Bitwarden Dual License Model
community.bitwarden.com
community.bitwarden.com
https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden
Previously discussed: https://news.ycombinator.com/item?id=48163389
If you believe that the technology works, that encryption is happening and that the decryption is only happening on your local machine then why in the fuck would I host this myself?
You need to believe that it does not work when they do it, but does work when you do it.
I have not seen any evidence of that.
I'm curious why other self hosters think it's a bad idea.
Thanks for sharing.
So probably its RSS usage is just mostly its own executable code?
What will you use when this stops working in the near future?
mostly i was missing power user features and especially ux for the browser plugin, namely you can't operate it fully with the keyboard, with keepassxc you can
No reason to use anything more complicated.
https://www.glassdoor.com/Reviews/Bitwarden-Reviews-E4337610...
Guess I'll never be visiting Glass Door again then.
Not sure if still the case but normally you have to not only 'sign in' but also feed them information (e.x. salary at a position, write a review, etc.) in order to be able to view much of anything.
They also do not give a shit about obvious 'juicing' (i.e. when it is obvious that upper management and/or HR is adding reviews where the 'con' reads like one of those softball warning phrases in a job description.)
The most egregious example I've found was that the Danish postal service had something like a 4,8/5,0 rating on Trustpilot. You'll be hard pressed to find a more inept, corrupt and universally hated company. So in an attempt to improve their public image, they decided to game the ratings, instead of actually delivering mail properly.
However they may have proved that they are indeed.. trash. Maybe even a few times.
One such case was https://www.forrester.com/blogs/glassdoors-mishandling-of-cu...
In my eyes they are in the same class of Facebook, uservoice, Pinterest, Quora etc.
Fundamentally it's all a game of whack-a-mole for admins unless some kind of microtransaction system is invented. Then a DDOS scraping event is just extra revenue.
or pooling together tokens and asking Claude nicely to make a mobile app
What's happening with Namecheap? I've been a user for a long time and haven't noticed anything.. Maybe I'm one of the frogs being boiled!
[2] https://discuss.privacyguides.net/t/privacy-concerns-regardi...
Bought out by private equity. I've moved my domains to Hover when I found out from that Hacker news thread before any of the enshittification affects me.
[2] https://discuss.privacyguides.net/t/privacy-concerns-regardi...
Bought out by private equity. I've moved my domains to Hover when I found out from that Hacker news thread before any of the enshittification affects me.
The switch to Vaultwarden was insanely easy.
But auto renewals not working at times for some reason, credit cards not being saved, prices rising vs competitors.
Just switched everything to CloudFlare since I'm always pointing to it anyways and use a lot of their services.
> And it never comes in a single dramatic announcement. It comes in layers. A feature post with a price change inside it. A LinkedIn update nobody made a press release about. A values page that says something slightly different than it did last week. If you’re still on Bitwarden cloud and this is giving you pause — it should. [...] Whether self-hosting stays viable long-term is the real question worth sitting with.
Everything else is just a nonsense, watermark and fluff, scamming from time and attention - there's NO value in the filler.
To reiterate: there's no value in this sort of the LLM garbage. There's value in the information, especially when formatted and provided in the humane format.
I don't understand why some people feel the need to turn a few hundred words if concise description into thousands via LLM.
Also protonpass.
Bitwarden was the no nonsense choice because it just worked.
How does this work with keepassxc? Does it depend on your file syncing primitive?
I already have "Proton Unlimited" as a subscription but until now I never used Proton Pass. I thought about giving up on Bitwarden for some time and probably will try it now. AFAIK you can even import your Bitwarden logins.
For me, Pass works much better, especially passkeys on Android. Bitwarden was very flaky in that regard, Proton Pass "just works".
I use Pass for personal logins and sharing family-related accounts with my wife.
Proton ticks all good-company boxes. E2ee, majority owned by the Proton foundation, all client-side code is OSS, and some other structures in place to protect themselves from corp greed. Best I could find.
Seriously. About as secure, if you're honest about the actual threat model (vs one security aficionados would like you to assume), and paper can't be enshittified.
[1]: https://en.wikipedia.org/wiki/Bruce_Schneier
[2]: https://www.schneier.com/blog/archives/2005/06/write_down_yo...
Current offerings are ok. But they had a pay once model before which they grandfathered in. I got lucky. It's amazing and no bullshit software.
Has apps from everything including browsers. Can use any cloud storage as vault. Supports un Pass passkey totp pin and everything you can think of.
https://docs.ipfs.tech/concepts/persistence/#pinning-service...
