https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden
Previously discussed: https://news.ycombinator.com/item?id=48163389
What's happening with Namecheap? I've been a user for a long time and haven't noticed anything.. Maybe I'm one of the frogs being boiled!
The switch to Vaultwarden was insanely easy.
mostly i was missing power user features and especially ux for the browser plugin, namely you can't operate it fully with the keyboard, with keepassxc you can
I'm curious why other self hosters think it's a bad idea.
What will you use when this stops working in the near future?
Thanks for sharing.
So probably its RSS usage is just mostly its own executable code?
https://www.glassdoor.com/Reviews/Bitwarden-Reviews-E4337610...
Guess I'll never be visiting Glass Door again then.
Not sure if still the case but normally you have to not only 'sign in' but also feed them information (e.x. salary at a position, write a review, etc.) in order to be able to view much of anything.
They also do not give a shit about obvious 'juicing' (i.e. when it is obvious that upper management and/or HR is adding reviews where the 'con' reads like one of those softball warning phrases in a job description.)
The most egregious example I've found was that the Danish postal service had something like a 4,8/5,0 rating on Trustpilot. You'll be hard pressed to find a more inept, corrupt and universally hated company. So in an attempt to improve their public image, they decided to game the ratings, instead of actually delivering mail properly.
Fundamentally it's all a game of whack-a-mole for admins unless some kind of microtransaction system is invented. Then a DDOS scraping event is just extra revenue.
However they may have proved that they are indeed.. trash. Maybe even a few times.
One such case was https://www.forrester.com/blogs/glassdoors-mishandling-of-cu...
In my eyes they are in the same class of Facebook, uservoice, Pinterest, Quora etc.
Fuck bitwardens creators for selling out. I want them to know they fucking suck.
> The price is updating to $1.65/month, billed annually.
Followed by a 25% discount for this reveal only.
Have to go back to my old invoice to see it was $10/y and now the new one $19.80/y
I never liked that I needed to pay premium just for 2FA but this abuse of trust is definitely the end of it.
Too bad I won't get a refund for my Oct 1st renewal but I'll happily cancel as soon as I get vaultwarden hosted.
But it is worrying that they might intentionally break vaultwarden in the future.
The argument here is always why would people spend all this time and money to build custom software when they can just pay a company $20-100 bucks a month? Because that product will become enshittified. It's not a question of if, its a question of when. I thought open-source SaaS would be immune, but clearly not.
If you excuse a Warcraft-y metaphor.
It's somewhat concerning to me that none of the security conscious people in this thread seem to notice that they are changing their privacy practices based on the advice of a language model pretending to be a person.
Also protonpass.
Bitwarden was the no nonsense choice because it just worked.
How does this work with keepassxc? Does it depend on your file syncing primitive?
I already have "Proton Unlimited" as a subscription but until now I never used Proton Pass. I thought about giving up on Bitwarden for some time and probably will try it now. AFAIK you can even import your Bitwarden logins.
For me, Pass works much better, especially passkeys on Android. Bitwarden was very flaky in that regard, Proton Pass "just works".
I use Pass for personal logins and sharing family-related accounts with my wife.
Proton ticks all good-company boxes. E2ee, majority owned by the Proton foundation, all client-side code is OSS, and some other structures in place to protect themselves from corp greed. Best I could find.
Seriously. About as secure, if you're honest about the actual threat model (vs one security aficionados would like you to assume), and paper can't be enshittified.
https://docs.ipfs.tech/concepts/persistence/#pinning-service...
Maybe someone could write a provably private client-based browser decryption script, hosted on various websites. We might need a new browser spec that sandboxes pages until they're unsandboxed, allowing them no egress/ingress or even local storage or cookies.
Or better yet, take that choice away from browser vendors, and create a runtime in the browser that simply can't be observed, perhaps by using zero-knowledge proofs.
Writing this out, I wonder if the issue is due to longstanding incomplete browser architecture, going back to when the web went mainstream in the mid-1990s. Or maybe it's still just an open problem.
Solve private distributed durable storage, along with a base level of secret computation eventually running about the speed of a 6502, 286 or 68000, and we wouldn't need free services that inevitably get privatized and ensh!ttified.
I have no idea if something like this already exists, I'm just speculating as to what base functionality it might need from first principles.
Also I wonder if similar techniques could be recruited to build an OS around cryptocurrency. That way a meta economy could run alongside the corrupt economy, and shield users from currency devaluation and other wealth inequality drivers used by the ultra-wealthy to increase the value of the means of production that they own relatively, so that they can buy more.
