Bitwarden Dual License Model (community.bitwarden.com)
312 points by Cider9986 7 hours ago
rsyring 6 hours ago
Very insightful blog post listed by another user as a sub-comment. Worth posting as a top-level comment:
https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden
Previously discussed: https://news.ycombinator.com/item?id=48163389
nugget 6 hours ago
Great find. This blog post - and specifically the background of the new management team - convinced me to start looking for a Bitwarden alternative. I’m watching the same “boil the frog” strategy unfold at Namecheap, and erode much of the brand trust they had built up over a decade, and it’s a shame.
jventura 3 hours ago
> I’m watching the same “boil the frog” strategy unfold at Namecheap, and erode much of the brand trust they had built up over a decade, and it’s a shame.
What's happening with Namecheap? I've been a user for a long time and haven't noticed anything.. Maybe I'm one of the frogs being boiled!
ygjb 3 hours ago
turtletontine 6 hours ago
Have you settled on a BitWarden alternative, or a short list you’re considering?
birksherty 5 hours ago
jazzyjackson 4 hours ago
What’s wrong with self hosted vaultwarden ? I guess there isn’t a FLOSS extension client/app?
dwedge 3 hours ago
alasano 2 hours ago
That's funny, Bitwarden and Namecheap are the two things I've migrated away from as well.
The switch to Vaultwarden was insanely easy.
movsx 42 minutes ago
28304283409234 33 minutes ago
backlit4034 6 hours ago
GlassDoors reveal the other side of the story
https://www.glassdoor.com/Reviews/Bitwarden-Reviews-E4337610...
alt227 6 hours ago
e40 an hour ago
latchkey 4 hours ago
ok_dad 3 hours ago
Excellent now I have to find something else again. You can’t fucking trust anyone not to chase money these days.
Fuck bitwardens creators for selling out. I want them to know they fucking suck.
microflash 5 hours ago
This post is what triggered me to cancel my subscription and migrate away from Bitwarden in July. I’ve seen too many repeats of this show. This has completely soured me from cloud-backed critical software. Slowly moving toward offline alternatives wherever possible and self-hosting when it isn’t.
axelthegerman 5 hours ago
Thank you for linking this, the price increase was indeed communicated to me directly via email but not very clearly
> The price is updating to $1.65/month, billed annually.
Followed by a 25% discount for this reveal only.
Have to go back to my old invoice to see it was $10/y and now the new one $19.80/y
I never liked that I needed to pay premium just for 2FA but this abuse of trust is definitely the end of it.
Too bad I won't get a refund for my Oct 1st renewal but I'll happily cancel as soon as I get vaultwarden hosted.
snailmailman 2 hours ago
One benefit of the current self-hosted option via vaultwarden is that you get 2FA and the other premium features by default.
But it is worrying that they might intentionally break vaultwarden in the future.
theturtletalks 5 hours ago
SSO is the feature many companies put behind their most expensive plans. It's exactly why the personal software revolution will take over SaaS.
The argument here is always why would people spend all this time and money to build custom software when they can just pay a company $20-100 bucks a month? Because that product will become enshittified. It's not a question of if, its a question of when. I thought open-source SaaS would be immune, but clearly not.
TeMPOraL 5 hours ago
Aardwolf 6 hours ago
Ok this is doing some damage. What's a possible alternative that works on both mobile and desktop, doesn't require yourself to run a server, and doesn't have worse reputation?
terminalbraid 6 hours ago
keepassxc works across any major platform, mobile platforms have keepass2android and KeePassium. You don't have to run your own server, but you do need some type of file sharing system to keep them synced. I personally run a webdav share on a vps with some sync scripts to keep a backup on devices otherwise. OneDrive, google drive, dropbox, and others work.
Also protonpass.
Arrowmaster 5 hours ago
GordonS 6 hours ago
Lapel2742 6 hours ago
Proton Pass?