Maybe someone could write a provably private client-based browser decryption script, hosted on various websites. We might need a new browser spec that sandboxes pages until they're unsandboxed, allowing them no egress/ingress or even local storage or cookies.
Or better yet, take that choice away from browser vendors, and create a runtime in the browser that simply can't be observed, perhaps by using zero-knowledge proofs.
Writing this out, I wonder if the issue is due to longstanding incomplete browser architecture, going back to when the web went mainstream in the mid-1990s. Or maybe it's still just an open problem.
Solve private distributed durable storage, along with a base level of secret computation eventually running about the speed of a 6502, 286 or 68000, and we wouldn't need free services that inevitably get privatized and ensh!ttified.
I have no idea if something like this already exists, I'm just speculating as to what base functionality it might need from first principles.
Also I wonder if similar techniques could be recruited to build an OS around cryptocurrency. That way a meta economy could run alongside the corrupt economy, and shield users from currency devaluation and other wealth inequality drivers used by the ultra-wealthy to increase the value of the means of production that they own relatively, so that they can buy more.
Arguably the process of wealth concentration is so fundamental that it puts a countdown on capitalism, driving it towards the late-stage capitalism that we've had since about 1970 when productivity diverged from wages, and eventually revolution which results in socialism/communism or even permanent authoritarian dystopia like on Star Wars. In a way, it's in the best interests of the ultra-wealthy to build meta economies, which of course makes those economies suspect and probably vulnerable to exploits, especially in the AI age. We've seen how crypto has created black markets capable of capturing governments, so maybe we should be careful what we wish for.
But really I just don't want to type my password anymore.
Or is it just software that has zero value to you because it’s intangible and you intentionally ignore the time and effort other people spend on it?
Someone has to pay for ongoing maintenance.
I don't think you understand what capitalism is, or you've spent no time at all looking into how many hundreds of millions have been killed under socialism, fascism, crony-capitalism, or any of the other means of exchange that involve force.
The federal government printing infinite money is the reason that companies need to constantly keep increasing profits, otherwise they will just ground down by the annual 15% inflation rate.
> The price is updating to $1.65/month, billed annually.
Followed by a 25% discount for this reveal only.
Have to go back to my old invoice to see it was $10/y and now the new one $19.80/y
I never liked that I needed to pay premium just for 2FA but this abuse of trust is definitely the end of it.
Too bad I won't get a refund for my Oct 1st renewal but I'll happily cancel as soon as I get vaultwarden hosted.
The argument here is always why would people spend all this time and money to build custom software when they can just pay a company $20-100 bucks a month? Because that product will become enshittified. It's not a question of if, its a question of when. I thought open-source SaaS would be immune, but clearly not.
If you excuse a Warcraft-y metaphor.
But it is worrying that they might intentionally break vaultwarden in the future.
It's somewhat concerning to me that none of the security conscious people in this thread seem to notice that they are changing their privacy practices based on the advice of a language model pretending to be a person.
Fuck bitwardens creators for selling out. I want them to know they fucking suck.
I don't even mind paying a reasonable amount for Bidwarden (as I do) or other things I find valuable, but it's the unlimited growth of profit that disgusts me. My Grand Father, Father, and myself were/are all business people (in very different industries) and we'd all be ashamed to double the price of something simply for more profit.
I think we need to be a bit more aware of our expectations from free products. By the end of the day on the free tier, and as long as you're not paying, you are a cost to the company. I think most of these problems go away if we don't rely or expect that much from free products. If we pay a little bit, even if it's just for the compute when self-hosting, it creates much healthier relationship.
The post also mentions GitHub. Let's be honest, they created a lot of value with the free tier, but we also can't have high expectations for a service we're not paying
Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.
Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.
It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.
I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.
"Some future components will be published under the commercial license and will exist only in that build."
(From that thread)
Changing licenses is a sick move and companies doing that should be fucked over, because the license made them big. Changing it later on means that they got greedy nothing more nothing less.
Without oss bitwarden would be a paid cloud like all the others that probably would’ve had a hard time getting trusted.
Or just trying hard to keep the company afloat?
Just because they published Open Source code at some point, you feel that you're entitled to free updates for the rest of your life?
No. That is not the expectation.
But using the open source brand going forward is a shitty move. If they want a commercial offering they should just rebrand and abandon the oss offering.
Bitwarden the company is not struggling.
Pay the $20/yr or whatever to have them host it and the whole world keeps turning.
Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all.
But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.
I'm not sure where your sentiment comes from here.