Arguably the process of wealth concentration is so fundamental that it puts a countdown on capitalism, driving it towards the late-stage capitalism that we've had since about 1970 when productivity diverged from wages, and eventually revolution which results in socialism/communism or even permanent authoritarian dystopia like on Star Wars. In a way, it's in the best interests of the ultra-wealthy to build meta economies, which of course makes those economies suspect and probably vulnerable to exploits, especially in the AI age. We've seen how crypto has created black markets capable of capturing governments, so maybe we should be careful what we wish for.
But really I just don't want to type my password anymore.
Or is it just software that has zero value to you because it’s intangible and you intentionally ignore the time and effort other people spend on it?
Everything else is just a nonsense, watermark and fluff, scamming from time and attention - there's NO value in the filler.
To reiterate: there's no value in this sort of the LLM garbage. There's value in the information, especially when formatted and provided in the humane format.
> And it never comes in a single dramatic announcement. It comes in layers. A feature post with a price change inside it. A LinkedIn update nobody made a press release about. A values page that says something slightly different than it did last week. If you’re still on Bitwarden cloud and this is giving you pause — it should. [...] Whether self-hosting stays viable long-term is the real question worth sitting with.
Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.
Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.
It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.
I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.
1) bundle the "source available" modules as part of redis source distribution 2) enable people who only want bsd code to be able to build a "redis_core" 3) commit to the community that the core will remain BSD licensed and that they are committed to making it the best key/value store. 4) increase the amount of source available code that until then had been kept closed (including what we called big redis/RedisOnFlash/MultiTier) 5) Require anyone using the redis trademarks in a commercial setting to ship the entire Redis (which includes the source available portions, so Amazon et al would no longer be able to use the Redis trademarks without a license deal.
Another alternative was to simply go to AGPL (which they went to anyways awhile later).
I failed to convince the leadership about this. I honestly think they squandered huge value in community engagement, but perhaps that's what they wanted. I left a bit after these changes were made as it became clear that the new US led leadership of the company wasn't particularity interested in what was the soul of redis. (previously was heavily Israeli led and a critical mass there was invested in redis as an open source product).
Funny story, the then new/current CEO used to be the head of WebEx at Cisco. We had a Q&A when he was hired and I asked, what did he learn from his time at WebEx about how to maintain market position (as they lost everything to zoom et al). His response at the time wasn't that convincing, but I was willing to give him the benefit of the doubt. I feel its fair to ask if the same thing occurred again.
"Some future components will be published under the commercial license and will exist only in that build."
(From that thread)
Pay the $20/yr or whatever to have them host it and the whole world keeps turning.
Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all.
by that logic, every time you send a password over a TLS connection, you're publishing it outright too
But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.
I'm not sure where your sentiment comes from here.
A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me. I much prefer 1Password's approach where they have a usually-hidden second secret (the "Secret Key") that both (A) isn't shown unless you're setting up another device, and (B) acts as extra data needed to form the decryption key for your vault.
The main threat model I'm thinking of protecting against is a 1password vault data breach of some kind (or possibly cooperation with government agencies) + password exposure in some way (be it from CCTV-extracted password entries, over-the-shoulder watching, etc), as even with both of those factors, they would somehow need to get your secret key to decrypt vaults.
Like, all of those lastpass vaults obtained during the Lastpass hack would be de-facto useless even with a correct password if their design included some sort of hidden secret secret.
Changing licenses is a sick move and companies doing that should be fucked over, because the license made them big. Changing it later on means that they got greedy nothing more nothing less.
Without oss bitwarden would be a paid cloud like all the others that probably would’ve had a hard time getting trusted.
Or just trying hard to keep the company afloat?
Just because they published Open Source code at some point, you feel that you're entitled to free updates for the rest of your life?
Everything will get chipped away piece by piece. It’s been happening continuously for well over a decade at this point and everyone should understand the strategy by now.
And it frequently fails to detect login fields, or does detect but fails to fill them with a generic error.
Admittedly the mobile clients have since been rewritten to be native (they were _really_ slow before), but Keyguard is still much faster/lighter.
I started using 1Password at work and it's just a.. nicer experience? It does all this and more. Everything is fast, the browser extension is more proactive/recognises fields better (Bitwarden can't really do multi step logins), and the desktop client isn't a chore to use.
The best comparison I would give is comparing Immich and Jellyfin (if you've used these), they are miles apart in terms of end user experience/polish/efficient design. One is engineered, the other feels like it's been hacked together by hobbyists.
Try to bring it up on bitwarden reddit sub, they will eat you alive
Then the community says it's okay, people are going to fork their clients, but that's gonna take trusting the future maintainers.