I already have "Proton Unlimited" as a subscription but until now I never used Proton Pass. I thought about giving up on Bitwarden for some time and probably will try it now. AFAIK you can even import your Bitwarden logins.
mpern 5 hours ago
rpozarickij 5 hours ago
attendant3446 3 hours ago
InsideOutSanta 6 hours ago
whynotmaybe 5 hours ago
Keepass on pc, keepass2android on mobile and the file is stored on onedrive. I'm starting to use macos so I'll install onedrive on it. Now onedrive's reputation is Microsoft's but I haven't heard of massive security breaches like many online password manager had.
frevib 5 hours ago
Proton pass.
Proton ticks all good-company boxes. E2ee, majority owned by the Proton foundation, all client-side code is OSS, and some other structures in place to protect themselves from corp greed. Best I could find.
sylos 5 hours ago
TeMPOraL 5 hours ago
Writing password down on paper and keeping them in your wallet.
Seriously. About as secure, if you're honest about the actual threat model (vs one security aficionados would like you to assume), and paper can't be enshittified.
Diti 24 minutes ago
dexterdog 4 hours ago
orta 6 hours ago
I like Enpass
hannasanarion 3 hours ago
Is there any writing on it that was written by a human? This blog post is clearly AI.
It's somewhat concerning to me that none of the security conscious people in this thread seem to notice that they are changing their privacy practices based on the advice of a language model pretending to be a person.
Cort3z 6 hours ago
I hate this. So much software I love keeps doing this. redis, docker, now bitwarden. I was so happy with bitwarden. Been a premium subscriber for many years. I have helped convert many people, including whole companies, to use this. Now they are doing us such a disservice. We need a completely free, no-nonsence, alternative. I wonder if it is possible to do a ipfs/torrent version without a central authority to permanently prevent this type of issue.
lisp2240 an hour ago
What we really need is an alternative to capitalism
halfcat 40 minutes ago
parineum 4 hours ago
I still use docker and redis for free and it seems like I'll be able to continue using bitwarden for free. I don't see what I've lost.
zackmorris 5 hours ago
I wonder that too, perhaps by encrypting the data with a key generated from a long passphrase meaningful to the user, that nobody could possibly guess. Then just store the data in a permanent cloud like IPFS, pinned with 4EVERLAND, Filebase and/or Pinata:
https://docs.ipfs.tech/concepts/persistence/#pinning-service...
Maybe someone could write a provably private client-based browser decryption script, hosted on various websites. We might need a new browser spec that sandboxes pages until they're unsandboxed, allowing them no egress/ingress or even local storage or cookies.
Or better yet, take that choice away from browser vendors, and create a runtime in the browser that simply can't be observed, perhaps by using zero-knowledge proofs.
Writing this out, I wonder if the issue is due to longstanding incomplete browser architecture, going back to when the web went mainstream in the mid-1990s. Or maybe it's still just an open problem.
Solve private distributed durable storage, along with a base level of secret computation eventually running about the speed of a 6502, 286 or 68000, and we wouldn't need free services that inevitably get privatized and ensh!ttified.
I have no idea if something like this already exists, I'm just speculating as to what base functionality it might need from first principles.
Also I wonder if similar techniques could be recruited to build an OS around cryptocurrency. That way a meta economy could run alongside the corrupt economy, and shield users from currency devaluation and other wealth inequality drivers used by the ultra-wealthy to increase the value of the means of production that they own relatively, so that they can buy more.
Arguably the process of wealth concentration is so fundamental that it puts a countdown on capitalism, driving it towards the late-stage capitalism that we've had since about 1970 when productivity diverged from wages, and eventually revolution which results in socialism/communism or even permanent authoritarian dystopia like on Star Wars. In a way, it's in the best interests of the ultra-wealthy to build meta economies, which of course makes those economies suspect and probably vulnerable to exploits, especially in the AI age. We've seen how crypto has created black markets capable of capturing governments, so maybe we should be careful what we wish for.
