I’m happy to hear it
. Thanks for fixing this so swiftly, I can confirm it works as expected now.
I’ve been reading about this project for sometime and now its the time to test it after the new changes in Bitwarden
The first thing I was searching for is changing login folder which took me sometime to figure out as it was so small ![]()
are you using AI to build this app?
No, AliasVault is not an AI or LLM generated project. I’m the main developer, but the project also includes and accepts contributions from outside contributors.
As the core of AliasVault’s logic revolves heavily around encryption and other security-sensitive code, this requires thorough system knowledge. Contributors may use whatever development tools assist their work though (including AI assistants), but every contribution must be personally authored, reviewed, tested, and understood by the person submitting it. Contributions that do not meet this standard are rejected.
You can read the full project policy regarding this on GitHub here.
Asking cause it has an AI feel to it. May be just me then thanks for engaging
I was thinking about self-hosting this, but I’m getting that impression as well. This section of the insallation page, for example, will definitely look very familiar to anyone who has vibecoded. It’s similar to the “Not just X, but also Y” of AI writing.
I also stalked (sorry lol) the developer a bit and there’s clearly heavy AI assistance in his comments and posts, including this one of course.
I’m not against using LLMs for programming, but this all gives me a bad feeling about code quality and security. I did a very basic search and looked for em-dashes in the code, and there seem to be some. That seems to confirm the AI assistance in the code, unless the developer likes to use em-dashes in his comments for some reason.
Anyways, what I wanted to mention with this is that I don’t think I trust AliasVault with my passwords and entire online life. You just don’t want don’t want a “bad-feeling” about things like this. I self-host my stuff, so I’ll stick with Vaultwarden and SimpleLogin. A security audit could change my mind though.
That’s just my opinion and skepticism though, I know this depends from person to person.
On the other hand, it would concern me if a project wasn’t using AI to secure their software.
Writing comments is totally different, but unrelated is that I don’t like it because it feels rude. It seems more reasonable to me to use AI for coding than for conversing with other people. I’m not stating if the dev of this project uses it for communication, I haven’t looked.
The SimpleX developer has said in the public chatroom that he uses AI extensively and barely writes code by hand. That’s a project that has had two audits (third in progress) from Trail of Bits and has been recommended by GrapheneOS. Google and Apple are also using AI extensively which we can see from the recent Chrome record amounts of bugfixes and there’s been tons in Android.
AI doesn’t necessarily introduce more bugs than human-written software. Vibecoding completely might be a bad idea for any software, though. I think it depends a lot on the developer steering the models.
This project was released before, as I remember it, AI had become incredibly useful and popular for coding. And the developer did say they had been a swe for many years.
Anyways, I also would probably not use it unless there was more auditing and eyes and more time.
I also feel this way. This seems like a prudent decision for yourself. I would not want to use something so important that I don’t trust, regardless of if that trust or distrust is warranted.
Hi @birb, thanks for your message! To start: I fully understand where your (and other’s) concerns regarding AI use are coming from.
However, generally speaking here and on a personal level I find it really disappointing (and potentially damaging) to see AliasVault, or any other project being dismissed as being “AI-generated” or “vibe-coded” based on a few screenshots, docs website, and broad assumptions.
To clarify a bit more on this topic (and re-iterate what I wrote about this earlier):
My personal view is that using AI to speed up certain low-risk and repetitive tasks is a perfectly valid use case. Also using AI for security reviews and a always-on second pair of eyes is a great way to catch potential issues early on in the development flow. With more than 15 years of professional software development experience, I am capable of judging where using tools like this are appropriate (net-positive) and where they are not.
The other side of the medal is real though: attempting to build a password manager (or any other serious application) in a weekend using AI and immediately publishing it, that is a very different matter. That is where poorly understood code, maintenance and security risks arise. This is a serious challenge for the software development world (and self-hosted community in particular), resulting in the abundance of the so-called “AI-slop”. With the current frontier models at their disposal, basically anyone can prompt a (seemingly) functional application to life in a matter of days. But how do you tell the difference between AI-slop and real thought out products? That’s a real and valid question.