A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me. I much prefer 1Password's approach where they have a usually-hidden second secret (the "Secret Key") that both (A) isn't shown unless you're setting up another device, and (B) acts as extra data needed to form the decryption key for your vault.
The main threat model I'm thinking of protecting against is a 1password vault data breach of some kind (or possibly cooperation with government agencies) + password exposure in some way (be it from CCTV-extracted password entries, over-the-shoulder watching, etc), as even with both of those factors, they would somehow need to get your secret key to decrypt vaults.
Like, all of those lastpass vaults obtained during the Lastpass hack would be de-facto useless even with a correct password if their design included some sort of hidden secret secret.
AFAIK, 2fa is just another step before a server - executing code as it was intended - will return vault data to you. It doesn't protect against vault disclosure aka ransomware / data breach, similar to the Lastpass breach.
As for yubikey to authenticate into a vault, I'm not sure if it's something that actually strengthens the knowledge required to get into a vault (assuming you have the vault data yourself). Like, is it actually another secret required to decrypt the vault data? Or is it just another step the server verifies before it grants you access to download the vault data (and then decrypt client-side)?
> A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me.
Yes, I meant 2FA via FIDO2. It strengthens up the entrance to your vault. No key? No entry.
by that logic, every time you send a password over a TLS connection, you're publishing it outright too
Everything will get chipped away piece by piece. It’s been happening continuously for well over a decade at this point and everyone should understand the strategy by now.
At least with bitwarden, if the value they're trying to extract becomes more than the product is worth, in terms of real cost, lockin or transparency, at least the code is open now and for the foreseeable future. And when it comes time to fork it, AI will make it easier for the future maintainer(s) to keep the fork alive at minimal expense.
Point is, if need be, the open source version could be forked and carried forward by someone else, using the public code as a definitive spec for any missing functionality.
1) bundle the "source available" modules as part of redis source distribution 2) enable people who only want bsd code to be able to build a "redis_core" 3) commit to the community that the core will remain BSD licensed and that they are committed to making it the best key/value store. 4) increase the amount of source available code that until then had been kept closed (including what we called big redis/RedisOnFlash/MultiTier) 5) Require anyone using the redis trademarks in a commercial setting to ship the entire Redis (which includes the source available portions, so Amazon et al would no longer be able to use the Redis trademarks without a license deal.
Another alternative was to simply go to AGPL (which they went to anyways awhile later).
I failed to convince the leadership about this. I honestly think they squandered huge value in community engagement, but perhaps that's what they wanted. I left a bit after these changes were made as it became clear that the new US led leadership of the company wasn't particularity interested in what was the soul of redis. (previously was heavily Israeli led and a critical mass there was invested in redis as an open source product).
Funny story, the then new/current CEO used to be the head of WebEx at Cisco. We had a Q&A when he was hired and I asked, what did he learn from his time at WebEx about how to maintain market position (as they lost everything to zoom et al). His response at the time wasn't that convincing, but I was willing to give him the benefit of the doubt. I feel its fair to ask if the same thing occurred again.
Business will have to try different things at different points due to external & internal pressures. Some decisions are reversible (at cost), some aren't. Decisions (chaotic / complex / complicated ones, at least) are not made merely based on available data and analysis, but also based on intuition, experiments, and predictions. Then, to look at the outcome rather than the process is missing the point. When the circumstance / situation isn't clear-cut, the feedback (the outcome of a decision) is in itself more valuable to the organization (than never having taken the decision, at all), especially when the costs (to reverse / change it) are bearable.
decisions that lose community can be reversed, but the consequence of those decisions (losing community) might not be reversible at any cost. Which it seems to be in this case.
As an example, at the company I switched to, they no longer use redis internally (not selling redis as a service, just using it as the internal caching layer of the product and never directly exposed to users, so would be a valid free use case under the switched to license) and instead use valkey.
While these use cases might never have made Redis Inc any significant amounts of money, they were free advertising that they gave up and even with the 2nd license change, is not something they've gained back as external contributors are more interested in valkey than redis.
And that goes to the email I wrote to leadership before the decision was publicized. 1) what are we trying to accomplish 2) what would be the negative consequence of the decision 3) is there another way to accomplish #1 while minimizing #2.
It was always clear to everyone that #2 would be a fork. Everyone already knew that Amazon was managing their own internal Redis repo where they did their own internal development and then would drop changes that they would benefit from not having to carry (vs Redis Inc doing a lot of their core redis work in public vs dropping completed things)
If #1 was to prevent Amazon et al from using redis trademarks, I don't think the license had to change. If #1 was to enable more non BSD code to be part of redis, I don't think the license of the core had to change. (how this would have impacted redis naming in linux distribution that only want to ship OSS code is a semi open Q but I think solvable).