But really I just don't want to type my password anymore.
haruka_ff 2 hours ago
atomicUpdate 4 hours ago
Why stop at a free password manager? Why not free food, clothes, cars, and everything else while you’re making demands?
Or is it just software that has zero value to you because it’s intangible and you intentionally ignore the time and effort other people spend on it?
vuldin 4 hours ago
TitaRusell 3 hours ago
Cort3z 3 hours ago
alt227 6 hours ago
I feel like this blog post deserves its own submission to HN
rsyring 6 hours ago
Four months ago: https://news.ycombinator.com/item?id=48163389
alt227 6 hours ago
dizhn 6 hours ago
Started humany but degraded into LLM speak towards the end. Especial the Vaultwarden section.
stavros 6 hours ago
It's all LLMese, start to finish. I found it hard to get through. Could have just been a bulleted list and it would have been better.
formerly_proven 5 hours ago
alt227 6 hours ago
So? It was useful information, who cares how it was written.
subscribed 2 hours ago
tuwtuwtuwtuw 5 hours ago
Wowfunhappy 6 hours ago
Unfortunately, any "insight" it might contain is ruined by the fact it's clearly written by an LLM instead of a person.
> And it never comes in a single dramatic announcement. It comes in layers. A feature post with a price change inside it. A LinkedIn update nobody made a press release about. A values page that says something slightly different than it did last week. If you’re still on Bitwarden cloud and this is giving you pause — it should. [...] Whether self-hosting stays viable long-term is the real question worth sitting with.
dannyw 7 hours ago
I actually find this somewhat understandable; and I'll be continuing my subscription; as long as all source continues to be available and personal self-hosting remains a viable option.
Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.
Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.
It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.
I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.
compsciphd 5 hours ago
I was at redis when they changed the license (the first time). I begged the new leadership to not change the core license but to do a few things instead.
1) bundle the "source available" modules as part of redis source distribution 2) enable people who only want bsd code to be able to build a "redis_core" 3) commit to the community that the core will remain BSD licensed and that they are committed to making it the best key/value store. 4) increase the amount of source available code that until then had been kept closed (including what we called big redis/RedisOnFlash/MultiTier) 5) Require anyone using the redis trademarks in a commercial setting to ship the entire Redis (which includes the source available portions, so Amazon et al would no longer be able to use the Redis trademarks without a license deal.
Another alternative was to simply go to AGPL (which they went to anyways awhile later).
I failed to convince the leadership about this. I honestly think they squandered huge value in community engagement, but perhaps that's what they wanted. I left a bit after these changes were made as it became clear that the new US led leadership of the company wasn't particularity interested in what was the soul of redis. (previously was heavily Israeli led and a critical mass there was invested in redis as an open source product).
Funny story, the then new/current CEO used to be the head of WebEx at Cisco. We had a Q&A when he was hired and I asked, what did he learn from his time at WebEx about how to maintain market position (as they lost everything to zoom et al). His response at the time wasn't that convincing, but I was willing to give him the benefit of the doubt. I feel its fair to ask if the same thing occurred again.
farlight 5 hours ago
Thank you for trying to do something to prevent it, many people wouldn't bother.
ignoramous an hour ago
> His response at the time wasn't that convincing, but I was willing to give him the benefit of the doubt. I feel its fair to ask if the same thing occurred again.
Business will have to try different things at different points due to external & internal pressures. Some decisions are reversible (at cost), some aren't. Decisions (chaotic / complex / complicated ones, at least) are not made merely based on available data and analysis, but also based on intuition, experiments, and predictions. Then, to look at the outcome rather than the process is missing the point. When the circumstance / situation isn't clear-cut, the feedback (the outcome of a decision) is in itself more valuable to the organization (than never having taken the decision, at all), especially when the costs (to reverse / change it) are bearable.
solarkraft 7 hours ago
I’m conflicted. On one hand I’m grateful for the years of trustworthy (and pay-what-you-want) password management. On the other this feels like an attempt to EEE the free version.
freedomben 7 hours ago
That's my concern as well. I have no problem with the current license change if they continue to publish all the code as they claim. My concern is that this is usually step 1 in a boil-the-frog strategy to eventually split and break off enterprise features. I'll give them some trust until they give me a reason not to (I think they've earned it), but the concern remains.
