Bitwarden Dual License Model(community.bitwarden.com) |
Bitwarden Dual License Model(community.bitwarden.com) |
https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden
Previously discussed: https://news.ycombinator.com/item?id=48163389
https://www.glassdoor.com/Reviews/Bitwarden-Reviews-E4337610...
Also protonpass.
I already have "Proton Unlimited" as a subscription but until now I never used Proton Pass. I thought about giving up on Bitwarden for some time and probably will try it now. AFAIK you can even import your Bitwarden logins.
Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.
Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.
It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.
I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.
Circa earlier this year I found this blog post, and have – as a paying customer nonetheless, mind you – continued to expect a 180-degree turn (which to be clear, this not yet is) ever since:
Admittedly the mobile clients have since been rewritten to be native (they were _really_ slow before), but Keyguard is still much faster/lighter.
I started using 1Password at work and it's just a.. nicer experience? It does all this and more. Everything is fast, the browser extension is more proactive/recognises fields better (Bitwarden can't really do multi step logins), and the desktop client isn't a chore to use.
The best comparison I would give is comparing Immich and Jellyfin (if you've used these), they are miles apart in terms of end user experience/polish/efficient design. One is engineered, the other feels like it's been hacked together by hobbyists.
Turns out Keyguard, an alternative Bitwarden client is already on the Play Store.
https://github.com/AChep/keyguard-app
Edit: turns out Keyguard is source available but fully copyrighted.
I’ve put up with the minor annoyance of Bitwarden iOS app auto-updates breaking compatibility with my server, which requires me to update the docker instance.
It’s likely I’ll just switch to Apple, since I believe they support importing standard password DB formats. I have less enthusiasm now to maintain the link between these ecosystems, especially if one is on a downward enshittification trajectory.
One of the family members I set up with Bitwarden has said it changed their life and they can't imagine not using it. I would guess that would apply to any crossplatform password manager but Bitwarden is quite good and the one that stuck.
I probably wouldn't move to one of these [1] because I don't like the UI of Proton Pass, the convenience of KeyPass, and 1Passsword is obvious. I'm interested in AliasVault as it seems to be a more privacy-focused password manager, which is cool, but I'd have to look more into it.
[1] https://www.privacyguides.org/en/passwords
[2] https://discuss.privacyguides.net/t/aliasvault-open-source-e...
Otherwise 1Password if you like paying money
It's very badly explained what actually changes
How on earth does that work? Is that something the GPL license even allows?
This sounds like they're just taking a GPL licensed application and using it for themselves to make money.
Only a matter of time until we see "OpenWarden", just like we saw the migration from Redis to Valkey.
But let's be honest. "enshittification" here really means "I don't want to pay for my tools and I want it completely for free forever."
Just look at the reactions towards the single UI change made in Firefox on HN [0] and already the complaints are there. Even if you charge your users $1 to remove tracking it is somehow "enshittification" because $1 is too much to pay for software maintenance.
The real cost of maintenance is the amount raised in VC capital (Bitwarden raised $100M) or $600M a year (Google paying Firefox). Donations won't cover the capital needed to fund Firefox or Bitwarden's development at all.
"Open source" is only sustainable when someone else is paying for that maintenance. Small donations will only take you so far until one core developer says that they are underpaid.
If it was only one change I doubt there'd be much pushback
That is completely the opposite of what is happening here. Lots of us pay premium Bitwarden subscriptions and are not happy with the way the company is headed, especially for a security company that holds the keys to many of our kingdoms.
"enshittification" here means a company that we trusted is now started to make decisions which erode that trust. Its happened before and it will happen from here unto eternity.
Oss trying to protect itself from scalpers?
Guess I'll never be visiting Glass Door again then.
Pay the $20/yr or whatever to have them host it and the whole world keeps turning.
Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all.
Changing licenses is a sick move and companies doing that should be fucked over, because the license made them big. Changing it later on means that they got greedy nothing more nothing less.
Without oss bitwarden would be a paid cloud like all the others that probably would’ve had a hard time getting trusted.
I am in no way, shape, or form, endorsing this PonyApp thingy and cannot vouch for it as I haven't audited it. But judging by what it says on the tin, it does appear like a candidate to solve the specific problem I have.
[0]: https://www.passwordstore.org/
"Some future components will be published under the commercial license and will exist only in that build."
(From that thread)
Bitwarden was the no nonsense choice because it just worked.
by that logic, every time you send a password over a TLS connection, you're publishing it outright too
But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.
I'm not sure where your sentiment comes from here.
A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me. I much prefer 1Password's approach where they have a usually-hidden second secret (the "Secret Key") that both (A) isn't shown unless you're setting up another device, and (B) acts as extra data needed to form the decryption key for your vault.
The main threat model I'm thinking of protecting against is a 1password vault data breach of some kind (or possibly cooperation with government agencies) + password exposure in some way (be it from CCTV-extracted password entries, over-the-shoulder watching, etc), as even with both of those factors, they would somehow need to get your secret key to decrypt vaults.
Like, all of those lastpass vaults obtained during the Lastpass hack would be de-facto useless even with a correct password if their design included some sort of hidden secret secret.
iOS has a good open source app KeeForge to open the encryped password files. I use SyncTrain on my phone to connect to my SyncThing network.