Personally, I think keeping the core as BSD but including the the non BSD source available portions could have been an effective "trojan horse" for getting the community at large to be more invested in those pieces.
Also personally, I think what caused Redis Inc leadership to go down the path they did was Amazon cloning a non bsd source available redis module that Redis Inc published (RedisJson, to the point that they cloned the entire api including "easter eggs" that weren't really meant to be used, i.e. an API alias named after a (former) executive JSON DEL vs JSON FORGET named after former sales VP Jason Forget). That was the point of Amazon no longer playing nice in a competitive friendly way on the BSD code level, but to try to undermine how Redis Inc tried to distinguish themselves from just the BSD code. That's the right, but it perhaps caused Redis Inc to make bad decisions. (and as an aside, in today's day and age of AI, I wonder what protection these source available licenses have from AI oriented cloning).
Admittedly the mobile clients have since been rewritten to be native (they were _really_ slow before), but Keyguard is still much faster/lighter.
I started using 1Password at work and it's just a.. nicer experience? It does all this and more. Everything is fast, the browser extension is more proactive/recognises fields better (Bitwarden can't really do multi step logins), and the desktop client isn't a chore to use.
The best comparison I would give is comparing Immich and Jellyfin (if you've used these), they are miles apart in terms of end user experience/polish/efficient design. One is engineered, the other feels like it's been hacked together by hobbyists.
And it frequently fails to detect login fields, or does detect but fails to fill them with a generic error.
Try to bring it up on bitwarden reddit sub, they will eat you alive
It's been requested for ages and they haven't delivered it yet.
Circa earlier this year I found this blog post, and have – as a paying customer nonetheless, mind you – continued to expect a 180-degree turn (which to be clear, this not yet is) ever since:
anyway, the bigger issue ive with this is the doubling of the price right from the get-go.
with private equity on the steering wheel, i suspect this will keep going up every year from now on, so ... while i too have been a loyal customer to date, i suspect ill be driven out within the next 1-2 years, because if they double the price again next year, its gonna be way beyond the value i get out of it given how decent the alternative have become since.
Should* Bitwarden turn to really evil, or they raise their prices outrageously, then I'll consider something else. For now, I'm staying.
Is that possible, does that exist?
I don't think that the visual indication means they aren't using the system way. The accessibility service is probably not a good idea given how much control it can give the app over your system.
Otherwise I'm not sure how Bitwarden saved passkeys could even work at all without using the native integration.
Then the community says it's okay, people are going to fork their clients, but that's gonna take trusting the future maintainers.
Also, even though they commit to keep maintaining an open source channel, we won't be able to verify the builds anymore.
Turns out Keyguard, an alternative Bitwarden client is already on the Play Store.
https://github.com/AChep/keyguard-app
Edit: turns out Keyguard is source available but fully copyrighted.
I skimmed the thread, so maybe I missed it, but from what I saw, saying they deliberately broke Vaultwarden is a bit if a stretch. They likely develop their apps without taking into account others (and rightfully so), and it happened to break an unsanctioned 3rd party implementation. Nothing nefarious.
I stand by that, but then again, this is about secrets management we’re talking about, so the organization would need a pretty high level of seriousness to be able to be trusted.
That’s a high bar for sure, but it looks to me like Bitwarden is trying to approach it from the top.
Currently selfhosting BW so somewhat dependent on them even if not cloud flavour. Genuinely starting to wonder whether I even want to shift to another provider though. Every time my data gets compromised it's always been a company. Makes me think a DIY'd solution may even be less risky. Would likely be of dubious cryptographic merit, but unlike these companies I don't have a bullseye on my back & no hacker is going to invest significant time to get into my handful of boring passwords. And I can selfhost something behind wireguard easily enough...
I love that Bitwarden exists, but as an "open source" project, it's always been a trad-corporate type code maintenance, rather than community-driven source contributions (exactly why we've seen things like Vaultwarden pop up) & that has generally just left all of their clients in that really awkward space where they're just good enough to be able to imagine their potential, but their maintenance is stagnant enough to ensure they'll never reach it.
Imo the community needs this kick to motivate the development of alt vaultwarden clients. Bitwarden gives us a great starting point but we need to break away.
I'm not immediately upset about the licensing change - I get the need to protect from low effort/value add reselling and things like that. I do still worry if this is a canary for future changes that run counter to the reasons I migrated to bitwarden in the first place (open, robust, trustworthy).
