Settings

Theme

Bitwarden Dual License Model

community.bitwarden.com

157 points by Cider9986 · 108 comments

Reader

21 threads
rsyring

Very insightful blog post listed by another user as a sub-comment. Worth posting as a top-level comment:

https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden

Previously discussed: https://news.ycombinator.com/item?id=48163389

  • nugget

    Great find. This blog post - and specifically the background of the new management team - convinced me to start looking for a Bitwarden alternative. I’m watching the same “boil the frog” strategy unfold at Namecheap, and erode much of the brand trust they had built up over a decade, and it’s a shame.

    • turtletontine

      Have you settled on a BitWarden alternative, or a short list you’re considering?

      • birksherty

        Proton Pass. I stopped using Bitwarden for a different reason, the mobile app was too slow when not connected to internet. I can't accept such slowness, the company will definitely give justifications for this. But I don't care, let me see my passwords or notes for a website immediately. Proton Pass is better in this regard.

    • backlit4034

      GlassDoors reveal the other side of the story

      https://www.glassdoor.com/Reviews/Bitwarden-Reviews-E4337610...

      • alt227

        Wow, another site that now refuses to play ball unless you sign in.

        Guess I'll never be visiting Glass Door again then.

        • chanux

          I can kind if understand how forcing everyone to add on to the pile of content, from a business point of view.

          However they may have proved that they are indeed.. trash. Maybe even a few times.

          One such case was https://www.forrester.com/blogs/glassdoors-mishandling-of-cu...

          In my eyes they are in the same class of Facebook, uservoice, Pinterest, Quora etc.

        • to11mtm

          GlassDoor has been gross about this for years.

          Not sure if still the case but normally you have to not only 'sign in' but also feed them information (e.x. salary at a position, write a review, etc.) in order to be able to view much of anything.

          They also do not give a shit about obvious 'juicing' (i.e. when it is obvious that upper management and/or HR is adding reviews where the 'con' reads like one of those softball warning phrases in a job description.)

        • happosai

          With the AI(?) bots doing a DDOS on on public websites via residential proxies the future is all website will require login.

  • Aardwolf

    Ok this is doing some damage. What's a possible alternative that works on both mobile and desktop, doesn't require yourself to run a server, and doesn't have worse reputation?

    • terminalbraid

      keepassxc works across any major platform, mobile platforms have keepass2android and KeePassium. You don't have to run your own server, but you do need some type of file sharing system to keep them synced. I personally run a webdav share on a vps with some sync scripts to keep a backup on devices otherwise. OneDrive, google drive, dropbox, and others work.

      Also protonpass.

      • Arrowmaster

        I specifically moved away from KeePassXC to Bitwarden with self hosted vaultwarden because the Linux desktop experience and mobile syncing was so terrible. While I love KeePassXC, using it on an immutable Linux distro where everything needs to be Flatpak means the browser extension doesn't work because it doesn't support Flatpak'd browsers back when I switched. Auto type is a security nightmare and is not an option. Syncing does not exist and with the constant death and forking of Syncthing on Android, it became unusable to randomly find out my db hasn't synced for a week and now I have to reset everything with a new fork yet again.

        Bitwarden was the no nonsense choice because it just worked.

      • GordonS

        Any good reason to use keepassxc rather than regular KeePass?

    • Lapel2742

      Proton Pass?

      I already have "Proton Unlimited" as a subscription but until now I never used Proton Pass. I thought about giving up on Bitwarden for some time and probably will try it now. AFAIK you can even import your Bitwarden logins.

      • InsideOutSanta

        I think Proton Pass is currently the best non-self-hosted option, and Proton's corporate structure offers some protection against enshittification.

    • orta

      I like Enpass

  • Cort3z

    I hate this. So much software I love keeps doing this. redis, docker, now bitwarden. I was so happy with bitwarden. Been a premium subscriber for many years. I have helped convert many people, including whole companies, to use this. Now they are doing us such a disservice. We need a completely free, no-nonsence, alternative. I wonder if it is possible to do a ipfs/torrent version without a central authority to permanently prevent this type of issue.