4ndrewl 7 hours ago
trentor 6 hours ago
I would be with you if they didn't change the owner to private equity in the last year.
zeroonetwothree 6 hours ago
Wasn’t it just a minority stake?
selectodude 6 hours ago
The thing I always think about is that they wouldn't have to change the license and tighten the screws if people paid for it. Getting mad that the free hosted password manager has changed the deal a little bit I find to be quite arrogant.
Pay the $20/yr or whatever to have them host it and the whole world keeps turning.
lstodd 6 hours ago
Hosted password manager is equivalent to publishing all your passwords outright.
Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all.
ricericerice 6 hours ago
techjamie 6 hours ago
selectodude 6 hours ago
orf 6 hours ago
willmadden 6 hours ago
merb 7 hours ago
Sorry but the elasticsearch thing was a big stupid take of elastic. It was big corpo against big corpo not the poor elastic company.
Changing licenses is a sick move and companies doing that should be fucked over, because the license made them big. Changing it later on means that they got greedy nothing more nothing less.
Without oss bitwarden would be a paid cloud like all the others that probably would’ve had a hard time getting trusted.
vanviegen 2 hours ago
> Changing it later on means that they got greedy nothing more nothing less.
Or just trying hard to keep the company afloat?
Just because they published Open Source code at some point, you feel that you're entitled to free updates for the rest of your life?
mcfedr 6 hours ago
elastics cloud offering was awful
behringer 6 hours ago
That's not what's happening here. They're making their app closed source with closed source features. Time to find a new provider.
dare944 4 hours ago
Per their public discussion on the topic, the non-OSS licenses will still be public and accessible for review.
donmcronald 3 hours ago
arjie 7 hours ago
Okay, it’s good they have the open source because if you rewrite the Chrome extension you can get it to load in under 100 ms after you click the button. If you use the standard Chrome extension you’re not having that happen on an M1 Max. Their stuff is far too heavy. Full JS framework to display a small box.
Ecco 6 hours ago
Any more details on this? Like did anyone build a better extension or are you just guessing?
lloydatkinson 6 hours ago
I’d be interested in hearing about this too.
mimischi 3 hours ago
talon8635 5 hours ago
How could you trust a third party (or even you own promoted AI) on this?
AlbinoDrought 5 hours ago
It would be nice if the forked client apps & extensions also avoided BC breaks, unline the mainline clients
ulimn 3 hours ago
While keeping feature-parity, right...?
InsideOutSanta 6 hours ago
OK, don't leave us hanging like this.
lucideer 39 minutes ago
As a loyal Bitwarden user, I think this is great news.
I love that Bitwarden exists, but as an "open source" project, it's always been a trad-corporate type code maintenance, rather than community-driven source contributions (exactly why we've seen things like Vaultwarden pop up) & that has generally just left all of their clients in that really awkward space where they're just good enough to be able to imagine their potential, but their maintenance is stagnant enough to ensure they'll never reach it.
Imo the community needs this kick to motivate the development of alt vaultwarden clients. Bitwarden gives us a great starting point but we need to break away.
0l 7 hours ago
IMO Bitwarden really isn't that well engineered software, and I now use Keyguard on Android/Vaultwarden server instead. Reminds me of Subsonic, with many competing clients/servers. Hopefully someone will write a third party browser extension as the current one is quite slow/buggy.
tmulcahy 6 hours ago
What about it isn't well engineered?
0l 5 hours ago
It's all just slow and mediocre. The Windows desktop client is a massive almost 400MB-download behemoth (and is electron-based), and if you have SSH keys you want to store in it you have no choice but to use it. Oh and you can't log into the browser extension automatically from the desktop client.
