151 points Cider9986 2 hours ago 94 comments
dannyw 1 hour ago | parent
Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.
Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.
It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.
I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.
solarkraft 1 hour ago | parent
freedomben 1 hour ago | parent
4ndrewl 1 hour ago | parent
"Some future components will be published under the commercial license and will exist only in that build."
(From that thread)
merb 1 hour ago | parent
Changing licenses is a sick move and companies doing that should be fucked over, because the license made them big. Changing it later on means that they got greedy nothing more nothing less.
Without oss bitwarden would be a paid cloud like all the others that probably would’ve had a hard time getting trusted.
mcfedr 55 minutes ago | parent
selectodude 58 minutes ago | parent
Pay the $20/yr or whatever to have them host it and the whole world keeps turning.
lstodd 44 minutes ago | parent
Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all.
selectodude 42 minutes ago | parent
willmadden 39 minutes ago | parent
techjamie 35 minutes ago | parent
But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.
I'm not sure where your sentiment comes from here.
technolo-g 29 minutes ago | parent
atherton94027 24 minutes ago | parent
iohvvbhdyh 19 minutes ago | parent
judge2020 7 minutes ago | parent
A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me. I much prefer 1Password's approach where they have a usually-hidden second secret (the "Secret Key") that both (A) isn't shown unless you're setting up another device, and (B) acts as extra data needed to form the decryption key for your vault.
The main threat model I'm thinking of protecting against is a 1password vault data breach of some kind (or possibly cooperation with government agencies) + password exposure in some way (be it from CCTV-extracted password entries, over-the-shoulder watching, etc), as even with both of those factors, they would somehow need to get your secret key to decrypt vaults.
Like, all of those lastpass vaults obtained during the Lastpass hack would be de-facto useless even with a correct password if their design included some sort of hidden secret secret.
orf 30 minutes ago | parent
ricericerice 28 minutes ago | parent
by that logic, every time you send a password over a TLS connection, you're publishing it outright too
behringer 24 minutes ago | parent
solarkraft 1 hour ago | parent
Cider9986 1 hour ago | parent
Turns out Keyguard, an alternative Bitwarden client is already on the Play Store.
https://github.com/AChep/keyguard-app
Edit: turns out Keyguard is source available but fully copyrighted.
alt227 44 minutes ago | parent
InsideOutSanta 28 minutes ago | parent
hn3ufz62f7 1 hour ago | parent
inexcf 1 hour ago | parent
movsx 1 hour ago | parent
The fact that they still do not support Yubikeys is holding me back from switching, but I expect this to be ironed out soon.
0l 1 hour ago | parent
movsx 1 hour ago | parent
I am in no way, shape, or form, endorsing this PonyApp thingy and cannot vouch for it as I haven't audited it. But judging by what it says on the tin, it does appear like a candidate to solve the specific problem I have.
[0]: https://www.passwordstore.org/
blahlabs 1 hour ago | parent
Cider9986 1 hour ago | parent
One of the family members I set up with Bitwarden has said it changed their life and they can't imagine not using it. I would guess that would apply to any crossplatform password manager but Bitwarden is quite good and the one that stuck.
I probably wouldn't move to one of these [1] because I don't like the UI of Proton Pass, the convenience of KeyPass, and 1Passsword is obvious. I'm interested in AliasVault as it seems to be a more privacy-focused password manager, which is cool, but I'd have to look more into it.
[1] https://www.privacyguides.org/en/passwords
[2] https://discuss.privacyguides.net/t/aliasvault-open-source-e...
0l 1 hour ago | parent
tmulcahy 1 hour ago | parent
0l 9 minutes ago | parent
Admittedly the mobile clients have since been rewritten to be native (they were _really_ slow before), but Keyguard is still much faster/lighter.
I started using 1Password at work and it's just a.. nicer experience? It does all this and more. Everything is fast, the browser extension is more proactive/recognises fields better (Bitwarden can't really do multi step logins), and the desktop client isn't a chore to use.