AliasVault however, is the result of 2,5 years and approx. 2.000 hours of manual work invested. It is not an AI-generated or “vibecoded” project in the slightest. Everything, including the architecture, security logic and cryptographic components are all carefully designed, reviewed, and tested with countless of hours invested. Also we actively listen to the community, work with independent security researchers and prioritize fixing bugs before we introduce new features.
Judging a project based on a few screenshots, install documentation, or literally em-dashes in code comments is not a meaningful assessment of the quality or security at all.
What you should instead judge a project on is the architecture, security model, issue history, roadmap, responsible disclosure process, etc. We are also working on getting a full external security audit done, which is planned for later this year. As I mentioned before, this is a very costly exercise for an independent product with (purposefully) no VC investors behind it, but thanks to alot of persistence and great help from the community, step-by-step we’re getting there. This is something I’m really proud of.
Regarding your mention of trust: that in the end is indeed personal and up to the user what they feel comfortable with. That is why it’s a good thing that you, as the user, can choose between multiple (open-source) products and make your own informed choices. Scrutiny is always a good thing, especially with products handling sensitive data.
I hope this answer provides some clarity on my position and AliasVault’s stance.
100% agree.
And to the points about UI language seeming to resemble (at least to some) AI content, I’d submit that it’s an important fact that all slop that AI produces is based on prior art. UI design and language, marketing-ese, em-dash-happy writing, and easy-to-read listicles (for another example) have been around for many years longer than AI has been around to imitate them. They’re patterns that exist in particular niches because they’re successful, because they’re lasting trends, or both. The fact that AI now imitates them does not make their presence clear indicators that AI produced them.
I don’t have a horse in the race other than I’m excited for another alternative in the password space, and hope for AV to succeed in its upcoming security audit.
I have to agree, my judgement on this project was not very good. I was initially going to mention a few other examples in the app and website, but I realized that UI is really not a good indicator of project quality or security. I’m actually going to be saving your list on what to judge a project on in my notes for the next time I come across a project with an AI feel to it.
Also, I’m sorry if my comment was overly negative. I did not mean to bad-mouth the project. I think it is a very promising project and fills a nice niche.
Anyways,
I don’t fully agree with this. As a heavy LLM user, I have noticed that AI’s writing style and UI language is actually quite distinct. It’s almost like the prior art you mention, but it just feels off.
I don’t know man, ask me to spot AI if some UI or text is at least partially generally by AI, imho I think I would be to do it pretty consistently. There seems to be a study citied on Wikipedia that supports this for text.
It is worth mentioning that it is still unfair to judge an entire project on just a single or cuple of screenshots. Coming back to AliasVault, my previous message did give the impression that I was judging it only by that, and possibly encouraged others to judge the project on only that screenshot; that was not very great on my part.
Hi
I have just come across AliasVault and like the look of it. I have been using Roboform for many years. I tried to import all Roboform data bit no site names or Safe Notes names were imported. I deleted all and decided to re-enter all currently relevant Safe Notes and all Logins on a case by case basis over the next few months.
All the best for the project.
Chris
Hi Chris,
Thanks for trying out and using AliasVault!
If possible, would you be able to share an anonymized example of the RoboForm CSV file you tried to import? Perhaps the column names have changed on RoboForm’s output side, if so, we can fix that on our end so it will start working for other users too.
If you could share just the first few rows of the CSV including the header column names and some example records (removing/replacing any actual sensitive info) should be enough. You can send it via PM here on PrivacyGuides or via Discord. Thanks in advance!
Here is a short file with Roboform Safe Notes and Logins. Hopefully I haven’t ruined the order.
Chris
(attachments)
SampleRoboformData.csv (1.29 KB)
Thanks for the example file! Based on this, I’ve done some further investigation and found the likely issue. It appears to be related to how RoboForm generates its CSV output: it seems to add a BOM (Byte Order Mark) at the beginning of the file, which causes the first line/row to be parsed incorrectly. As a result, the titles of the items in that row are not being parsed correctly.
Other password managers that we support do not seem to experience this issue. I have now added a fix to the import mechanism which should fix this issue for all future imports. The fix will be included in the next (minor) release.
So thanks for taking the time to report this issue! Will help other people in the future as well. ![]()