  • alt227

    I feel like this blog post deserves its own submission to HN

  • dizhn

    Started humany but degraded into LLM speak towards the end. Especial the Vaultwarden section.

    • stavros

      It's all LLMese, start to finish. I found it hard to get through. Could have just been a bulleted list and it would have been better.

    • alt227

      So? It was useful information, who cares how it was written.

dannyw

I actually find this somewhat understandable; and I'll be continuing my subscription; as long as all source continues to be available and personal self-hosting remains a viable option.

Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.

Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.

It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.

I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.

  • compsciphd

    I was at redis when they changed the license (the first time). I begged the new leadership to not change the core license but to do a few things instead.

    1) bundle the "source available" modules as part of redis source distribution 2) enable people who only want bsd code to be able to build a "redis_core" 3) commit to the community that the core will remain BSD licensed and that they are committed to making it the best key/value store. 4) increase the amount of source available code that until then had been kept closed (including what we called big redis/RedisOnFlash/MultiTier) 5) Require anyone using the redis trademarks in a commercial setting to ship the entire Redis (which includes the source available portions, so Amazon et al would no longer be able to use the Redis trademarks without a license deal.

    Another alternative was to simply go to AGPL (which they went to anyways awhile later).

    I failed to convince the leadership about this. I honestly think they squandered huge value in community engagement, but perhaps that's what they wanted. I left a bit after these changes were made as it became clear that the new US led leadership of the company wasn't particularity interested in what was the soul of redis. (previously was heavily Israeli led and a critical mass there was invested in redis as an open source product).

    Funny story, the then new/current CEO used to be the head of WebEx at Cisco. We had a Q&A when he was hired and I asked, what did he learn from his time at WebEx about how to maintain market position (as they lost everything to zoom et al). His response at the time wasn't that convincing, but I was willing to give him the benefit of the doubt. I feel its fair to ask if the same thing occurred again.

  • trentor

    I would be with you if they didn't change the owner to private equity in the last year.

  • solarkraft

    I’m conflicted. On one hand I’m grateful for the years of trustworthy (and pay-what-you-want) password management. On the other this feels like an attempt to EEE the free version.

    • freedomben

      That's my concern as well. I have no problem with the current license change if they continue to publish all the code as they claim. My concern is that this is usually step 1 in a boil-the-frog strategy to eventually split and break off enterprise features. I'll give them some trust until they give me a reason not to (I think they've earned it), but the concern remains.

      • 4ndrewl

        They don't?

        "Some future components will be published under the commercial license and will exist only in that build."

        (From that thread)

  • selectodude

    The thing I always think about is that they wouldn't have to change the license and tighten the screws if people paid for it. Getting mad that the free hosted password manager has changed the deal a little bit I find to be quite arrogant.

    Pay the $20/yr or whatever to have them host it and the whole world keeps turning.

    • lstodd

      Hosted password manager is equivalent to publishing all your passwords outright.

      Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all.

      • ricericerice

        you have no idea how bitwarden works, do you...

        by that logic, every time you send a password over a TLS connection, you're publishing it outright too

      • techjamie

        People are going to try much harder to break into the main Bitwarden servers than they are my little Vaultwarden instance. Plus, I have the ability to lock it behind a VPN so it isn't even publicly exposed.

        But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.

        I'm not sure where your sentiment comes from here.

        • judge2020

          > But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.

          A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me. I much prefer 1Password's approach where they have a usually-hidden second secret (the "Secret Key") that both (A) isn't shown unless you're setting up another device, and (B) acts as extra data needed to form the decryption key for your vault.

          The main threat model I'm thinking of protecting against is a 1password vault data breach of some kind (or possibly cooperation with government agencies) + password exposure in some way (be it from CCTV-extracted password entries, over-the-shoulder watching, etc), as even with both of those factors, they would somehow need to get your secret key to decrypt vaults.