Also, even though they commit to keep maintaining an open source channel, we won't be able to verify the builds anymore.
Is that possible, does that exist?
anyway, the bigger issue ive with this is the doubling of the price right from the get-go.
with private equity on the steering wheel, i suspect this will keep going up every year from now on, so ... while i too have been a loyal customer to date, i suspect ill be driven out within the next 1-2 years, because if they double the price again next year, its gonna be way beyond the value i get out of it given how decent the alternative have become since.
Turns out Keyguard, an alternative Bitwarden client is already on the Play Store.
https://github.com/AChep/keyguard-app
Edit: turns out Keyguard is source available but fully copyrighted.
I'm not immediately upset about the licensing change - I get the need to protect from low effort/value add reselling and things like that. I do still worry if this is a canary for future changes that run counter to the reasons I migrated to bitwarden in the first place (open, robust, trustworthy).
Counter to many other commenters I personally prefer bitwarden over 1password, and certainly over lastpass and roboform, etc.
My only gripe is having to unlock the desktop app separately from the browser extension, which after adopting the ssh agent functionality became kinda annoying.
One of the family members I set up with Bitwarden has said it changed their life and they can't imagine not using it. I would guess that would apply to any crossplatform password manager but Bitwarden is quite good and the one that stuck.
I probably wouldn't move to one of these [1] because I don't like the UI of Proton Pass, the convenience of KeyPass, and 1Passsword is obvious. I'm interested in AliasVault as it seems to be a more privacy-focused password manager, which is cool, but I'd have to look more into it.
[1] https://www.privacyguides.org/en/passwords
[2] https://discuss.privacyguides.net/t/aliasvault-open-source-e...
Otherwise 1Password if you like paying money
From a quick look, that seems to be Desktop only.
iOS has a good open source app KeeForge to open the encryped password files. I use SyncTrain on my phone to connect to my SyncThing network.
I’m not sure why growth at all costs needs to be the business model for every company?… make a great product, if you need to charge more over time cool, but don’t rug pull.
They had/have(?) cybersale recently but did not offer the lifetime version. Otherwise I would have bought it. It is not open-source but it is damn convenient.
The fact that they still do not support Yubikeys is holding me back from switching, but I expect this to be ironed out soon.
I am in no way, shape, or form, endorsing this PonyApp thingy and cannot vouch for it as I haven't audited it. But judging by what it says on the tin, it does appear like a candidate to solve the specific problem I have.
[0]: https://www.passwordstore.org/
It's very badly explained what actually changes
I’ve put up with the minor annoyance of Bitwarden iOS app auto-updates breaking compatibility with my server, which requires me to update the docker instance.
It’s likely I’ll just switch to Apple, since I believe they support importing standard password DB formats. I have less enthusiasm now to maintain the link between these ecosystems, especially if one is on a downward enshittification trajectory.
> Some future components will be published under the commercial license and will exist only in that build. Newly developed features will be evaluated on a case-by-case basis for which license applies to them.
by which it means "no new features will land in OSS versions", as is tradition for open core development
How on earth does that work? Is that something the GPL license even allows?
This sounds like they're just taking a GPL licensed application and using it for themselves to make money.
To get any PR merged in Bitwarden, you are forced to sign a CLA that reassigns copyright to Bitwarden Inc so they can relicense as they wish.
> How on earth does that work? Is that something the GPL license even allows?
GPL doesn't apply in this case, since the copy that you are acquiring is entirely under the commercial license.
Only a matter of time until we see "OpenWarden", just like we saw the migration from Redis to Valkey.
But let's be honest. "enshittification" here really means "I don't want to pay for my tools and I want it completely for free forever."
Just look at the reactions towards the single UI change made in Firefox on HN [0] and already the complaints are there. Even if you charge your users $1 to remove tracking it is somehow "enshittification" because $1 is too much to pay for software maintenance.
The real cost of maintenance is the amount raised in VC capital (Bitwarden raised $100M) or $600M a year (Google paying Firefox). Donations won't cover the capital needed to fund Firefox or Bitwarden's development at all.
"Open source" is only sustainable when someone else is paying for that maintenance. Small donations will only take you so far until one core developer says that they are underpaid.
That is completely the opposite of what is happening here. Lots of us pay premium Bitwarden subscriptions and are not happy with the way the company is headed, especially for a security company that holds the keys to many of our kingdoms.
"enshittification" here means a company that we trusted is now started to make decisions which erode that trust. Its happened before and it will happen from here unto eternity.
Vaultwarden already exists
If it was only one change I doubt there'd be much pushback
Oss trying to protect itself from scalpers?