rsyring 1 day ago

Very insightful blog post listed by another user as a sub-comment. Worth posting as a top-level comment:

https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden

Previously discussed: https://news.ycombinator.com/item?id=48163389

  • nugget 1 day ago

    Great find. This blog post - and specifically the background of the new management team - convinced me to start looking for a Bitwarden alternative. I’m watching the same “boil the frog” strategy unfold at Namecheap, and erode much of the brand trust they had built up over a decade, and it’s a shame.

    • turtletontine 1 day ago

      Have you settled on a BitWarden alternative, or a short list you’re considering?

      • birksherty 1 day ago

        Proton Pass. I stopped using Bitwarden for a different reason, the mobile app was too slow when not connected to internet. I can't accept such slowness, the company will definitely give justifications for this. But I don't care, let me see my passwords or notes for a website immediately. Proton Pass is better in this regard.

        • doodlesdev 1 day ago

          Proton Pass cannot be self-hosted.

          • missmewiththatl 1 day ago

            As a self-hoster, I don't think password managers should be self-hosted.

            • Oxodao 1 day ago

              On the contrary. If there's one thing you should self-host is definetly password manager.

              • nine_k 1 day ago

                Why, you can of course self-host it, too, but the infrastructure should be entirely separate.

            • cortesoft 1 day ago

              What? Why not?

              • torzer321 1 day ago

                password managers should not involve hosting at all, use something file-local, keepass(xc) or alike

                • SV_BubbleTime 1 day ago

                  Keepass people always in these topics with ”offline rules!! … now let me tell you how I use it with a copy on my phone and sync it with Dropbox and a backup on a git repo”

                  • SmashDan 20 hours ago

                    I setup it up for myself once and it was too much effort, and I found the browser integration very poor compared to Bitwarden.

            • tappio 1 day ago

              I don't see much reason not to self-host a properly built password manager like Vaultwarden or something similar? The clients keep a local encrypted copy of the vault, so the server only needs to be up for syncing. If it went down for a week, you probably wouldn't even notice unless you were saving new logins. And even if the server got hacked, everything on it is encrypted. Why do you think it should not be selfhosted?

              • Barrin92 1 day ago

                you just listed all the reasons why you don't need to self host yourself

                • SV_BubbleTime 1 day ago

                  Thanks, on these topics I feel like I’m fucking crazy for not wanting to self host.

                  If you believe that the technology works, that encryption is happening and that the decryption is only happening on your local machine then why in the fuck would I host this myself?

                  You need to believe that it does not work when they do it, but does work when you do it.

                  I have not seen any evidence of that.

                  • tappio 14 hours ago

                    It works just fine when they do it as long as they want, that is not the point. For me self hosting is a mostly a question of independence and digital sovereignty. We've seen all kinds of service providers turn into garbage over time, so I'd rather not rely on a company that needs to extract as much money from me as possible.

                    • SV_BubbleTime 57 minutes ago

                      So what do you think the threat is? That they’re skimming data off with their extension? That they’re going to close up shop and take your encrypted vault with them? That they’re lying and storing your master and then peeking at your vault?

                      In order for snooping to be true, the extension would need to phone home what you’re viewing and I think that would be a pretty big no-go with everyone.

                      In order for them to close shop and take your vault… do you have any serious reason to assume that might happen? I’m sure it’s happened with X or Y obscure company before. Does it seem likely at bitwarden’s size? Is this threat not just as equally remedied with your own paper backup?

            • jazzyjackson 1 day ago

              Can’t relate. If you’re worried about you’re own reliability to keep it online, just keep paper backups

          • sliken 1 day ago

            As as self-hoster, I recommend vault warden. Supports 2fa, written in rust, works pretty well, is easy to backup, and you can use bitwarden's phone client.

            I'm curious why other self hosters think it's a bad idea.

            • movsx 1 day ago

              Presumably, it's a memory hog. What is your RAM usage?

              • rented_mule 1 day ago

                For me, vaultwarden's RSS is ~45 MB, with ~13MB of that being shared. I have it running as a secondary thing on a 512 MB machine and don't notice it's there. Is there a reason you presume it's a memory hog?

                • movsx 1 day ago

                  I'm surprised, actually. I expected at least an order of magnitude more. In my humble opinion, this is still a lot of memory -- probably an order of magnitude (or even two) more than what is realistically required for the task. But this is just my own philosophy, and I do realize that the days of careful memory utilization are long gone.

                  Thanks for sharing.

                • nh2 1 day ago

                  For me, RSS 35 MB, SHR 23 MB. The vaultwarden executable is 38 MB (typical Rust executable that links Rust code statically, and only dynamically links libssl.so and libc.so dynamically).

                  So probably its RSS usage is just mostly its own executable code?

              • ulimn 1 day ago

                I think the memory hog you're thinking of is the official Bitwarden self-hosted backend. Vaultwarden is pretty light on resources.

            • dwedge 1 day ago

              > and you can use bitwarden's phone client

              What will you use when this stops working in the near future?

              • zeendo 4 hours ago

                Why does everyone act like this hypothetical (and however likely) future is something that needs to be acted on now?

                I'll just export my vault and move to KeepPass or something else?

            • BrandoElFollito 1 day ago

              I moved to the cloud for a simple reason: if I die tomorrow people who depend in the service are screwed. And this is an important service, like email or digital archives.

              • nightski 1 day ago

                I'm confused, so you are self hosting it for other people?

                • BrandoElFollito 22 hours ago

                  Yes I was - for me and my family (and a few friends)

                  • nightski 19 hours ago

                    Yeah I have no problems letting family and friends use cloud services. I keep the self hosted stuff for myself.

            • zeendo 4 hours ago

              Because people don't trust themselves to do proper backups as if this is some kind of black magic or something.

              I've been self hosting Vaultwarden for me and my wife for years without issue. People like to tell others what they should and shouldn't do because they want to feel superior to others, I suppose.

              It's especially strange since self hosting is, aside from the 'fun' aspect of it, about personal control. So this tsk tsk'ing from others about self hosting a password manager is especially ridiculous.

          • jchw 1 day ago

            I am using Keepass XC + Keepass DX synchronized with Syncthing. There's really nothing to self-host, other than throwing Syncthing on a NAS so you can make sure you have at least one machine online at all times. But even that isn't critical, since both Keepass XC and Keepass DX have a "Merge" option if anything falls out of sync.

            • jonny2811 1 day ago

              ive used keepassxc forever, switched to proton pass after the release, because i was managing my db in git and it was always a pain to keep in sync, but switched back a couple of weeks ago with exactly the same setup, syncthing and KeepassDx also works suprisingly well.

              mostly i was missing power user features and especially ux for the browser plugin, namely you can't operate it fully with the keyboard, with keepassxc you can

          • zikduruqe 1 day ago

            But passwordstore.org can.

            No reason to use anything more complicated.

    • backlit4034 1 day ago

      GlassDoors reveal the other side of the story

      https://www.glassdoor.com/Reviews/Bitwarden-Reviews-E4337610...

      • alt227 1 day ago

        Wow, another site that now refuses to play ball unless you sign in.

        Guess I'll never be visiting Glass Door again then.

        • to11mtm 1 day ago

          GlassDoor has been gross about this for years.

          Not sure if still the case but normally you have to not only 'sign in' but also feed them information (e.x. salary at a position, write a review, etc.) in order to be able to view much of anything.

          They also do not give a shit about obvious 'juicing' (i.e. when it is obvious that upper management and/or HR is adding reviews where the 'con' reads like one of those softball warning phrases in a job description.)

          • encom 1 day ago

            This is the fate of every online review site. Every single one. Including IMDB as I realised yesterday while trying to find something to watch.

            The most egregious example I've found was that the Danish postal service had something like a 4,8/5,0 rating on Trustpilot. You'll be hard pressed to find a more inept, corrupt and universally hated company. So in an attempt to improve their public image, they decided to game the ratings, instead of actually delivering mail properly.