The best comparison I would give is comparing Immich and Jellyfin (if you've used these), they are miles apart in terms of end user experience/polish/efficient design. One is engineered, the other feels like it's been hacked together by hobbyists.
arjie 1 hour ago | parent
InsideOutSanta 30 minutes ago | parent
AlbinoDrought 9 minutes ago | parent
talon8635 7 minutes ago | parent
mindracer 1 hour ago | parent
pprotas 1 hour ago | parent
Otherwise 1Password if you like paying money
Mashimo 1 hour ago | parent
From a quick look, that seems to be Desktop only.
pprotas 59 minutes ago | parent
iOS has a good open source app KeeForge to open the encryped password files. I use SyncTrain on my phone to connect to my SyncThing network.
mindracer 41 minutes ago | parent
upboundspiral 49 minutes ago | parent
pprotas 31 minutes ago | parent
LeBit 30 minutes ago | parent
cricalix 7 minutes ago | parent
karel-3d 1 hour ago | parent
It's very badly explained what actually changes
anilgulecha 1 hour ago | parent
rsyring 1 hour ago | parent
https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden
Previously discussed: https://news.ycombinator.com/item?id=48163389
nugget 1 hour ago | parent
turtletontine 53 minutes ago | parent
backlit4034 45 minutes ago | parent
https://www.glassdoor.com/Reviews/Bitwarden-Reviews-E4337610...
alt227 38 minutes ago | parent
Guess I'll never be visiting Glass Door again then.
dizhn 56 minutes ago | parent
Aardwolf 54 minutes ago | parent
orta 51 minutes ago | parent
terminalbraid 48 minutes ago | parent
Also protonpass.
Arrowmaster 15 minutes ago | parent
Bitwarden was the no nonsense choice because it just worked.
Lapel2742 38 minutes ago | parent
I already have "Proton Unlimited" as a subscription but until now I never used Proton Pass. I thought about giving up on Bitwarden for some time and probably will try it now. AFAIK you can even import your Bitwarden logins.
InsideOutSanta 31 minutes ago | parent
alt227 46 minutes ago | parent
rsyring 35 minutes ago | parent
alt227 28 minutes ago | parent
Cort3z 38 minutes ago | parent
rvz 1 hour ago | parent
Only a matter of time until we see "OpenWarden", just like we saw the migration from Redis to Valkey.
But let's be honest. "enshittification" here really means "I don't want to pay for my tools and I want it completely for free forever."
Just look at the reactions towards the single UI change made in Firefox on HN [0] and already the complaints are there. Even if you charge your users $1 to remove tracking it is somehow "enshittification" because $1 is too much to pay for software maintenance.
The real cost of maintenance is the amount raised in VC capital (Bitwarden raised $100M) or $600M a year (Google paying Firefox). Donations won't cover the capital needed to fund Firefox or Bitwarden's development at all.
"Open source" is only sustainable when someone else is paying for that maintenance. Small donations will only take you so far until one core developer says that they are underpaid.
alt227 41 minutes ago | parent
That is completely the opposite of what is happening here. Lots of us pay premium Bitwarden subscriptions and are not happy with the way the company is headed, especially for a security company that holds the keys to many of our kingdoms.
"enshittification" here means a company that we trusted is now started to make decisions which erode that trust. Its happened before and it will happen from here unto eternity.
rkent 28 minutes ago | parent
malfist 16 minutes ago | parent
If it was only one change I doubt there'd be much pushback
caaqil 1 hour ago | parent
scotty79 1 hour ago | parent
charcircuit 41 minutes ago | parent
gucci-on-fleek 18 minutes ago | parent
contravariant 39 minutes ago | parent
How on earth does that work? Is that something the GPL license even allows?
This sounds like they're just taking a GPL licensed application and using it for themselves to make money.
zeroonetwothree 23 minutes ago | parent
talon8635 10 minutes ago | parent
robertlane0 14 minutes ago | parent
fiatpandas 13 minutes ago | parent
I’ve put up with the minor annoyance of Bitwarden iOS app auto-updates breaking compatibility with my server, which requires me to update the docker instance.
It’s likely I’ll just switch to Apple, since I believe they support importing standard password DB formats. I have less enthusiasm now to maintain the link between these ecosystems, especially if one is on a downward enshittification trajectory.