Need help?
<- Back

Comments (236)

  • rsyring
    Very insightful blog post listed by another user as a sub-comment. Worth posting as a top-level comment:https://blog.ppb1701.com/the-quiet-renovation-at-bitwardenPreviously discussed: https://news.ycombinator.com/item?id=48163389
  • dannyw
    I actually find this somewhat understandable; and I'll be continuing my subscription; as long as all source continues to be available and personal self-hosting remains a viable option.Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.
  • arjie
    Okay, it’s good they have the open source because if you rewrite the Chrome extension you can get it to load in under 100 ms after you click the button. If you use the standard Chrome extension you’re not having that happen on an M1 Max. Their stuff is far too heavy. Full JS framework to display a small box.
  • 0l
    IMO Bitwarden really isn't that well engineered software, and I now use Keyguard on Android/Vaultwarden server instead. Reminds me of Subsonic, with many competing clients/servers. Hopefully someone will write a third party browser extension as the current one is quite slow/buggy.
  • figmert
    This was always inevitable when they took funding.
  • bigbaguette
    Everyone is mentioning Vaultwarden, but self-hosting this kind of service comes with quite a strong requirement of keeping it secure. Many might prefer letting a trusted actor take care of that.Then the community says it's okay, people are going to fork their clients, but that's gonna take trusting the future maintainers.Also, even though they commit to keep maintaining an open source channel, we won't be able to verify the builds anymore.
  • lucideer
    As a loyal Bitwarden user, I think this is great news.I love that Bitwarden exists, but as an "open source" project, it's always been a trad-corporate type code maintenance, rather than community-driven source contributions (exactly why we've seen things like Vaultwarden pop up) & that has generally just left all of their clients in that really awkward space where they're just good enough to be able to imagine their potential, but their maintenance is stagnant enough to ensure they'll never reach it.Imo the community needs this kick to motivate the development of alt vaultwarden clients. Bitwarden gives us a great starting point but we need to break away.
  • josephcsible
    Why does the title of this submission say "Dual License"? The linked page doesn't use that term anywhere, and it's also not an accurate description of what this change is.
  • zeroonetwothree
    I’ve been a premium subscriber for 10+ years and I have to admit I don’t really care about this license stuff. As long as it keeps working well I’m happy.
  • j1elo
    Instead of overlaying its own UI on top of form fields, I'd like Bitwarden (or any other PW manager) to act as a provider for the underlying system's native fill service, usually the browser, or Android, or OSX. They will always work much better than any 3rd party app.Is that possible, does that exist?
  • solarkraft
    I’m willing to commit money to a project committed to release free builds without these shenanigans.
  • aetherspawn
    Switch to free Apple Passwords and call it a day.
  • Cider9986
    This is enshittification but I'm not gonna drop Bitwarden unless they do something really bad. I'm already on the F-Droid version from their GitHub for my GrapheneOS phone because that one has no Google services/telemetry.One of the family members I set up with Bitwarden has said it changed their life and they can't imagine not using it. I would guess that would apply to any crossplatform password manager but Bitwarden is quite good and the one that stuck.I probably wouldn't move to one of these [1] because I don't like the UI of Proton Pass, the convenience of KeyPass, and 1Passsword is obvious. I'm interested in AliasVault as it seems to be a more privacy-focused password manager, which is cool, but I'd have to look more into it.[1] https://www.privacyguides.org/en/passwords[2] https://discuss.privacyguides.net/t/aliasvault-open-source-e...
  • brachkow
    In case you are all-Apple, there is no reason to use either 1Password or Bitwarden – since a few years ago Apple Passwords have everything you need
  • mnahkies
    Bitwarden is one of the few subscriptions I have in a patron sense - eg: I've never actually needed any of the premium feature's, but I chose to pay anyway as I felt that was a way to contribute to the long term viability of the project.I'm not immediately upset about the licensing change - I get the need to protect from low effort/value add reselling and things like that. I do still worry if this is a canary for future changes that run counter to the reasons I migrated to bitwarden in the first place (open, robust, trustworthy).Counter to many other commenters I personally prefer bitwarden over 1password, and certainly over lastpass and roboform, etc.My only gripe is having to unlock the desktop app separately from the browser extension, which after adopting the ssh agent functionality became kinda annoying.
  • mindracer
    This seems like the beginning of the end, what password manager is recommended now?
  • inexcf
    Well seems like Bitwarden is dying. A clear move towards enshittification. I was fine with the premium subscription existing while i was self-hosting Vaultwarden, but now every step seems to make that worse. Now new features will be under the commercial license an everything else will be slowly neglected. Time to jump ship.
  • andrewjneumann
    I get needing to price more, but it really feels like a slow shift to M&A, when they couple it with license changes and “case by case basis” to make it back to OSS.I’m not sure why growth at all costs needs to be the business model for every company?… make a great product, if you need to charge more over time cool, but don’t rug pull.
  • Beijinger
    I use enpass.io, the free version.They had/have(?) cybersale recently but did not offer the lifetime version. Otherwise I would have bought it. It is not open-source but it is damn convenient.
  • economic9725
    Don't be evil. Always.
  • karel-3d
    I don't understand the point or the motivation. They don't list any.It's very badly explained what actually changes
  • snapplebobapple
    So is there an alternative that i can migrate my business to with sso and zerotrust?
  • anon
    undefined
  • anilgulecha
    Rust based vaultwarden awaits.
  • anon
    undefined
  • robertlane0
    Licensing changes aside, this is why I've never been enthused for hosted password management, it's too easy for the terms of the agreement to change. (And in the case of LastPass, endless breaches). Honestly, plain KeePassXC and an arrangement to sync the password database has served me well because I can use any compatible client I can trust with it.
  • basilgohar
    Vaultwarden is a self-hostable protocol-equivalent alternative.
  • fiatpandas
    I’ve used vaultwarden and the official bitwarden macOS and iOS clients for a few years now, but it’s probably not wise to stay with it as a server long term, unless VW released their own apps.I’ve put up with the minor annoyance of Bitwarden iOS app auto-updates breaking compatibility with my server, which requires me to update the docker instance.It’s likely I’ll just switch to Apple, since I believe they support importing standard password DB formats. I have less enthusiasm now to maintain the link between these ecosystems, especially if one is on a downward enshittification trajectory.
  • EasyMark
    why do I always feel like "this is where the enshittification begins" when I hear about license changes, even though these seem kind of harmless? But I'm not a lawyer so my hackles always hackle. And yes I am a paying customer, currently
  • contravariant
    I'm a bit confused what they're actually doing. Their code is now covered by two different licenses with each file licensed under one of the two and they claim the resulting application is using the commercial Bitwarden license and not the GPL license?How on earth does that work? Is that something the GPL license even allows?This sounds like they're just taking a GPL licensed application and using it for themselves to make money.
  • PunchyHamster
    VC money gonna get their returns one way or another> Some future components will be published under the commercial license and will exist only in that build. Newly developed features will be evaluated on a case-by-case basis for which license applies to them.by which it means "no new features will land in OSS versions", as is tradition for open core development
  • tamimio
    Bitwarden was my go to a while ago before moving to self hosted, even tho my password in the vault can get leaked anytime they won’t matter (2fa not in the same vault), but still, I don’t trust saas or anyone anymore, all crucial things are self hosted.
  • charcircuit
    I don't see hours this business strategy works post LLMs. Someone's just going to immediately prompt into existence any commercial feature you make into the open source side.
  • scotty79
    I'll be moving to PearPass ... there's really no reason for any company to hold my passwords for me.
  • caaqil
    Unless they pull the LastPass crap, this is not a big deal for regular users.
  • rvz
    The problem with this license change is that it is unenforceable, now that developers believe they can vibe-code their own.Only a matter of time until we see "OpenWarden", just like we saw the migration from Redis to Valkey.But let's be honest. "enshittification" here really means "I don't want to pay for my tools and I want it completely for free forever."Just look at the reactions towards the single UI change made in Firefox on HN [0] and already the complaints are there. Even if you charge your users $1 to remove tracking it is somehow "enshittification" because $1 is too much to pay for software maintenance.The real cost of maintenance is the amount raised in VC capital (Bitwarden raised $100M) or $600M a year (Google paying Firefox). Donations won't cover the capital needed to fund Firefox or Bitwarden's development at all."Open source" is only sustainable when someone else is paying for that maintenance. Small donations will only take you so far until one core developer says that they are underpaid.[0] https://news.ycombinator.com/item?id=49892721
  • petterroea
    Yet another elasticsearch. Or terraform. Or redis. I guess?Oss trying to protect itself from scalpers?
  • hn3ufz62f7
    Ran Vaultwarden for a team of ~15 for years and that's the part I'd watch here, the clients are the leverage, not the server. If the mobile apps stop being buildable from source the self host story gets a lot thinner.