Admittedly the mobile clients have since been rewritten to be native (they were _really_ slow before), but Keyguard is still much faster/lighter.
I started using 1Password at work and it's just a.. nicer experience? It does all this and more. Everything is fast, the browser extension is more proactive/recognises fields better (Bitwarden can't really do multi step logins), and the desktop client isn't a chore to use.
The best comparison I would give is comparing Immich and Jellyfin (if you've used these), they are miles apart in terms of end user experience/polish/efficient design. One is engineered, the other feels like it's been hacked together by hobbyists.
jttnr an hour ago
Saris 5 hours ago
The main thing is it's just slow as molasses, just clicking the extension icon can sometimes take over a second to show anything.
And it frequently fails to detect login fields, or does detect but fails to fill them with a generic error.
mceachen 5 hours ago
Syncing is iffy. Saving credentials associated to a shared org fails randomly. Rendering (x11/Firefox) sometimes fails completely, but is predictably slow. Auto fill can be buggy. Opening vaults on iOS can be remarkably slow.
movsx 5 hours ago
Besides being slow, I found it buggy as hell. For instance, I wanted to log in with my Yubikey on my phone, and it flat out refused to let me in despite the master password and the PIN being 100% correct. There's even an open issue on Github about this, that they're doing absolutely nothing about, demonstrating the incompetence further at some really grand scales.
maxo133 4 hours ago
Avamander 4 hours ago
Slow as hell, it's like what happened to LastPass. Nobody gave a shit about UI/UX issues.
schleck8 7 hours ago
Isn't Vaultwarden using the same clients?
Timshel 6 hours ago
Keyguard appears to be alternative Bitwarden compatible clients.
alright2565 6 hours ago
Cider9986 7 hours ago
Yes but this person is using an alternative Android client as well.
figmert 7 hours ago
This was always inevitable when they took funding.
msdz 7 hours ago
Correct.
Circa earlier this year I found this blog post, and have – as a paying customer nonetheless, mind you – continued to expect a 180-degree turn (which to be clear, this not yet is) ever since:
bigbaguette 5 hours ago
Everyone is mentioning Vaultwarden, but self-hosting this kind of service comes with quite a strong requirement of keeping it secure. Many might prefer letting a trusted actor take care of that.
Then the community says it's okay, people are going to fork their clients, but that's gonna take trusting the future maintainers.
Also, even though they commit to keep maintaining an open source channel, we won't be able to verify the builds anymore.
jellyroll42 4 hours ago
Something like TailScale, HeadScale, or NetBird makes it dead simple to securely access and sync
donmcronald 3 hours ago
Isn’t the server end of VW zero knowledge?
josephcsible 4 hours ago
Why does the title of this submission say "Dual License"? The linked page doesn't use that term anywhere, and it's also not an accurate description of what this change is.
zeroonetwothree 6 hours ago
I’ve been a premium subscriber for 10+ years and I have to admit I don’t really care about this license stuff. As long as it keeps working well I’m happy.
talon8635 5 hours ago
I’m the same. It’s a paltry price for an outstanding product with great features that improves my life/security greatly
ffsm8 5 hours ago
i dont know how many years ive been a subscriber -- the oldest email ive got from them is switching my email 8 years ago, and i know for certain i used it on another email before that... but emails on that previous domain were never long lived, so theyre gone.
anyway, the bigger issue ive with this is the doubling of the price right from the get-go.
with private equity on the steering wheel, i suspect this will keep going up every year from now on, so ... while i too have been a loyal customer to date, i suspect ill be driven out within the next 1-2 years, because if they double the price again next year, its gonna be way beyond the value i get out of it given how decent the alternative have become since.
Avamander 4 hours ago
The latest macOS/native UI refresh is horrible though. It really hasn't improved in terms of speed either after regressing during the UI refresh before the latest.
j1elo 5 hours ago
Instead of overlaying its own UI on top of form fields, I'd like Bitwarden (or any other PW manager) to act as a provider for the underlying system's native fill service, usually the browser, or Android, or OSX. They will always work much better than any 3rd party app.