        • chanux 1 day ago

          I can kind if understand how forcing everyone to add on to the pile of content, from a business point of view.

          However they may have proved that they are indeed.. trash. Maybe even a few times.

          One such case was https://www.forrester.com/blogs/glassdoors-mishandling-of-cu...

          In my eyes they are in the same class of Facebook, uservoice, Pinterest, Quora etc.

          • demibabs 23 hours ago

            What’s wrong with Pinterest? (I don’t use it)

        • happosai 1 day ago

          With the AI(?) bots doing a DDOS on on public websites via residential proxies the future is all website will require login.

          • waltbosz 1 day ago

            Can't the bots just sign up for accounts?

            • happosai 1 day ago

              Yes they can. But then you see which account as took part of the DDOS scraping, and delete all accounts that match the pattern and site gets back under control.

              Fundamentally it's all a game of whack-a-mole for admins unless some kind of microtransaction system is invented. Then a DDOS scraping event is just extra revenue.

          • nine_k 1 day ago

            In the specific case of Glassdoor, leaving a review about an organization sometime requires a proof that you work there, e.g. receiving a pass code sent to a work email. I'd say that this is reasonable, and makes gaming the reviews much harder.

        • wiether 1 day ago

          Ironic, given their name.

        • RobotToaster 10 hours ago

          I can't even get that far, it just gives me an infinite cloudflare verification loop.

      • latchkey 1 day ago

        it goes into an infinite redirect loop for me. lol.

      • e40 1 day ago

        All but one of the reviews for my company are completely fake (at Glassdoor).

    • jazzyjackson 1 day ago

      What’s wrong with self hosted vaultwarden ? I guess there isn’t a FLOSS extension client/app?

      • dwedge 1 day ago

        Presumably the bitwarden apps will stop working with them eventually

        • pas 1 day ago

          addig Vaulwarden compatibility to already FOSS mobile password managers might be the path of least resistance

          or pooling together tokens and asking Claude nicely to make a mobile app

          • limagnolia 1 day ago

            Or just fork the OSS bitwarden client?

          • dwedge 1 day ago

            With android changes this year how do you deploy it?

      • jdboyd 18 hours ago

        Today, Bitwarden works as the FLOSS extension client/app. Next year, maybe Bitwarden won't be, but we will still have the source for today's code which can be forked and carried forward. I like to think there are enough users behind Bitwarden that a fork would likely work out if it came to that. For that reason I'm not jumping ship yet.

    • jventura 1 day ago

      > I’m watching the same “boil the frog” strategy unfold at Namecheap, and erode much of the brand trust they had built up over a decade, and it’s a shame.

      What's happening with Namecheap? I've been a user for a long time and haven't noticed anything.. Maybe I'm one of the frogs being boiled!

    • alasano 1 day ago

      That's funny, Bitwarden and Namecheap are the two things I've migrated away from as well.

      The switch to Vaultwarden was insanely easy.

      • movsx 1 day ago

        Just curious, why Namecheap?

        • alasano 23 hours ago

          I honestly don't remember what annoyed me at first.

          But auto renewals not working at times for some reason, credit cards not being saved, prices rising vs competitors.

          Just switched everything to CloudFlare since I'm always pointing to it anyways and use a lot of their services.

  • Wowfunhappy 1 day ago

    Unfortunately, any "insight" it might contain is ruined by the fact it's clearly written by an LLM instead of a person.

    > And it never comes in a single dramatic announcement. It comes in layers. A feature post with a price change inside it. A LinkedIn update nobody made a press release about. A values page that says something slightly different than it did last week. If you’re still on Bitwarden cloud and this is giving you pause — it should. [...] Whether self-hosting stays viable long-term is the real question worth sitting with.

  • dizhn 1 day ago

    Started humany but degraded into LLM speak towards the end. Especial the Vaultwarden section.

    • alt227 1 day ago

      So? It was useful information, who cares how it was written.

      • tuwtuwtuwtuw 1 day ago

        I bet most people that reads blogs care about how they are written.

        • alt227 1 day ago

          If people dont like how something is written they can move on, they are not being forced to read it.

          • tuwtuwtuwtuw 1 day ago

            Of course. Or, as we see here, they can critize the content that they thought was badly written. That's also allowed.

      • subscribed 1 day ago

        The information is there, and could fit one paragraph.

        Everything else is just a nonsense, watermark and fluff, scamming from time and attention - there's NO value in the filler.

        To reiterate: there's no value in this sort of the LLM garbage. There's value in the information, especially when formatted and provided in the humane format.

      • dizhn 6 hours ago

        For me personally the information itself become suspect when I notice it was AI generated. I am not intimately involved with every single topic to know the difference.

    • stavros 1 day ago

      It's all LLMese, start to finish. I found it hard to get through. Could have just been a bulleted list and it would have been better.

      • formerly_proven 1 day ago

        Over 1k words for something which fits in two paragraphs. Painful.

      • Panzer04 20 hours ago

        I bet it was a bulleted list before they fed it into an AI.

        I don't understand why some people feel the need to turn a few hundred words if concise description into thousands via LLM.

  • Aardwolf 1 day ago

    Ok this is doing some damage. What's a possible alternative that works on both mobile and desktop, doesn't require yourself to run a server, and doesn't have worse reputation?

    • orta 1 day ago

      I like Enpass

    • terminalbraid 1 day ago

      keepassxc works across any major platform, mobile platforms have keepass2android and KeePassium. You don't have to run your own server, but you do need some type of file sharing system to keep them synced. I personally run a webdav share on a vps with some sync scripts to keep a backup on devices otherwise. OneDrive, google drive, dropbox, and others work.

      Also protonpass.

      • GordonS 1 day ago

        Any good reason to use keepassxc rather than regular KeePass?

        • qwerpy 1 day ago

          At the time I decided to go with regular keepass, it was because setting up OneDrive sync (directly to OneDrive, not depending on a mapped folder because I use as little MS software as possible) and browser extension was easier. And the cross platform UI on KeePassXC just didn’t look and feel good on windows.

          • GordonS 1 day ago

            I still mainly use Windows and Android, so if cross-platform is the only real reason to switch, I think I'll stick. I have it syncing over SFTP, works great.

      • Arrowmaster 1 day ago

        I specifically moved away from KeePassXC to Bitwarden with self hosted vaultwarden because the Linux desktop experience and mobile syncing was so terrible. While I love KeePassXC, using it on an immutable Linux distro where everything needs to be Flatpak means the browser extension doesn't work because it doesn't support Flatpak'd browsers back when I switched. Auto type is a security nightmare and is not an option. Syncing does not exist and with the constant death and forking of Syncthing on Android, it became unusable to randomly find out my db hasn't synced for a week and now I have to reset everything with a new fork yet again.

        Bitwarden was the no nonsense choice because it just worked.

        • philsnow 1 day ago

          I used to use gnupass and its variants (including passforios on mobile), but what brought me to bitwarden was being able to make changes on two clients and merge the results cleanly / usefully without needing to do anything manually at all.

          How does this work with keepassxc? Does it depend on your file syncing primitive?

          • Arrowmaster 1 day ago

            When I stopped using KeePassXC, there was no merging. You configured each client to save immediately and reload when detecting the file changed. If you used a tool like Syncthing then you had to monitor for conflicts (which stopped syncing) and manually fix them. If the major clients on Linux, Android, and browser extensions all supported proper syncing on their own, I might switch back.

        • Semaphor 18 hours ago

          Mobile syncing works extremely well for me with Keepass2Android and webdav. Includes merge support. The sync story on Android is imo the best because of that.

    • Lapel2742 1 day ago

      Proton Pass?

      I already have "Proton Unlimited" as a subscription but until now I never used Proton Pass. I thought about giving up on Bitwarden for some time and probably will try it now. AFAIK you can even import your Bitwarden logins.

      • InsideOutSanta 1 day ago

        I think Proton Pass is currently the best non-self-hosted option, and Proton's corporate structure offers some protection against enshittification.