          Like, all of those lastpass vaults obtained during the Lastpass hack would be de-facto useless even with a correct password if their design included some sort of hidden secret secret.

        • atherton94027

          I'm not sure that calculus is going to be true for much longer – with the costs of AI falling, it's going to be much easier to throw tokens at the problem even tiny targets that wouldn't have been worth it before. Can you guarantee your VPN is patched and secure at all times?

        • technolo-g

          I took it to mean non-self hosted is like publishing your passwords online, which I agree with.

        • iohvvbhdyh

          AI will do it

      • selectodude

        I mean, no it's absolutely nothing like "publishing all your passwords outright" but fine. Pay the $20/yr and don't have them host it, host it yourself. Just pay them the $20.

      • orf

        Your comment is generally ignorant on infosec.

      • willmadden

        Do you have a quantum computer from the future and a file of passwords that haven't been changed in 50 years? Complete nonsense.

  • behringer

    That's not what's happening here. They're making their app closed source with closed source features. Time to find a new provider.

  • merb

    Sorry but the elasticsearch thing was a big stupid take of elastic. It was big corpo against big corpo not the poor elastic company.

    Changing licenses is a sick move and companies doing that should be fucked over, because the license made them big. Changing it later on means that they got greedy nothing more nothing less.

    Without oss bitwarden would be a paid cloud like all the others that probably would’ve had a hard time getting trusted.

arjie

Okay, it’s good they have the open source because if you rewrite the Chrome extension you can get it to load in under 100 ms after you click the button. If you use the standard Chrome extension you’re not having that happen on an M1 Max. Their stuff is far too heavy. Full JS framework to display a small box.

zeroonetwothree

I’ve been a premium subscriber for 10+ years and I have to admit I don’t really care about this license stuff. As long as it keeps working well I’m happy.

  • talon8635

    I’m the same. It’s a paltry price for an outstanding product with great features that improves my life/security greatly

0l

IMO Bitwarden really isn't that well engineered software, and I now use Keyguard on Android/Vaultwarden server instead. Reminds me of Subsonic, with many competing clients/servers. Hopefully someone will write a third party browser extension as the current one is quite slow/buggy.

  • tmulcahy

    What about it isn't well engineered?

    • 0l

      It's all just slow and mediocre. The Windows desktop client is a massive almost 400MB-download behemoth (and is electron-based), and if you have SSH keys you want to store in it you have no choice but to use it. Oh and you can't log into the browser extension automatically from the desktop client.

      Admittedly the mobile clients have since been rewritten to be native (they were _really_ slow before), but Keyguard is still much faster/lighter.

      I started using 1Password at work and it's just a.. nicer experience? It does all this and more. Everything is fast, the browser extension is more proactive/recognises fields better (Bitwarden can't really do multi step logins), and the desktop client isn't a chore to use.

      The best comparison I would give is comparing Immich and Jellyfin (if you've used these), they are miles apart in terms of end user experience/polish/efficient design. One is engineered, the other feels like it's been hacked together by hobbyists.

    • mceachen

      Syncing is iffy. Saving credentials associated to a shared org fails randomly. Rendering (x11/Firefox) sometimes fails completely, but is predictably slow. Auto fill can be buggy. Opening vaults on iOS can be remarkably slow.

  • schleck8

    Isn't Vaultwarden using the same clients?

figmert

This was always inevitable when they took funding.

solarkraft

I’m willing to commit money to a project committed to release free builds without these shenanigans.

  • Cider9986OP

    Bitwarden is still releasing free builds but yeah you'd need a new project with a new name to use it from the Play Store or App Store.

    Turns out Keyguard, an alternative Bitwarden client is already on the Play Store.

    https://github.com/AChep/keyguard-app

    Edit: turns out Keyguard is source available but fully copyrighted.

    • alt227

      So if we now have Vaultwarden + keyguard can these things move away from Bitwardens api and pursue their own?