Is that possible, does that exist?
Cider9986 4 hours ago
I think they do that on Android but also have the accessibility based option.
j1elo 3 hours ago
I use it on Android and it's always been a Bitwarden-specific pop-up that shows up on password fields. Maybe with accessibility mode it would work as you mention? Ok that's a new thing to test.
diavolodeejay 3 hours ago
Just to clarify, you mean something like it is done in iOs?
solarkraft 7 hours ago
I’m willing to commit money to a project committed to release free builds without these shenanigans.
Cider9986 7 hours ago
Bitwarden is still releasing free builds but yeah you'd need a new project with a new name to use it from the Play Store or App Store.
Turns out Keyguard, an alternative Bitwarden client is already on the Play Store.
https://github.com/AChep/keyguard-app
Edit: turns out Keyguard is source available but fully copyrighted.
alt227 6 hours ago
So if we now have Vaultwarden + keyguard can these things move away from Bitwardens api and pursue their own?
InsideOutSanta 6 hours ago
embedding-shape 2 hours ago
The question is, what structure can protect this in an ongoing way? Say you setup a non-profit foundation, even those seemingly can be perverted to become for-profit businesses with corporate shenanigans (see OpenAI), so if you wanted to somehow "guarantee this group always release things this way", is there any legal structure that can enforce this somehow, "forever"?
Cider9986 7 hours ago
This is enshittification but I'm not gonna drop Bitwarden unless they do something really bad. I'm already on the F-Droid version from their GitHub for my GrapheneOS phone because that one has no Google services/telemetry.
One of the family members I set up with Bitwarden has said it changed their life and they can't imagine not using it. I would guess that would apply to any crossplatform password manager but Bitwarden is quite good and the one that stuck.
I probably wouldn't move to one of these [1] because I don't like the UI of Proton Pass, the convenience of KeyPass, and 1Passsword is obvious. I'm interested in AliasVault as it seems to be a more privacy-focused password manager, which is cool, but I'd have to look more into it.
[1] https://www.privacyguides.org/en/passwords
[2] https://discuss.privacyguides.net/t/aliasvault-open-source-e...
brachkow 2 hours ago
In case you are all-Apple, there is no reason to use either 1Password or Bitwarden – since a few years ago Apple Passwords have everything you need
mnahkies 4 hours ago
Bitwarden is one of the few subscriptions I have in a patron sense - eg: I've never actually needed any of the premium feature's, but I chose to pay anyway as I felt that was a way to contribute to the long term viability of the project.
I'm not immediately upset about the licensing change - I get the need to protect from low effort/value add reselling and things like that. I do still worry if this is a canary for future changes that run counter to the reasons I migrated to bitwarden in the first place (open, robust, trustworthy).
Counter to many other commenters I personally prefer bitwarden over 1password, and certainly over lastpass and roboform, etc.
My only gripe is having to unlock the desktop app separately from the browser extension, which after adopting the ssh agent functionality became kinda annoying.
mindracer 7 hours ago
This seems like the beginning of the end, what password manager is recommended now?
pprotas 6 hours ago
KeepAssXC + SyncThing works well if you don't mind tinkering and like independence from corporations
Otherwise 1Password if you like paying money
LeBit 6 hours ago
Keep Ass XC? Is it a fork?
dannyw 5 hours ago
cricalix 5 hours ago
1Password has the whole thing of providing money to Omarchy's foundation. For some, that is a hard blocker.
tcfhgj 4 hours ago
1Password is not open source in the first place
Mashimo 6 hours ago
> KeepAssXC + SyncThing works
From a quick look, that seems to be Desktop only.
pprotas 6 hours ago
upboundspiral 6 hours ago
Saris 5 hours ago
Zambyte 5 hours ago
economic9725 43 minutes ago
Don't be evil. Always.
andrewjneumann 5 hours ago
I get needing to price more, but it really feels like a slow shift to M&A, when they couple it with license changes and “case by case basis” to make it back to OSS.