      • mpern 1 day ago

        FWIW I moved to Proton Pass after I read the blog post months ago. The switch was seamless except for passkeys (had to enroll new ones; back then I only found a tool to convert Proton Pass passkeys to Bitwarden, but not the other way around)

        For me, Pass works much better, especially passkeys on Android. Bitwarden was very flaky in that regard, Proton Pass "just works".

        I use Pass for personal logins and sharing family-related accounts with my wife.

        • a012 11 hours ago

          I discovered that only Proton Pass works on my old Android 9. I guess this is the way to go.

      • rpozarickij 1 day ago

        I'm really happy that Proton Pass provides an option to copy the username/password when you right click on an item. In the Bitwarden macOS app you have to click a dedicated copying button which feels so unintuitive and I had to consciously think about this every time I needed to copy a username/password. And Bitwarden has so many other things that could be improved in its UI, but due to muscle memory I forgot that there exist other password managers out there. So far Proton Pass seems to be much more polished than Bitwarden. Except it took me a while to find how to enable 2FA, which is in "Account and password" (not "Security and privacy") in the account settings.

      • attendant3446 1 day ago

        Proton Pass has a good backend, but their clients are so-so. Specifically, the auto-fill feature in both browser extension and Android client. The browser extension is also pretty buggy, keeps forgetting settings, and occasionally logs me out.

    • frevib 1 day ago

      Proton pass.

      Proton ticks all good-company boxes. E2ee, majority owned by the Proton foundation, all client-side code is OSS, and some other structures in place to protect themselves from corp greed. Best I could find.

      • sylos 1 day ago

        Didn't it recently come out that the ceo of proton was donating to far right groups interested in dismantling privacy and security, let alone their racist policies?

        • fph 1 day ago

          You might be mixing them up with Mullvad.

        • Bloating 1 day ago

          In so far as google translate and my adhd filter can tell, he donated to political party that support marxism … maybe people are figuring-out that authoritarian happens on both sides to the 1 dimensional political spectrum

    • whynotmaybe 1 day ago

      Keepass on pc, keepass2android on mobile and the file is stored on onedrive. I'm starting to use macos so I'll install onedrive on it. Now onedrive's reputation is Microsoft's but I haven't heard of massive security breaches like many online password manager had.

    • TeMPOraL 1 day ago

      Writing password down on paper and keeping them in your wallet.

      Seriously. About as secure, if you're honest about the actual threat model (vs one security aficionados would like you to assume), and paper can't be enshittified.

    • CrimsonRain 22 hours ago

      Enpass.

      Current offerings are ok. But they had a pay once model before which they grandfathered in. I got lucky. It's amazing and no bullshit software.

      Has apps from everything including browsers. Can use any cloud storage as vault. Supports un Pass passkey totp pin and everything you can think of.

  • Cort3z 1 day ago

    I hate this. So much software I love keeps doing this. redis, docker, now bitwarden. I was so happy with bitwarden. Been a premium subscriber for many years. I have helped convert many people, including whole companies, to use this. Now they are doing us such a disservice. We need a completely free, no-nonsence, alternative. I wonder if it is possible to do a ipfs/torrent version without a central authority to permanently prevent this type of issue.

    • zackmorris 1 day ago

      I wonder that too, perhaps by encrypting the data with a key generated from a long passphrase meaningful to the user, that nobody could possibly guess. Then just store the data in a permanent cloud like IPFS, pinned with 4EVERLAND, Filebase and/or Pinata:

      https://docs.ipfs.tech/concepts/persistence/#pinning-service...

      Maybe someone could write a provably private client-based browser decryption script, hosted on various websites. We might need a new browser spec that sandboxes pages until they're unsandboxed, allowing them no egress/ingress or even local storage or cookies.

      Or better yet, take that choice away from browser vendors, and create a runtime in the browser that simply can't be observed, perhaps by using zero-knowledge proofs.

      Writing this out, I wonder if the issue is due to longstanding incomplete browser architecture, going back to when the web went mainstream in the mid-1990s. Or maybe it's still just an open problem.

      Solve private distributed durable storage, along with a base level of secret computation eventually running about the speed of a 6502, 286 or 68000, and we wouldn't need free services that inevitably get privatized and ensh!ttified.

      I have no idea if something like this already exists, I'm just speculating as to what base functionality it might need from first principles.

      Also I wonder if similar techniques could be recruited to build an OS around cryptocurrency. That way a meta economy could run alongside the corrupt economy, and shield users from currency devaluation and other wealth inequality drivers used by the ultra-wealthy to increase the value of the means of production that they own relatively, so that they can buy more.

      Arguably the process of wealth concentration is so fundamental that it puts a countdown on capitalism, driving it towards the late-stage capitalism that we've had since about 1970 when productivity diverged from wages, and eventually revolution which results in socialism/communism or even permanent authoritarian dystopia like on Star Wars. In a way, it's in the best interests of the ultra-wealthy to build meta economies, which of course makes those economies suspect and probably vulnerable to exploits, especially in the AI age. We've seen how crypto has created black markets capable of capturing governments, so maybe we should be careful what we wish for.

      But really I just don't want to type my password anymore.

      • haruka_ff 1 day ago

        Nit: IPFS is never a "permanent cloud", even with pinning services - you stop paying, eventually the data will be gone as no one will serve it anymore. You might be looking for Arweave for better permanence, which 4EVERLAND also supports as a storage target (although there is no way to "update" the data as well)

    • atomicUpdate 1 day ago

      Why stop at a free password manager? Why not free food, clothes, cars, and everything else while you’re making demands?

      Or is it just software that has zero value to you because it’s intangible and you intentionally ignore the time and effort other people spend on it?

      • vuldin 1 day ago

        I think most people don't mind paying for software, they just mind situations like having to rent software forever (subscriptions), or software companies being ran by people who are only focused on increasing revenue at the expense of actual making good/better software.

        • lokar 1 day ago

          I think subscriptions are fair if you want updates, which for anything security related you do. The alternative (from decades ago) is to re-buy it every few years.

          Someone has to pay for ongoing maintenance.

          • nightski 23 hours ago

            This isn't about cost. If these projects, like bitwarden, were run at cost the price would be negligible. Instead you see software companies with like 80% margins (or even higher). Not to mention that if the price was reduced to near cost then you'd get more users which would even further decrease the cost.

            • lokar 7 hours ago

              I’m not sure why people focus so much on costs as a driver of prices. They provide a floor on prices (past which it’s unprofitable). But prices are set based on demand and competition. And here there is no “lock in” or monopoly, it’s fairly easy to move between several password managers.

      • Cort3z 1 day ago

        Did you even read what I wrote?

      • TitaRusell 1 day ago

        Firefox comes with a password manager built in. Gratis.

        • figmert 20 hours ago

          Yes, and it has no way of doing autofill in anything but firefox. And has barely seen any love for a long time

    • parineum 1 day ago

      I still use docker and redis for free and it seems like I'll be able to continue using bitwarden for free. I don't see what I've lost.

    • lisp2240 1 day ago

      What we really need is an alternative to capitalism

      • halfcat 1 day ago

        There are many alternatives.

      • KetoManx64 18 hours ago

        > a socio-economic system based on private property rights, including the private ownership of resources or capital, with economic decisions made largely through the operation of a market unregulated by the state.

        I don't think you understand what capitalism is, or you've spent no time at all looking into how many hundreds of millions have been killed under socialism, fascism, crony-capitalism, or any of the other means of exchange that involve force.

        The federal government printing infinite money is the reason that companies need to constantly keep increasing profits, otherwise they will just ground down by the annual 15% inflation rate.

    • pjmlp 7 hours ago

      Maybe devs should pay for their tools like other professionals, and how we used to do in the last century, e.g. open any random BYTE digital archive.

  • axelthegerman 1 day ago

    Thank you for linking this, the price increase was indeed communicated to me directly via email but not very clearly

    > The price is updating to $1.65/month, billed annually.

