Linux Fest because I pointed out, do you use SSH keys? Same concept. And they're just like, Oh, so I won for the right. Not that anybody was worried about that, but just in case I won that battle. So I always wrap up shows the same way. Was there something that you wanted to talk about, that you wanted to promote or call attention to that we haven't covered today? Oh, that's a great question. I will say there's one other thing I wanted to cover, which is a big improvement that's been added to business experiences when using Bitwarden is a completely different way of essentially sharing passwords. And that is by having the organization itself own those items, whereas other kind of password managers in the space, they have individuals owning those items. You can choose whichever one you'd like whenever you're using Bitwarden, but by having the organization actually own particular items that are being stored within your Bitwarden vault, it makes reporting so much easier. So reporting with features like access intelligence, you're able to see the complete view of all the passwords being used in your organization. And that makes onboarding and offboarding even easier. So instead of a password kind of being accidentally deprecated when someone leaves, right? And then all of a sudden you realize, oh my gosh, we don't have access to this one system because Joe over here, you know, had that password. That's not the case whenever you use Bitwarden. So I really wanted to point that out because I think that's a really cool improvement. And for individuals who have, you know, or organizations that have individuals owning particular passwords, Bitwarden just released a really nice kind of migration path as well for them to have the organization to own them instead. So really streamlining that reporting, really streamlining that onboarding and offboarding, and just making sure that everything is kind of secured in the same place. So I wanted to mention that as well. That was something that was released, I believe last year, but it is a really cool improvement, especially for those managing larger organizations. Definitely, yeah, the onboarding issue was something that came to mind was at my previous job, we actually had someone leave the company and she was the one who owned a lot of the marketing accounts. And so of course her mailbox had been retired and none of that was stored in an organization. So I got to spend days tracking down different email accounts and some of them were her email. Some of them were the shared marketing ad, you know, the company name email. And so even though I was a technical product marketer, I was our marketing security guy for a few weeks as we tracked down all these accounts and reset passwords. And luckily I was able to set up an organization and reset all the emails, reset all the passwords for the offboarding process, but also kind of secured it moving forward. So actually when my contract expired, all they had to do was go into the organization, remove my account from the password manager and then just reset all the passwords and everything was kosher. So yeah, that's a great feature. Yeah, and unfortunately that is a story we hear time and time again, right? Is someone leaves with all the keys to the kingdom or all the passwords for a particular kind of function within the organization, especially at startups. I see that a lot. And so this is really a way to simplify that, right? You're trying to streamline IT admins time or even technical product marketers, making sure that they don't have to spend all that time tracking down these logins or creating new logins because that's just a real pain. No one wants to do that. For sure. Well, Kasey, so aside from the Bitwarden website, is there anywhere folks should go to learn more? Yeah, bitwarden.com, you can start a free trial there or even set up a free account and maybe upgrade to premium like Eric did. But yeah, that's a great place to start. Yeah, it literally was some kind of a personal record. I use Bitwarden for all of like 10 or 15 minutes. I was like, here, take my money, sold. I mean, I will say there are a lot of great features in the premium plan, right? So that's where you can store TOTP codes, share those across different users. I use masked email addresses and you can generate those in Bitwarden, which is really cool for some of your more secure logins. There's lots of different things you can do if you decide to use the premium plan. But always free as well. So what's kind of funny is I saw a beautiful use of the encrypted send feature. Oh yeah. So Shelby and her husband have a shared game server that they host. And so they sent an encrypted Bitwarden send, dropped the URL into our Matrix room and shared it that way. I was like, this is such a professional use of Bitwarden features for a shared game server. This is perfect. And for those who are listening to Bitwarden send is essentially a functionality where you can send text or encrypted files to anyone. So I use that whenever I'm doing my taxes, right? To make sure that I'm sending all my information securely as opposed to just randomly attaching, you know, tax files in an email somewhere. And what's cool is that there's actually a new feature addition to encrypted sends as well, where you can specify the email of the person who will be opening it. So unless that, so the receiver essentially has to have access to that email inbox to access your encrypted send. So really helpful for those who, you know, I wanna make sure that this send is only going to a very particular person. So tax accountants is a great example of that. I guess if you have a video game server, you know, sharing that kind of information, there's so many different use cases. I've been forcing my husband to use it for quite a long time now and he's finally on board. Nice, well, congratulations on that home victory. I know what it's like to try and get family to standardize on tech. Oh yeah, oh yeah. Also, yeah, a great mention is that, you know, because Bitwarden is free, it's a really good kind of first step towards, you know, getting family members, getting friends on, you know, secure password management. That's a really good kind of like starting area, right? I've done that countless times at this point for the people in my life, one, because I know Bitwarden very well, but it's also a really good starting point. For sure, yeah, that is a great piece of advice. So head over to bitwarden.com, make sure you sign up, enjoy the free trial. It is a fantastic application. It is one of the few areas of my life where, I guess, of my technology life that I'm not concerned about. Bitwarden's not going anywhere. The features just keep getting better. I'm really excited to see the new UI when it comes out. So there's just plenty of features to work with. In fact, I think I mentioned earlier in the show that I'm using the barest percentage of what Bitwarden's capable of now. So I'm going to have to spend some time in the coming weeks playing with it and seeing what areas of my life could be easier and or more secure. So, Kasey, really appreciate, go ahead, go ahead. Oh, sorry, I didn't mean to interrupt. I will say the Bitwarden subreddit too, there's so many people that are so excited about using Bitwarden that they share a lot of their use cases there as well and how they set up their personal workflows. And so there's lots of really cool tidbits you can learn there as well. I may or may not have joined that subreddit when you mentioned it the first time. Fantastic. Yeah, people in the audio version have got to wonder what it is that I do during recordings. But yeah, I joined the subreddit when you mentioned it. No Bitwarden had one. But yeah, definitely check out the Bitwarden subreddit, check out the Bitwarden websites. They've got an amazing blog as well. Kasey and her team do a fantastic job of putting out new content. So definitely go check that out if you want to learn more about Bitwarden. In the meantime, this has been episode number 26 of the IT Guy Show. Really excited to see the show growing. In fact, I've brought in a consultant. You all know him, Noah Chelliah of the Ask Noah Show is actually going to be consulting with me to help get the word out, produce some better content. So definitely keep an eye on the channel. And if you have any nerdy friends who are into Linux, open source, careers, burnouts, D&D or just ridiculous dad jokes, make sure to share the channel with them. Like I said, the channel started growing again. We kind of stalled out over the spring, but glad to see that more people are finding the content. So it's not just me shouting into the void. As I mentioned at the top of the show, we've got 45 homelabs coming up in two weeks. So that'll be middle of August when that show airs. Really excited because I've got all kinds of questions for my homelab, my own use cases from Plex to Podman to bootc. So I'm really excited to talk to them about hardware. So I can finally lay my Dell PowerEdge R720 to rest. Poor girl, she's had a long busy career and looking forward to not having to pay colo fees anymore. So if you're interested in buying new hardware, definitely check out the 45 homelabs episode here in a couple of weeks. Until then, you can reach me on social media. I'm at IT Guy Eric, just about everywhere. And you can follow Kasey and Bitwarden at bitwarden.com. And so on behalf of my guests and myself, thank you all for joining us and we'll see you again next time.