I’m not sure why growth at all costs needs to be the business model for every company?… make a great product, if you need to charge more over time cool, but don’t rug pull.
inexcf 7 hours ago
Well seems like Bitwarden is dying. A clear move towards enshittification. I was fine with the premium subscription existing while i was self-hosting Vaultwarden, but now every step seems to make that worse. Now new features will be under the commercial license an everything else will be slowly neglected. Time to jump ship.
movsx 7 hours ago
I have been eyeballing PassPony[0] as a replacement.
The fact that they still do not support Yubikeys is holding me back from switching, but I expect this to be ironed out soon.
0l 7 hours ago
Looks far too sloppy for me to trust this software with my passwords...
movsx 6 hours ago
blahlabs 7 hours ago
Any suggestions or ideas for where to?
Beijinger 4 hours ago
I use enpass.io, the free version.
They had/have(?) cybersale recently but did not offer the lifetime version. Otherwise I would have bought it. It is not open-source but it is damn convenient.
snapplebobapple 3 hours ago
So is there an alternative that i can migrate my business to with sso and zerotrust?
karel-3d 7 hours ago
I don't understand the point or the motivation. They don't list any.
It's very badly explained what actually changes
MisterMunchkin 5 hours ago
They want money
karel-3d an hour ago
But how does this lead them there? It's really badly explained. They already have a paid version that has extra features. (For years now.) Like the SSO integration. What will be different now?
anilgulecha 6 hours ago
Rust based vaultwarden awaits.
EasyMark an hour ago
if you like maintaining servers that are exposed to the web in the age of AI rogue agents
robertlane0 5 hours ago
Licensing changes aside, this is why I've never been enthused for hosted password management, it's too easy for the terms of the agreement to change. (And in the case of LastPass, endless breaches). Honestly, plain KeePassXC and an arrangement to sync the password database has served me well because I can use any compatible client I can trust with it.
basilgohar 5 hours ago
Vaultwarden is a self-hostable protocol-equivalent alternative.
EasyMark an hour ago
why do I always feel like "this is where the enshittification begins" when I hear about license changes, even though these seem kind of harmless? But I'm not a lawyer so my hackles always hackle. And yes I am a paying customer, currently
fiatpandas 5 hours ago
I’ve used vaultwarden and the official bitwarden macOS and iOS clients for a few years now, but it’s probably not wise to stay with it as a server long term, unless VW released their own apps.
I’ve put up with the minor annoyance of Bitwarden iOS app auto-updates breaking compatibility with my server, which requires me to update the docker instance.
It’s likely I’ll just switch to Apple, since I believe they support importing standard password DB formats. I have less enthusiasm now to maintain the link between these ecosystems, especially if one is on a downward enshittification trajectory.
contravariant 6 hours ago
I'm a bit confused what they're actually doing. Their code is now covered by two different licenses with each file licensed under one of the two and they claim the resulting application is using the commercial Bitwarden license and not the GPL license?
How on earth does that work? Is that something the GPL license even allows?
This sounds like they're just taking a GPL licensed application and using it for themselves to make money.
watusername 5 hours ago
It's how a lot of open-core products work. Basically, when you hold the copyright, you can apply whatever license you wish when distributing the software at any time. People can use existing copies of the code under their old licenses, but they must follow the new terms if they acquire the code through the new channels.
To get any PR merged in Bitwarden, you are forced to sign a CLA that reassigns copyright to Bitwarden Inc so they can relicense as they wish.
> How on earth does that work? Is that something the GPL license even allows?
GPL doesn't apply in this case, since the copy that you are acquiring is entirely under the commercial license.
contravariant an hour ago
> To get any PR merged in Bitwarden, you are forced to sign a CLA that reassigns copyright to Bitwarden Inc so they can relicense as they wish.