Counter to many other commenters I personally prefer bitwarden over 1password, and certainly over lastpass and roboform, etc.
My only gripe is having to unlock the desktop app separately from the browser extension, which after adopting the ssh agent functionality became kinda annoying.
One of the family members I set up with Bitwarden has said it changed their life and they can't imagine not using it. I would guess that would apply to any crossplatform password manager but Bitwarden is quite good and the one that stuck.
I probably wouldn't move to one of these [1] because I don't like the UI of Proton Pass, the convenience of KeyPass, and 1Passsword is obvious. I'm interested in AliasVault as it seems to be a more privacy-focused password manager, which is cool, but I'd have to look more into it.
[1] https://www.privacyguides.org/en/passwords
[2] https://discuss.privacyguides.net/t/aliasvault-open-source-e...
Otherwise 1Password if you like paying money
From a quick look, that seems to be Desktop only.
iOS has a good open source app KeeForge to open the encryped password files. I use SyncTrain on my phone to connect to my SyncThing network.
Pros: it’s free and will probably be free forever, can store and generate TOTP codes, biometric unlock, very easily syncs between devices, great integration on macOS and iPhone/Pad, easy sharing of password to family members without them needing a subscription.
I have been a 1PW user for 10+ years but earlier this year started the long transition to save $10/month for the rest of my life which turns out to be a non-insignificant amount.
The fact that they still do not support Yubikeys is holding me back from switching, but I expect this to be ironed out soon.
I am in no way, shape, or form, endorsing this PonyApp thingy and cannot vouch for it as I haven't audited it. But judging by what it says on the tin, it does appear like a candidate to solve the specific problem I have.
[0]: https://www.passwordstore.org/
Similar situation with Deno...
Oh no! They'll stay a buggy mess. Damn, I was really hoping the windows app might get cleaned up.
I’m not sure why growth at all costs needs to be the business model for every company?… make a great product, if you need to charge more over time cool, but don’t rug pull.
It's very badly explained what actually changes
They had/have(?) cybersale recently but did not offer the lifetime version. Otherwise I would have bought it. It is not open-source but it is damn convenient.
How on earth does that work? Is that something the GPL license even allows?
This sounds like they're just taking a GPL licensed application and using it for themselves to make money.
To get any PR merged in Bitwarden, you are forced to sign a CLA that reassigns copyright to Bitwarden Inc so they can relicense as they wish.
> How on earth does that work? Is that something the GPL license even allows?
GPL doesn't apply in this case, since the copy that you are acquiring is entirely under the commercial license.
Ah I see, yes that would explain it. That makes this a bit more concerning I suppose.
> Some future components will be published under the commercial license and will exist only in that build. Newly developed features will be evaluated on a case-by-case basis for which license applies to them.
by which it means "no new features will land in OSS versions", as is tradition for open core development
I’ve put up with the minor annoyance of Bitwarden iOS app auto-updates breaking compatibility with my server, which requires me to update the docker instance.
It’s likely I’ll just switch to Apple, since I believe they support importing standard password DB formats. I have less enthusiasm now to maintain the link between these ecosystems, especially if one is on a downward enshittification trajectory.
Them not understanding how PBKDF2 works?
Them leaking all the encrypted user vaults?
Then raising prices and being impossible to work with as corporate customers?
Straight up fuck LastPass.
It looks like they're making a special commercial version specifically so that they can sell it, and make the case for the government to buy it for the extra commercial-only features.
Oss trying to protect itself from scalpers?
Only a matter of time until we see "OpenWarden", just like we saw the migration from Redis to Valkey.
But let's be honest. "enshittification" here really means "I don't want to pay for my tools and I want it completely for free forever."
Just look at the reactions towards the single UI change made in Firefox on HN [0] and already the complaints are there. Even if you charge your users $1 to remove tracking it is somehow "enshittification" because $1 is too much to pay for software maintenance.
The real cost of maintenance is the amount raised in VC capital (Bitwarden raised $100M) or $600M a year (Google paying Firefox). Donations won't cover the capital needed to fund Firefox or Bitwarden's development at all.
"Open source" is only sustainable when someone else is paying for that maintenance. Small donations will only take you so far until one core developer says that they are underpaid.
That is completely the opposite of what is happening here. Lots of us pay premium Bitwarden subscriptions and are not happy with the way the company is headed, especially for a security company that holds the keys to many of our kingdoms.
"enshittification" here means a company that we trusted is now started to make decisions which erode that trust. Its happened before and it will happen from here unto eternity.
If it was only one change I doubt there'd be much pushback
Vaultwarden already exists