      • InsideOutSanta

        Is there any reason to? It's kinda nice that they all stick to the same contract. I don't really like the Bitwarden desktop app, but because there's so much code out there, it was pretty easy to have an LLM write a detailed spec for a client and then implement something that works for me.

robertlane0

Licensing changes aside, this is why I've never been enthused for hosted password management, it's too easy for the terms of the agreement to change. (And in the case of LastPass, endless breaches). Honestly, plain KeePassXC and an arrangement to sync the password database has served me well because I can use any compatible client I can trust with it.

Cider9986OP

This is enshittification but I'm not gonna drop Bitwarden unless they do something really bad. I'm already on the F-Droid version from their GitHub for my GrapheneOS phone because that one has no Google services/telemetry.

One of the family members I set up with Bitwarden has said it changed their life and they can't imagine not using it. I would guess that would apply to any crossplatform password manager but Bitwarden is quite good and the one that stuck.

I probably wouldn't move to one of these [1] because I don't like the UI of Proton Pass, the convenience of KeyPass, and 1Passsword is obvious. I'm interested in AliasVault as it seems to be a more privacy-focused password manager, which is cool, but I'd have to look more into it.

[1] https://www.privacyguides.org/en/passwords

[2] https://discuss.privacyguides.net/t/aliasvault-open-source-e...

fiatpandas

I’ve used vaultwarden and the official bitwarden macOS and iOS clients for a few years now, but it’s probably not wise to stay with it as a server long term, unless VW released their own apps.

I’ve put up with the minor annoyance of Bitwarden iOS app auto-updates breaking compatibility with my server, which requires me to update the docker instance.

It’s likely I’ll just switch to Apple, since I believe they support importing standard password DB formats. I have less enthusiasm now to maintain the link between these ecosystems, especially if one is on a downward enshittification trajectory.

mindracer

This seems like the beginning of the end, what password manager is recommended now?

  • pprotas

    KeepAssXC + SyncThing works well if you don't mind tinkering and like independence from corporations

    Otherwise 1Password if you like paying money

    • cricalix

      1Password has the whole thing of providing money to Omarchy's foundation. For some, that is a hard blocker.

    • LeBit

      Keep Ass XC? Is it a fork?

    • Mashimo

      > KeepAssXC + SyncThing works

      From a quick look, that seems to be Desktop only.

      • pprotas

        Not desktop only, KeePass uses an encrypted file, all you need is a way to decrypt it. You can store it in iCloud or whatever you like to sync files between devices.

        iOS has a good open source app KeeForge to open the encryped password files. I use SyncTrain on my phone to connect to my SyncThing network.

        • mindracer

          I use syncthing for my Linux devices but though it didn’t work on iOS. Will check out SyncTrain, thanks!

      • Zambyte

        Look longer :)

      • upboundspiral

        It's unfortunate that its a bit fragmented but there are Android / iOS complements as well - respectively keepassDX and keepassium.

        • pprotas

          You can see it as fragmentation, or you can look at it as having a choice. You can pick and choose how you access your data, without any corporation screwing you over the first chance they get.

karel-3d

I don't understand the point or the motivation. They don't list any.

It's very badly explained what actually changes

inexcf

Well seems like Bitwarden is dying. A clear move towards enshittification. I was fine with the premium subscription existing while i was self-hosting Vaultwarden, but now every step seems to make that worse. Now new features will be under the commercial license an everything else will be slowly neglected. Time to jump ship.

  • movsx

    I have been eyeballing PassPony[0] as a replacement.

    The fact that they still do not support Yubikeys is holding me back from switching, but I expect this to be ironed out soon.

    [0]: https://passpony.app/

    • 0l

      Looks far too sloppy for me to trust this software with my passwords...

      • movsx

        I do not like the idea of self-hosting VaultWarden because I generally do not like the idea of application software requiring so much random access memory for even the simplest tasks. So, my idea was to use something like pass[0] or passage[1] (pass[0] + age[2]) on a remote server, but the problem arises when Yubikeys come into play.