Ah I see, yes that would explain it. That makes this a bit more concerning I suppose.
PunchyHamster 4 hours ago
VC money gonna get their returns one way or another
> Some future components will be published under the commercial license and will exist only in that build. Newly developed features will be evaluated on a case-by-case basis for which license applies to them.
by which it means "no new features will land in OSS versions", as is tradition for open core development
EasyMark an hour ago
that's what it always seems like. buy a viable company, load it up with debt until it bankrupts, take your fees, declare bankruptcy.
tamimio 4 hours ago
Bitwarden was my go to a while ago before moving to self hosted, even tho my password in the vault can get leaked anytime they won’t matter (2fa not in the same vault), but still, I don’t trust saas or anyone anymore, all crucial things are self hosted.
charcircuit 6 hours ago
I don't see hours this business strategy works post LLMs. Someone's just going to immediately prompt into existence any commercial feature you make into the open source side.
gucci-on-fleek 6 hours ago
For most software, sure, but I wouldn't really trust a vibe-coded password manager.
scotty79 6 hours ago
I'll be moving to PearPass ... there's really no reason for any company to hold my passwords for me.
caaqil 6 hours ago
Unless they pull the LastPass crap, this is not a big deal for regular users.
SV_BubbleTime an hour ago
Which LastPass crap?
Them not understanding how PBKDF2 works?
Them leaking all the encrypted user vaults?
Then raising prices and being impossible to work with as corporate customers?
Straight up fuck LastPass.
rvz 6 hours ago
The problem with this license change is that it is unenforceable, now that developers believe they can vibe-code their own.
Only a matter of time until we see "OpenWarden", just like we saw the migration from Redis to Valkey.
But let's be honest. "enshittification" here really means "I don't want to pay for my tools and I want it completely for free forever."
Just look at the reactions towards the single UI change made in Firefox on HN [0] and already the complaints are there. Even if you charge your users $1 to remove tracking it is somehow "enshittification" because $1 is too much to pay for software maintenance.
The real cost of maintenance is the amount raised in VC capital (Bitwarden raised $100M) or $600M a year (Google paying Firefox). Donations won't cover the capital needed to fund Firefox or Bitwarden's development at all.
"Open source" is only sustainable when someone else is paying for that maintenance. Small donations will only take you so far until one core developer says that they are underpaid.
rkent 6 hours ago
Thunderbird is a rare counter-example of an open source project that manages to maintain a significant staff through donations. Although affiliated with Mozilla, they are not funded by Mozilla. (I am no longer affiliated with Thunderbird, but I managed the project in the dark years after Mozilla suddenly dropped all funding and tried to get us to leave Mozilla.)
alt227 6 hours ago
> But let's be honest. "enshittification" here really means "I don't want to pay for my tools and I want it completely for free forever."
That is completely the opposite of what is happening here. Lots of us pay premium Bitwarden subscriptions and are not happy with the way the company is headed, especially for a security company that holds the keys to many of our kingdoms.
"enshittification" here means a company that we trusted is now started to make decisions which erode that trust. Its happened before and it will happen from here unto eternity.
cortesoft 5 hours ago
> Only a matter of time until we see "OpenWarden", just like we saw the migration from Redis to Valkey.
Vaultwarden already exists
malfist 5 hours ago
I "new Firefox design" is hardly "single UI change"
If it was only one change I doubt there'd be much pushback
petterroea 7 hours ago
Yet another elasticsearch. Or terraform. Or redis. I guess?
Oss trying to protect itself from scalpers?
Rebelgecko 7 hours ago
The new owners are just seeing how gradually they can boil the frog before the userbase moves elsewhere. Gotta maximize returns.
hn3ufz62f7 7 hours ago
Ran Vaultwarden for a team of ~15 for years and that's the part I'd watch here, the clients are the leverage, not the server. If the mobile apps stop being buildable from source the self host story gets a lot thinner.