    Followed by a 25% discount for this reveal only.

    Have to go back to my old invoice to see it was $10/y and now the new one $19.80/y

    I never liked that I needed to pay premium just for 2FA but this abuse of trust is definitely the end of it.

    Too bad I won't get a refund for my Oct 1st renewal but I'll happily cancel as soon as I get vaultwarden hosted.

    • theturtletalks 1 day ago

      SSO is the feature many companies put behind their most expensive plans. It's exactly why the personal software revolution will take over SaaS.

      The argument here is always why would people spend all this time and money to build custom software when they can just pay a company $20-100 bucks a month? Because that product will become enshittified. It's not a question of if, its a question of when. I thought open-source SaaS would be immune, but clearly not.

      • TeMPOraL 1 day ago

        SaaS is what killed open source. "OSS SaaS" is just the resurrected undead abominations that somehow manage to trick the peasants and pass off as living.

        If you excuse a Warcraft-y metaphor.

    • snailmailman 1 day ago

      One benefit of the current self-hosted option via vaultwarden is that you get 2FA and the other premium features by default.

      But it is worrying that they might intentionally break vaultwarden in the future.

  • microflash 1 day ago

    This post is what triggered me to cancel my subscription and migrate away from Bitwarden in July. I’ve seen too many repeats of this show. This has completely soured me from cloud-backed critical software. Slowly moving toward offline alternatives wherever possible and self-hosting when it isn’t.

  • hannasanarion 1 day ago

    Is there any writing on it that was written by a human? This blog post is clearly AI.

    It's somewhat concerning to me that none of the security conscious people in this thread seem to notice that they are changing their privacy practices based on the advice of a language model pretending to be a person.

  • ok_dad 1 day ago

    Excellent now I have to find something else again. You can’t fucking trust anyone not to chase money these days.

    Fuck bitwardens creators for selling out. I want them to know they fucking suck.

    • bonestamp2 23 hours ago

      > You can’t fucking trust anyone not to chase money these days.

      I don't even mind paying a reasonable amount for Bidwarden (as I do) or other things I find valuable, but it's the unlimited growth of profit that disgusts me. My Grand Father, Father, and myself were/are all business people (in very different industries) and we'd all be ashamed to double the price of something simply for more profit.

      • pjmlp 7 hours ago

        This phenomenon started to take effect when companies moved into being managed by MBA folks without any role into making the companies happen in first place, the introduction of CEO and administrative board, and so on.

        Usually this was never an issue when becoming the one at the driving wheel, was due scaling up the ladder all the way from the bottom, or having the luck of being in the owners' family already.

        Disgustes me as well, above all the layoffs only to give the money to the "poor" shareholders.

  • onel 11 hours ago

    That's a great article, but I think the author is over emphasizing a bit on the fact that the guy has PE connections. I also think that's most likely that will go in that direction, but IDK if that's the reason for it.

    I think we need to be a bit more aware of our expectations from free products. By the end of the day on the free tier, and as long as you're not paying, you are a cost to the company. I think most of these problems go away if we don't rely or expect that much from free products. If we pay a little bit, even if it's just for the compute when self-hosting, it creates much healthier relationship.

    The post also mentions GitHub. Let's be honest, they created a lot of value with the free tier, but we also can't have high expectations for a service we're not paying

dannyw 1 day ago

I actually find this somewhat understandable; and I'll be continuing my subscription; as long as all source continues to be available and personal self-hosting remains a viable option.

Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.

Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.

It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.

I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.

  • solarkraft 1 day ago

    I’m conflicted. On one hand I’m grateful for the years of trustworthy (and pay-what-you-want) password management. On the other this feels like an attempt to EEE the free version.

    • freedomben 1 day ago

      That's my concern as well. I have no problem with the current license change if they continue to publish all the code as they claim. My concern is that this is usually step 1 in a boil-the-frog strategy to eventually split and break off enterprise features. I'll give them some trust until they give me a reason not to (I think they've earned it), but the concern remains.

      • 4ndrewl 1 day ago

        They don't?

        "Some future components will be published under the commercial license and will exist only in that build."

        (From that thread)

  • merb 1 day ago

    Sorry but the elasticsearch thing was a big stupid take of elastic. It was big corpo against big corpo not the poor elastic company.

    Changing licenses is a sick move and companies doing that should be fucked over, because the license made them big. Changing it later on means that they got greedy nothing more nothing less.

    Without oss bitwarden would be a paid cloud like all the others that probably would’ve had a hard time getting trusted.

    • mcfedr 1 day ago

      elastics cloud offering was awful

    • vanviegen 1 day ago

      > Changing it later on means that they got greedy nothing more nothing less.

      Or just trying hard to keep the company afloat?

      Just because they published Open Source code at some point, you feel that you're entitled to free updates for the rest of your life?

      • panja 15 hours ago

        Is there any evidence that Bitwarden was struggling financially before this?

      • merb 15 hours ago

        > Just because they published Open Source code at some point, you feel that you're entitled to free updates for the rest of your life?

        No. That is not the expectation.

        But using the open source brand going forward is a shitty move. If they want a commercial offering they should just rebrand and abandon the oss offering.

        Bitwarden the company is not struggling.

  • selectodude 1 day ago

    The thing I always think about is that they wouldn't have to change the license and tighten the screws if people paid for it. Getting mad that the free hosted password manager has changed the deal a little bit I find to be quite arrogant.

    Pay the $20/yr or whatever to have them host it and the whole world keeps turning.

    • lstodd 1 day ago

      Hosted password manager is equivalent to publishing all your passwords outright.

      Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all.

      • selectodude 1 day ago

        I mean, no it's absolutely nothing like "publishing all your passwords outright" but fine. Pay the $20/yr and don't have them host it, host it yourself. Just pay them the $20.

      • willmadden 1 day ago

        Do you have a quantum computer from the future and a file of passwords that haven't been changed in 50 years? Complete nonsense.

      • techjamie 1 day ago

        People are going to try much harder to break into the main Bitwarden servers than they are my little Vaultwarden instance. Plus, I have the ability to lock it behind a VPN so it isn't even publicly exposed.

        But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.

        I'm not sure where your sentiment comes from here.

        • technolo-g 1 day ago

          I took it to mean non-self hosted is like publishing your passwords online, which I agree with.

        • atherton94027 1 day ago

          I'm not sure that calculus is going to be true for much longer – with the costs of AI falling, it's going to be much easier to throw tokens at the problem even tiny targets that wouldn't have been worth it before. Can you guarantee your VPN is patched and secure at all times?

          • yjftsjthsd-h 1 day ago

            Can you guarantee the hosted servers are patched and secure at all times?

            • atherton94027 20 hours ago

              No but at least these companies have a full-time security team working on that. It's different when it's you doing this as a hobby in your homelab

              • yjftsjthsd-h 4 hours ago

                I dunno, from watching the news I trust my setup more than theirs

        • judge2020 1 day ago

          > But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.

          A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me. I much prefer 1Password's approach where they have a usually-hidden second secret (the "Secret Key") that both (A) isn't shown unless you're setting up another device, and (B) acts as extra data needed to form the decryption key for your vault.

          The main threat model I'm thinking of protecting against is a 1password vault data breach of some kind (or possibly cooperation with government agencies) + password exposure in some way (be it from CCTV-extracted password entries, over-the-shoulder watching, etc), as even with both of those factors, they would somehow need to get your secret key to decrypt vaults.

          Like, all of those lastpass vaults obtained during the Lastpass hack would be de-facto useless even with a correct password if their design included some sort of hidden secret secret.

          • movsx 1 day ago

            Are you aware of Yubikeys?

            • judge2020 15 hours ago

              Do you mean yubikeys as in 2FA for bitwarden (etc)? Or yubikeys as in requiring a challenge response to authenticate into a vault?

              AFAIK, 2fa is just another step before a server - executing code as it was intended - will return vault data to you. It doesn't protect against vault disclosure aka ransomware / data breach, similar to the Lastpass breach.

              As for yubikey to authenticate into a vault, I'm not sure if it's something that actually strengthens the knowledge required to get into a vault (assuming you have the vault data yourself). Like, is it actually another secret required to decrypt the vault data? Or is it just another step the server verifies before it grants you access to download the vault data (and then decrypt client-side)?

              • movsx 14 hours ago

                I'm sorry, I should have pointed out what I was replying to.

                > A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me.

                Yes, I meant 2FA via FIDO2. It strengthens up the entrance to your vault. No key? No entry.

                • judge2020 8 hours ago

                  2FA just doesn't change the threat model I presented, since the actual decryption step is not strengthened. I agree that fido2 2fa for a PW manager is really great, in general.

      • orf 1 day ago

        Your comment is generally ignorant on infosec.

      • ricericerice 1 day ago

        you have no idea how bitwarden works, do you...

        by that logic, every time you send a password over a TLS connection, you're publishing it outright too

  • trentor 1 day ago

    I would be with you if they didn't change the owner to private equity in the last year.

  • behringer 1 day ago

    That's not what's happening here. They're making their app closed source with closed source features. Time to find a new provider.

    • dare944 1 day ago

      Per their public discussion on the topic, the non-OSS licenses will still be public and accessible for review.

      • donmcronald 1 day ago

        We’ve seen it countless times over the last decade. OpenSolaris was the first big one. The open source side isn’t going to change, it’ll just get abandoned. They’re committed to open source… for now. Nothing is going to change… for now. They’ll maintain compatibility with compatible servers… for now.

        Everything will get chipped away piece by piece. It’s been happening continuously for well over a decade at this point and everyone should understand the strategy by now.

        • dare944 1 day ago

          Of course. There's never any free lunch. There's always a cost to software development. Just sometimes the cost gets shifted in a way that's beneficial to the general public. But it never lasts.

          At least with bitwarden, if the value they're trying to extract becomes more than the product is worth, in terms of real cost, lockin or transparency, at least the code is open now and for the foreseeable future. And when it comes time to fork it, AI will make it easier for the future maintainer(s) to keep the fork alive at minimal expense.

      • behringer 18 hours ago

        Public code is not open source.

        • dare944 18 hours ago

          Doesn't need to be. Point an AI at it and say reproduce the behavior.

          Point is, if need be, the open source version could be forked and carried forward by someone else, using the public code as a definitive spec for any missing functionality.

          • behringer 7 hours ago

            That is legally dubious and doesn't help you when you don't want to self host

    • onel 11 hours ago

      I don't think that's what the post mentioned. It says some new features will go with the new license, which is closed. Sad but not the same thing

  • compsciphd 1 day ago

    I was at redis when they changed the license (the first time). I begged the new leadership to not change the core license but to do a few things instead.

    1) bundle the "source available" modules as part of redis source distribution 2) enable people who only want bsd code to be able to build a "redis_core" 3) commit to the community that the core will remain BSD licensed and that they are committed to making it the best key/value store. 4) increase the amount of source available code that until then had been kept closed (including what we called big redis/RedisOnFlash/MultiTier) 5) Require anyone using the redis trademarks in a commercial setting to ship the entire Redis (which includes the source available portions, so Amazon et al would no longer be able to use the Redis trademarks without a license deal.

    Another alternative was to simply go to AGPL (which they went to anyways awhile later).

    I failed to convince the leadership about this. I honestly think they squandered huge value in community engagement, but perhaps that's what they wanted. I left a bit after these changes were made as it became clear that the new US led leadership of the company wasn't particularity interested in what was the soul of redis. (previously was heavily Israeli led and a critical mass there was invested in redis as an open source product).

    Funny story, the then new/current CEO used to be the head of WebEx at Cisco. We had a Q&A when he was hired and I asked, what did he learn from his time at WebEx about how to maintain market position (as they lost everything to zoom et al). His response at the time wasn't that convincing, but I was willing to give him the benefit of the doubt. I feel its fair to ask if the same thing occurred again.

    • farlight 1 day ago

      Thank you for trying to do something to prevent it, many people wouldn't bother.

    • ignoramous 1 day ago

      > His response at the time wasn't that convincing, but I was willing to give him the benefit of the doubt. I feel its fair to ask if the same thing occurred again.

      Business will have to try different things at different points due to external & internal pressures. Some decisions are reversible (at cost), some aren't. Decisions (chaotic / complex / complicated ones, at least) are not made merely based on available data and analysis, but also based on intuition, experiments, and predictions. Then, to look at the outcome rather than the process is missing the point. When the circumstance / situation isn't clear-cut, the feedback (the outcome of a decision) is in itself more valuable to the organization (than never having taken the decision, at all), especially when the costs (to reverse / change it) are bearable.

      • compsciphd 13 hours ago

        so there are a lot of words that I don't quite understand. basically decisions have to be made and perhaps they'll lead to bad outcomes, but having that outcome is better than not making any decision and one can always reverse the decision.

        decisions that lose community can be reversed, but the consequence of those decisions (losing community) might not be reversible at any cost. Which it seems to be in this case.

        As an example, at the company I switched to, they no longer use redis internally (not selling redis as a service, just using it as the internal caching layer of the product and never directly exposed to users, so would be a valid free use case under the switched to license) and instead use valkey.

        While these use cases might never have made Redis Inc any significant amounts of money, they were free advertising that they gave up and even with the 2nd license change, is not something they've gained back as external contributors are more interested in valkey than redis.

        And that goes to the email I wrote to leadership before the decision was publicized. 1) what are we trying to accomplish 2) what would be the negative consequence of the decision 3) is there another way to accomplish #1 while minimizing #2.

        It was always clear to everyone that #2 would be a fork. Everyone already knew that Amazon was managing their own internal Redis repo where they did their own internal development and then would drop changes that they would benefit from not having to carry (vs Redis Inc doing a lot of their core redis work in public vs dropping completed things)

        If #1 was to prevent Amazon et al from using redis trademarks, I don't think the license had to change. If #1 was to enable more non BSD code to be part of redis, I don't think the license of the core had to change. (how this would have impacted redis naming in linux distribution that only want to ship OSS code is a semi open Q but I think solvable).

        Personally, I think keeping the core as BSD but including the the non BSD source available portions could have been an effective "trojan horse" for getting the community at large to be more invested in those pieces.

        Also personally, I think what caused Redis Inc leadership to go down the path they did was Amazon cloning a non bsd source available redis module that Redis Inc published (RedisJson, to the point that they cloned the entire api including "easter eggs" that weren't really meant to be used, i.e. an API alias named after a (former) executive JSON DEL vs JSON FORGET named after former sales VP Jason Forget). That was the point of Amazon no longer playing nice in a competitive friendly way on the BSD code level, but to try to undermine how Redis Inc tried to distinguish themselves from just the BSD code. That's the right, but it perhaps caused Redis Inc to make bad decisions. (and as an aside, in today's day and age of AI, I wonder what protection these source available licenses have from AI oriented cloning).

arjie 1 day ago

Okay, it’s good they have the open source because if you rewrite the Chrome extension you can get it to load in under 100 ms after you click the button. If you use the standard Chrome extension you’re not having that happen on an M1 Max. Their stuff is far too heavy. Full JS framework to display a small box.

  • Ecco 1 day ago

    Any more details on this? Like did anyone build a better extension or are you just guessing?

    • lloydatkinson 1 day ago

      I’d be interested in hearing about this too.

      • mimischi 1 day ago

        In today’s day and age I read the OP as saying that threw an LLM at the extension repo and had it reimplement/improve upon for a private fork of theirs.

  • AlbinoDrought 1 day ago

    It would be nice if the forked client apps & extensions also avoided BC breaks, unline the mainline clients

  • talon8635 1 day ago

    How could you trust a third party (or even you own promoted AI) on this?

  • ulimn 1 day ago

    While keeping feature-parity, right...?

MetroWind 48 minutes ago

People should own their credentials instead of storing it in someone else's computers.

0l 1 day ago

IMO Bitwarden really isn't that well engineered software, and I now use Keyguard on Android/Vaultwarden server instead. Reminds me of Subsonic, with many competing clients/servers. Hopefully someone will write a third party browser extension as the current one is quite slow/buggy.

  • schleck8 1 day ago

    Isn't Vaultwarden using the same clients?

    • Cider9986 1 day ago

      Yes but this person is using an alternative Android client as well.

  • tmulcahy 1 day ago

    What about it isn't well engineered?

    • 0l 1 day ago

      It's all just slow and mediocre. The Windows desktop client is a massive almost 400MB-download behemoth (and is electron-based), and if you have SSH keys you want to store in it you have no choice but to use it. Oh and you can't log into the browser extension automatically from the desktop client.

      Admittedly the mobile clients have since been rewritten to be native (they were _really_ slow before), but Keyguard is still much faster/lighter.

      I started using 1Password at work and it's just a.. nicer experience? It does all this and more. Everything is fast, the browser extension is more proactive/recognises fields better (Bitwarden can't really do multi step logins), and the desktop client isn't a chore to use.

      The best comparison I would give is comparing Immich and Jellyfin (if you've used these), they are miles apart in terms of end user experience/polish/efficient design. One is engineered, the other feels like it's been hacked together by hobbyists.

      • jttnr 1 day ago

        Same goes for the bitwarden cli (`bw`). Its super slow and if you use it in scripts to pull multiple values (username, password), it takes ages. I personally switched to rbw (https://github.com/doy/rbw) and its day and night.

    • mceachen 1 day ago

      Syncing is iffy. Saving credentials associated to a shared org fails randomly. Rendering (x11/Firefox) sometimes fails completely, but is predictably slow. Auto fill can be buggy. Opening vaults on iOS can be remarkably slow.

    • Saris 1 day ago

      The main thing is it's just slow as molasses, just clicking the extension icon can sometimes take over a second to show anything.

      And it frequently fails to detect login fields, or does detect but fails to fill them with a generic error.

    • movsx 1 day ago

      Besides being slow, I found it buggy as hell. For instance, I wanted to log in with my Yubikey on my phone, and it flat out refused to let me in despite the master password and the PIN being 100% correct. There's even an open issue on Github about this, that they're doing absolutely nothing about, demonstrating the incompetence further at some really grand scales.

      • maxo133 1 day ago

        exactly this. and their autofill sucks so much on chrome desktop. It's bloated and slow. Even lastpass has a better and faster extension

        Try to bring it up on bitwarden reddit sub, they will eat you alive

    • Avamander 1 day ago

      Slow as hell, it's like what happened to LastPass. Nobody gave a shit about UI/UX issues.

    • cromka 11 hours ago

      I mean, one of the most basic functionalities is missing: duplicate detection. This and the ability to just add a new domain to existing entry instead of a completely new one.

      It's been requested for ages and they haven't delivered it yet.

figmert 1 day ago

This was always inevitable when they took funding.

josephcsible 1 day ago

Why does the title of this submission say "Dual License"? The linked page doesn't use that term anywhere, and it's also not an accurate description of what this change is.

zeroonetwothree 1 day ago

I’ve been a premium subscriber for 10+ years and I have to admit I don’t really care about this license stuff. As long as it keeps working well I’m happy.

  • talon8635 1 day ago

    I’m the same. It’s a paltry price for an outstanding product with great features that improves my life/security greatly

  • ffsm8 1 day ago

    i dont know how many years ive been a subscriber -- the oldest email ive got from them is switching my email 8 years ago, and i know for certain i used it on another email before that... but emails on that previous domain were never long lived, so theyre gone.

    anyway, the bigger issue ive with this is the doubling of the price right from the get-go.

    with private equity on the steering wheel, i suspect this will keep going up every year from now on, so ... while i too have been a loyal customer to date, i suspect ill be driven out within the next 1-2 years, because if they double the price again next year, its gonna be way beyond the value i get out of it given how decent the alternative have become since.

  • Avamander 1 day ago

    The latest macOS/native UI refresh is horrible though. It really hasn't improved in terms of speed either after regressing during the UI refresh before the latest.

  • EbNar 13 hours ago

    Honestly... Same. The alternatives are either more expensive (Proton pass costs least 1.5x ) or less convenient (keepass* and the likes) or more expensive and closed source (1pass) etc. Additionally, I could easily switch to keepass, but it has already been too difficult to convince my SO to finally use a damn password manager to ask now her to ditch the new toy (Bitwarden) for something new.

    </i>Should* Bitwarden turn to really evil, or they raise their prices outrageously, then I'll consider something else. For now, I'm staying.

j1elo 1 day ago

Instead of overlaying its own UI on top of form fields, I'd like Bitwarden (or any other PW manager) to act as a provider for the underlying system's native fill service, usually the browser, or Android, or OSX. They will always work much better than any 3rd party app.

Is that possible, does that exist?

  • Cider9986 1 day ago

    I think they do that on Android but also have the accessibility based option.

    • j1elo 1 day ago

      I use it on Android and it's always been a Bitwarden-specific pop-up that shows up on password fields. Maybe with accessibility mode it would work as you mention? Ok that's a new thing to test.

      • Cider9986 1 day ago

        I assumed that the accessibility one is non-standard and Bitwarden's uses the system native one. Because I see Bitwarden in passwords and autofill in settings (or something along those lines). I find it to work way better than on iOS anyway.

        I don't think that the visual indication means they aren't using the system way. The accessibility service is probably not a good idea given how much control it can give the app over your system.

        • qlte 18 hours ago

          Yes, Bitwarden definitely advertises itself as a password provider within Android's built in password/passkey manager API. I see Bitwarden appear in the list of saved passwords in the native UI along with Chrome which I have set as secondary.

          Otherwise I'm not sure how Bitwarden saved passkeys could even work at all without using the native integration.

  • diavolodeejay 1 day ago

    Just to clarify, you mean something like it is done in iOs?

    • j1elo 23 hours ago

      Probably! I just haven't seen it working on iOS. I'm mostly on Android, Windows, Linux, and Firefox everywhere.

  • MrGilbert 23 hours ago

    They do that on iOS. Integrates quite well.

bigbaguette 1 day ago

Everyone is mentioning Vaultwarden, but self-hosting this kind of service comes with quite a strong requirement of keeping it secure. Many might prefer letting a trusted actor take care of that.

Then the community says it's okay, people are going to fork their clients, but that's gonna take trusting the future maintainers.

Also, even though they commit to keep maintaining an open source channel, we won't be able to verify the builds anymore.

  • jellyroll42 1 day ago

    Something like TailScale, HeadScale, or NetBird makes it dead simple to securely access and sync

  • donmcronald 1 day ago

    Isn’t the server end of VW zero knowledge?

  • phoghed 6 hours ago

    I quit self hosting vaultwarden because in the age of the LLM security is an arms race that I’m not going to win. Switched to Apple Passwords.

    • MaKey 4 hours ago

      It's fine if you don't want to manage your self-hosted stuff anymore but implying that self-hosting is dead now because of LLMs is doomerism.

solarkraft 1 day ago

I’m willing to commit money to a project committed to release free builds without these shenanigans.

  • Cider9986 1 day ago

    Bitwarden is still releasing free builds but yeah you'd need a new project with a new name to use it from the Play Store or App Store.

    Turns out Keyguard, an alternative Bitwarden client is already on the Play Store.

    https://github.com/AChep/keyguard-app

    Edit: turns out Keyguard is source available but fully copyrighted.

    • alt227 1 day ago

      So if we now have Vaultwarden + keyguard can these things move away from Bitwardens api and pursue their own?

      • InsideOutSanta 1 day ago

        Is there any reason to? It's kinda nice that they all stick to the same contract. I don't really like the Bitwarden desktop app, but because there's so much code out there, it was pretty easy to have an LLM write a detailed spec for a client and then implement something that works for me.

        • chrismorgan 1 day ago

          The Bitwarden web client has actively broken Vaultwarden compatibility at least once <https://github.com/dani-garcia/vaultwarden/issues/7607>. It’s reasonable to expect they’ll do so more, carelessly or deliberately. They already have features and UI that don’t make sense for Vaultwarden, and the rate of such things feels to me (as a mere user) to have increased. When Bitwarden continues in the direction they’re going, I think a hard fork of the entire ecosystem for Vaultwarden is fairly likely, and it will almost certainly be a good thing, and in hindsight we’ll probably wish the fork branched off earlier.

          • figmert 19 hours ago

            > The Bitwarden web client has actively broken Vaultwarden compatibility at least once

            I skimmed the thread, so maybe I missed it, but from what I saw, saying they deliberately broke Vaultwarden is a bit if a stretch. They likely develop their apps without taking into account others (and rightfully so), and it happened to break an unsanctioned 3rd party implementation. Nothing nefarious.

            • chrismorgan 3 hours ago

              I didn’t say deliberately, but I did say actively. It sounds like this was something that would have broken older Bitwarden self-hosting servers too (no idea how old, or whether this is true at all, for I haven’t checked).

              The “nefarious” dividing line is often hard to assess. For a better-known example, it’s interesting just how many times Google has done things like degrading their stuff on Firefox by user-agent string detection, and then been all apologetic about it, it was a mistake, &c. Malice and incompetence can be indistinguishable.

  • embedding-shape 1 day ago

    The question is, what structure can protect this in an ongoing way? Say you setup a non-profit foundation, even those seemingly can be perverted to become for-profit businesses with corporate shenanigans (see OpenAI), so if you wanted to somehow "guarantee this group always release things this way", is there any legal structure that can enforce this somehow, "forever"?

    • solarkraft 8 hours ago

      I was going to say that’s not the level of security I require from that hypothetical organization: OpenAI was subverted by the perspective of many billions in profit, while many projects are running on idealism just fine (because there’s no profit on it).

      I stand by that, but then again, this is about secrets management we’re talking about, so the organization would need a pretty high level of seriousness to be able to be trusted.

      That’s a high bar for sure, but it looks to me like Bitwarden is trying to approach it from the top.

lucideer 1 day ago

As a loyal Bitwarden user, I think this is great news.

I love that Bitwarden exists, but as an "open source" project, it's always been a trad-corporate type code maintenance, rather than community-driven source contributions (exactly why we've seen things like Vaultwarden pop up) & that has generally just left all of their clients in that really awkward space where they're just good enough to be able to imagine their potential, but their maintenance is stagnant enough to ensure they'll never reach it.

Imo the community needs this kick to motivate the development of alt vaultwarden clients. Bitwarden gives us a great starting point but we need to break away.

Cider9986 1 day ago

This is enshittification but I'm not gonna drop Bitwarden unless they do something really bad. I'm already on the F-Droid version from their GitHub for my GrapheneOS phone because that one has no Google services/telemetry.

One of the family members I set up with Bitwarden has said it changed their life and they can't imagine not using it. I would guess that would apply to any crossplatform password manager but Bitwarden is quite good and the one that stuck.

I probably wouldn't move to one of these [1] because I don't like the UI of Proton Pass, the convenience of KeyPass, and 1Passsword is obvious. I'm interested in AliasVault as it seems to be a more privacy-focused password manager, which is cool, but I'd have to look more into it.

[1] https://www.privacyguides.org/en/passwords

[2] https://discuss.privacyguides.net/t/aliasvault-open-source-e...

mnahkies 1 day ago

Bitwarden is one of the few subscriptions I have in a patron sense - eg: I've never actually needed any of the premium feature's, but I chose to pay anyway as I felt that was a way to contribute to the long term viability of the project.

I'm not immediately upset about the licensing change - I get the need to protect from low effort/value add reselling and things like that. I do still worry if this is a canary for future changes that run counter to the reasons I migrated to bitwarden in the first place (open, robust, trustworthy).

Counter to many other commenters I personally prefer bitwarden over 1password, and certainly over lastpass and roboform, etc.

My only gripe is having to unlock the desktop app separately from the browser extension, which after adopting the ssh agent functionality became kinda annoying.

Havoc 15 hours ago

Yeah they've been giving ominous vibes lately.

Currently selfhosting BW so somewhat dependent on them even if not cloud flavour. Genuinely starting to wonder whether I even want to shift to another provider though. Every time my data gets compromised it's always been a company. Makes me think a DIY'd solution may even be less risky. Would likely be of dubious cryptographic merit, but unlike these companies I don't have a bullseye on my back & no hacker is going to invest significant time to get into my handful of boring passwords. And I can selfhost something behind wireguard easily enough...

mindracer 1 day ago

This seems like the beginning of the end, what password manager is recommended now?

  • pprotas 1 day ago

    KeepAssXC + SyncThing works well if you don't mind tinkering and like independence from corporations

    Otherwise 1Password if you like paying money

    • Mashimo 1 day ago

      > KeepAssXC + SyncThing works

      From a quick look, that seems to be Desktop only.

      • pprotas 1 day ago

        Not desktop only, KeePass uses an encrypted file, all you need is a way to decrypt it. You can store it in iCloud or whatever you like to sync files between devices.

        iOS has a good open source app KeeForge to open the encryped password files. I use SyncTrain on my phone to connect to my SyncThing network.

        • mindracer 1 day ago

          I use syncthing for my Linux devices but though it didn’t work on iOS. Will check out SyncTrain, thanks!

      • upboundspiral 1 day ago

        It's unfortunate that its a bit fragmented but there are Android / iOS complements as well - respectively keepassDX and keepassium.

        • pprotas 1 day ago

          You can see it as fragmentation, or you can look at it as having a choice. You can pick and choose how you access your data, without any corporation screwing you over the first chance they get.

      • Saris 1 day ago

        There are several good Android Keepass clients, and Syncthing apps too.

    • LeBit 1 day ago

      Keep Ass XC? Is it a fork?

      • dannyw 1 day ago

        KeePass XC :)

    • cricalix 1 day ago

      1Password has the whole thing of providing money to Omarchy's foundation. For some, that is a hard blocker.

    • tcfhgj 1 day ago

      1Password is not open source in the first place

  • aetherspawn 1 day ago

    Apple Keychain (free Passwords app)

    • johanyc 22 hours ago

      Can't even generate passwords of certain length

      • aetherspawn 20 hours ago

        There are Pros and Cons. Cons: generated passwords have less flexibility, not being able to add custom fields (ie backup codes or PIN), can’t store key files (unless you copy and paste contents into Notes section, which doesn’t redact it), no independent master vault password like 1Password.

        Pros: it’s free and will probably be free forever, can store and generate TOTP codes, biometric unlock, very easily syncs between devices, great integration on macOS and iPhone/Pad, easy sharing of password to family members without them needing a subscription.

        I have been a 1PW user for 10+ years but earlier this year started the long transition to save $10/month for the rest of my life which turns out to be a non-insignificant amount.

  • onel 11 hours ago

    Vaultwarden, self-hosting that is now 1-click deploy

inexcf 1 day ago

Well seems like Bitwarden is dying. A clear move towards enshittification. I was fine with the premium subscription existing while i was self-hosting Vaultwarden, but now every step seems to make that worse. Now new features will be under the commercial license an everything else will be slowly neglected. Time to jump ship.

brachkow 1 day ago

In case you are all-Apple, there is no reason to use either 1Password or Bitwarden – since a few years ago Apple Passwords have everything you need

andrewjneumann 1 day ago

I get needing to price more, but it really feels like a slow shift to M&A, when they couple it with license changes and “case by case basis” to make it back to OSS.

I’m not sure why growth at all costs needs to be the business model for every company?… make a great product, if you need to charge more over time cool, but don’t rug pull.

taikahessu 20 hours ago

Yes, get out already if ypu haven't, this ship has already sank a long time ago. I'm a paying happy 1password customer myself, but you could explore how keepass fits your workflow.

Grimeton 18 hours ago

They all realize that it's a good idea to cash in on stuff now because in 2-3 years thanks to AI it won't be possible anymore.

Similar situation with Deno...

itintheory 20 hours ago

> No action is needed, and the apps will work exactly as they do today.

Oh no! They'll stay a buggy mess. Damn, I was really hoping the windows app might get cleaned up.

  • para_parolu 20 hours ago

    Luckily it’s much easier to change software and fix bugs now. Even without publishing diffs

karel-3d 1 day ago

I don't understand the point or the motivation. They don't list any.

It's very badly explained what actually changes

  • MisterMunchkin 1 day ago

    They want money

    • karel-3d 1 day ago

      But how does this lead them there? It's really badly explained. They already have a paid version that has extra features. (For years now.) Like the SSO integration. What will be different now?

anilgulecha 1 day ago

Rust based vaultwarden awaits.

  • EasyMark 1 day ago

    if you like maintaining servers that are exposed to the web in the age of AI rogue agents

    • cromka 11 hours ago

      We've had Wireguard for years now. Use Wireguard and don't expose your services publicly.

Beijinger 1 day ago

I use enpass.io, the free version.

They had/have(?) cybersale recently but did not offer the lifetime version. Otherwise I would have bought it. It is not open-source but it is damn convenient.

robertlane0 1 day ago

Licensing changes aside, this is why I've never been enthused for hosted password management, it's too easy for the terms of the agreement to change. (And in the case of LastPass, endless breaches). Honestly, plain KeePassXC and an arrangement to sync the password database has served me well because I can use any compatible client I can trust with it.

snapplebobapple 1 day ago

So is there an alternative that i can migrate my business to with sso and zerotrust?

basilgohar 1 day ago

Vaultwarden is a self-hostable protocol-equivalent alternative.

contravariant 1 day ago

I'm a bit confused what they're actually doing. Their code is now covered by two different licenses with each file licensed under one of the two and they claim the resulting application is using the commercial Bitwarden license and not the GPL license?

How on earth does that work? Is that something the GPL license even allows?

This sounds like they're just taking a GPL licensed application and using it for themselves to make money.

  • watusername 1 day ago

    It's how a lot of open-core products work. Basically, when you hold the copyright, you can apply whatever license you wish when distributing the software at any time. People can use existing copies of the code under their old licenses, but they must follow the new terms if they acquire the code through the new channels.

    To get any PR merged in Bitwarden, you are forced to sign a CLA that reassigns copyright to Bitwarden Inc so they can relicense as they wish.

    > How on earth does that work? Is that something the GPL license even allows?

    GPL doesn't apply in this case, since the copy that you are acquiring is entirely under the commercial license.

    • contravariant 1 day ago

      > To get any PR merged in Bitwarden, you are forced to sign a CLA that reassigns copyright to Bitwarden Inc so they can relicense as they wish.

      Ah I see, yes that would explain it. That makes this a bit more concerning I suppose.

PunchyHamster 1 day ago

VC money gonna get their returns one way or another

> Some future components will be published under the commercial license and will exist only in that build. Newly developed features will be evaluated on a case-by-case basis for which license applies to them.

by which it means "no new features will land in OSS versions", as is tradition for open core development

  • EasyMark 1 day ago

    that's what it always seems like. buy a viable company, load it up with debt until it bankrupts, take your fees, declare bankruptcy.

tamimio 1 day ago

Bitwarden was my go to a while ago before moving to self hosted, even tho my password in the vault can get leaked anytime they won’t matter (2fa not in the same vault), but still, I don’t trust saas or anyone anymore, all crucial things are self hosted.

charcircuit 1 day ago

I don't see hours this business strategy works post LLMs. Someone's just going to immediately prompt into existence any commercial feature you make into the open source side.

  • gucci-on-fleek 1 day ago

    For most software, sure, but I wouldn't really trust a vibe-coded password manager.

scotty79 1 day ago

I'll be moving to PearPass ... there's really no reason for any company to hold my passwords for me.

fiatpandas 1 day ago

I’ve used vaultwarden and the official bitwarden macOS and iOS clients for a few years now, but it’s probably not wise to stay with it as a server long term, unless VW released their own apps.

I’ve put up with the minor annoyance of Bitwarden iOS app auto-updates breaking compatibility with my server, which requires me to update the docker instance.

It’s likely I’ll just switch to Apple, since I believe they support importing standard password DB formats. I have less enthusiasm now to maintain the link between these ecosystems, especially if one is on a downward enshittification trajectory.

EasyMark 1 day ago

why do I always feel like "this is where the enshittification begins" when I hear about license changes, even though these seem kind of harmless? But I'm not a lawyer so my hackles always hackle. And yes I am a paying customer, currently

caaqil 1 day ago

Unless they pull the LastPass crap, this is not a big deal for regular users.

  • SV_BubbleTime 1 day ago

    Which LastPass crap?

    Them not understanding how PBKDF2 works?

    Them leaking all the encrypted user vaults?

    Then raising prices and being impossible to work with as corporate customers?

    Straight up fuck LastPass.

LoganDark 21 hours ago

> you'll see some new products released soon - including a government version of Bitwarden - where having this license will give Bitwarden the legal protection it needs.

It looks like they're making a special commercial version specifically so that they can sell it, and make the case for the government to buy it for the extra commercial-only features.

petterroea 1 day ago

Yet another elasticsearch. Or terraform. Or redis. I guess?

Oss trying to protect itself from scalpers?

  • Rebelgecko 1 day ago

    The new owners are just seeing how gradually they can boil the frog before the userbase moves elsewhere. Gotta maximize returns.

hn3ufz62f7 1 day ago

Ran Vaultwarden for a team of ~15 for years and that's the part I'd watch here, the clients are the leverage, not the server. If the mobile apps stop being buildable from source the self host story gets a lot thinner.

rvz 1 day ago

The problem with this license change is that it is unenforceable, now that developers believe they can vibe-code their own.

Only a matter of time until we see "OpenWarden", just like we saw the migration from Redis to Valkey.

But let's be honest. "enshittification" here really means "I don't want to pay for my tools and I want it completely for free forever."

Just look at the reactions towards the single UI change made in Firefox on HN [0] and already the complaints are there. Even if you charge your users $1 to remove tracking it is somehow "enshittification" because $1 is too much to pay for software maintenance.

The real cost of maintenance is the amount raised in VC capital (Bitwarden raised $100M) or $600M a year (Google paying Firefox). Donations won't cover the capital needed to fund Firefox or Bitwarden's development at all.

"Open source" is only sustainable when someone else is paying for that maintenance. Small donations will only take you so far until one core developer says that they are underpaid.

[0] https://news.ycombinator.com/item?id=49892721

  • alt227 1 day ago

    > But let's be honest. "enshittification" here really means "I don't want to pay for my tools and I want it completely for free forever."

    That is completely the opposite of what is happening here. Lots of us pay premium Bitwarden subscriptions and are not happy with the way the company is headed, especially for a security company that holds the keys to many of our kingdoms.

    "enshittification" here means a company that we trusted is now started to make decisions which erode that trust. Its happened before and it will happen from here unto eternity.

  • rkent 1 day ago

    Thunderbird is a rare counter-example of an open source project that manages to maintain a significant staff through donations. Although affiliated with Mozilla, they are not funded by Mozilla. (I am no longer affiliated with Thunderbird, but I managed the project in the dark years after Mozilla suddenly dropped all funding and tried to get us to leave Mozilla.)

  • malfist 1 day ago

    I "new Firefox design" is hardly "single UI change"

    If it was only one change I doubt there'd be much pushback

  • cortesoft 1 day ago

    > Only a matter of time until we see "OpenWarden", just like we saw the migration from Redis to Valkey.

    Vaultwarden already exists

aetherspawn 1 day ago

Switch to free Apple Passwords and call it a day.