        I am in no way, shape, or form, endorsing this PonyApp thingy and cannot vouch for it as I haven't audited it. But judging by what it says on the tin, it does appear like a candidate to solve the specific problem I have.

        [0]: https://www.passwordstore.org/

        [1]: https://github.com/FiloSottile/passage

        [2]: https://github.com/FiloSottile/age

  • blahlabs

    Any suggestions or ideas for where to?

anilgulecha

Rust based vaultwarden awaits.

contravariant

I'm a bit confused what they're actually doing. Their code is now covered by two different licenses with each file licensed under one of the two and they claim the resulting application is using the commercial Bitwarden license and not the GPL license?

How on earth does that work? Is that something the GPL license even allows?

This sounds like they're just taking a GPL licensed application and using it for themselves to make money.

  • watusername

    It's how a lot of open-core products work. Basically, when you hold the copyright, you can apply whatever license you wish when distributing the software at any time. People can use existing copies of the code under their old licenses, but they must follow the new terms if they acquire the code through the new channels.

    To get any PR merged in Bitwarden, you are forced to sign a CLA that reassigns copyright to Bitwarden Inc so they can relicense as they wish.

    > How on earth does that work? Is that something the GPL license even allows?

    GPL doesn't apply in this case, since the copy that you are acquiring is entirely under the commercial license.

charcircuit

I don't see hours this business strategy works post LLMs. Someone's just going to immediately prompt into existence any commercial feature you make into the open source side.

scotty79

I'll be moving to PearPass ... there's really no reason for any company to hold my passwords for me.

caaqil

Unless they pull the LastPass crap, this is not a big deal for regular users.

rvz

The problem with this license change is that it is unenforceable, now that developers believe they can vibe-code their own.

Only a matter of time until we see "OpenWarden", just like we saw the migration from Redis to Valkey.

But let's be honest. "enshittification" here really means "I don't want to pay for my tools and I want it completely for free forever."

Just look at the reactions towards the single UI change made in Firefox on HN [0] and already the complaints are there. Even if you charge your users $1 to remove tracking it is somehow "enshittification" because $1 is too much to pay for software maintenance.

The real cost of maintenance is the amount raised in VC capital (Bitwarden raised $100M) or $600M a year (Google paying Firefox). Donations won't cover the capital needed to fund Firefox or Bitwarden's development at all.

"Open source" is only sustainable when someone else is paying for that maintenance. Small donations will only take you so far until one core developer says that they are underpaid.

[0] https://news.ycombinator.com/item?id=49892721

  • rkent

    Thunderbird is a rare counter-example of an open source project that manages to maintain a significant staff through donations. Although affiliated with Mozilla, they are not funded by Mozilla. (I am no longer affiliated with Thunderbird, but I managed the project in the dark years after Mozilla suddenly dropped all funding and tried to get us to leave Mozilla.)

  • malfist

    I "new Firefox design" is hardly "single UI change"

    If it was only one change I doubt there'd be much pushback

  • alt227

    > But let's be honest. "enshittification" here really means "I don't want to pay for my tools and I want it completely for free forever."

    That is completely the opposite of what is happening here. Lots of us pay premium Bitwarden subscriptions and are not happy with the way the company is headed, especially for a security company that holds the keys to many of our kingdoms.

    "enshittification" here means a company that we trusted is now started to make decisions which erode that trust. Its happened before and it will happen from here unto eternity.

petterroea

Yet another elasticsearch. Or terraform. Or redis. I guess?

Oss trying to protect itself from scalpers?

  • Rebelgecko

    The new owners are just seeing how gradually they can boil the frog before the userbase moves elsewhere. Gotta maximize returns.

hn3ufz62f7

Ran Vaultwarden for a team of ~15 for years and that's the part I'd watch here, the clients are the leverage, not the server. If the mobile apps stop being buildable from source the self host story gets a lot thinner.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection