8 ms·
Concerns raised over Bitwarden moving further away from open source
- chx 2y agoSo there's nothing. > Being able to build the app as you are trying to do here is an issue we plan to resolve and is merely a bug. Tempest in a teapot. What about reporting a bug and chill? Instead of immediately jumping the gun and flooding the issue tracker of the one company that still tries with preaching? What is this going to achieve? Of course they locked it. Shame on everyone who commented some RMS-inspired lament into their issue queue.
- minebreaker 2y agoYour comment is misleading. What the CTO said is that, "build [failure] with bitwarden_license directory removed" is a bug. It doesn't change the fact that the SDK is not released under the free license. EDIT: citation EDIT2: s/CEO/CTO/
- chx 2y agoAnd you are wrong and I am right. As always when I post here (although I really am angry that I was right that AI will start killing people and it did). Bitwarden is doing the right thing. https://github.com/bitwarden/clients/issues/11611#issuecomment-2436287977 https://github.com/bitwarden/clients/issues/11611#issuecomme...
- bluSCALE4 2y agoI left Bitwarden as soon as they started using dark patterns in their UI. They got in the way instead of enhancing the user experience.
- addicted 2y agoWhat dark patterns have you observed that I should keep an eye out for?
- the_duke 2y agoMaking it seem like you can use a premium feature, only to present you with a "You need to upgrade" view after a few steps. Eg for Keypass and authenticator.
- godelski 2y agoI'm also not sure what utility the premium features are. There's the encrypted files, but they don't live in a vault. It seems that most obvious use case (being that you only get 1G) is to attach photos to IDs. But the implementation is silly. It's encrypted on their cloud where you download a copy and it then lives unencrypted on your device. It seems silly that this is the implementation considering your passwords live in a local vault where you don't need a network connection. Idk, I do want to support them but it does concern me when developers do not think about details, especially when it comes to security. The little things matter a lot.
- bluSCALE4 2y agoWhen you enabled the browser plugin, it would completely cover the input box, preventing you from using basic browser functionality meant to prevent you from using an alternative while it's enabled.
- Jamie9912 2y agoI never understood the appeal of web-based password managers. KeePass all the way, all offline, no randomly changing UI, everything in a single .db file. Need syncing? Use Cloud storage service.
- csomar 2y agoYou can do the same with Bitwarden by having the vault in your local computer.
- doctorpangloss 2y agoCan it fill passwords in iPhone Safari?
- jez 2y agoYes, via the KeePassium client: https://github.com/keepassium/KeePassium https://github.com/keepassium/KeePassium As with all iOS apps, there’s no guarantee that the open source app code on GitHub corresponds to what you install from the App Store. I have been very satisfied with KeePassium, it integrates with all the cloud storage providers I’d want and the app itself works well.
- mirashii 2y agoNotably though, Keepassium from the App Store is licensed differently than the version on GitHub. Only the Keepassium team can ever actually submit to the App Store as GPL software is banned, and so they do not accept contributions so that they have the ability to submit under a proprietary license.
- doctorpangloss 2y agoGPL software isn't banned. Is this just your speculation?
- jez 2y agoMy reading from the License section[1] of the Keepasium README and this Stack Exchange post[2] is that the author of KeePassium wishes to license KeePassium under GPLv3. Accepting applications licensed under GPLv3 would require that Apple provide certain forms of source code alongside App Store downloads which they are unwilling to do. As such the App Store terms of service has terminology stating that you give Apple the right to not do that, which is something that only the copyright holder(s) of a work can do. The simplest way to have clarity over who holds the copyright is to have a single author. So long as the KeePassium author is willing to assign Apple the permission implicit in submitting to the App Store, that’s fine. It just means that all other uses of KeePassium must follow the GPLv3 license. I am not a lawyer, nor really even well-versed in IP law, and you should not take this as legal advice. [1] https://github.com/keepassium/KeePassium?tab=readme-ov-file#license https://github.com/keepassium/KeePassium?tab=readme-ov-file#... [2] https://opensource.stackexchange.com/questions/9500/is-apple-allowed-to-distribute-gplv3-licensed-software-through-its-ios-app-store https://opensource.stackexchange.com/questions/9500/is-apple...
- OutOfHere 2y agoOpen source developers should think twice before accepting VC funding. The VC then own them.
- josu 2y agoWhat alternatives do you recommend?
- hannofcart 2y agoKeepassXC. https://keepassxc.org/ https://keepassxc.org/ Recently switched over from a premium Bitwarden account to it. Import from Bitwarden was a breeze. Note that KeepassXC only writes to a local encrypted db file. Syncing that across devices is left to you. I used Syncthing for that.
- cyberax 2y agoNo support for passkeys, either.
- zeofig 2y agoIt does support passkeys.
- cyberax 2y agoiOS application doesn't: https://github.com/keepassium/KeePassium/issues/297 https://github.com/keepassium/KeePassium/issues/297 Neither does the Android app: https://github.com/PhilippC/keepass2android/issues/2099 https://github.com/PhilippC/keepass2android/issues/2099
- zeofig 2y agoWell that SUCKS!
- trinsic2 2y agoI wouldn't trust passkey myself [0] [0]: https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/?ref=labnotes.org https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shatt...
- johnkizer 2y agoDisappointing that a website that touts itself for, among other things, "Open Source News", is missing the core definition issue in that headline: what is at issue here has zero to do with how open or closed the source code is. It's only related to how free/libre the license is. That's a big deal to some, no doubt, but it's important to be precise about language in cases like this, especially since folks will undoubtedly assume that this means secret user-hostile things will now be embedded in the source code, sight-unseen.
- happymellon 2y agoThe licence is the definition of Open Source.
- cyberax 2y agoI'm paying for BitWarden because I want to support them. But it's pretty clear that they're backsliding. This is understandable, the password manager market is saturated and implementing new features like Passkeys is far from trivial. Still, they are the only real option for a one-click mostly open source password manager that works across all the major platforms and that supports modern features.
- j16sdiz 2y agoIsn't passkey support already in? I am using that in day-to-day basis. Bugs exists, but it is not that far.
- cyberax 2y agoI mean that implementing things like passkeys required a lot of front-loaded work from them, without getting any compensation. So it's understandable that they're trying to push people to get subscriptions.
- SeriousM 2y agoEnpass is supported on all platforms and you can decide how and where you want to store your passwords (local up to cloud infras)
- ffsm8 2y ago> > for a one-click mostly open source password manager Enpass is open source? Since when?
- x3n0ph3n3 2y agoI wonder when they are going to start blocking official clients from using things like vaultwarden.
- ValentineC 2y agoI haven't looked at their clients repo [1] thoroughly, but I guess it's a good thing the bulk of their client apps are licensed under GPLv3 and can be easily forked. [1] https://github.com/bitwarden/clients https://github.com/bitwarden/clients
- froggerexpert 2y agoThis is disappointing. I use gopass for my personal passwords, but had moved family passwords to Bitwarden, and selected that hosted provide becauser it was open source. I will continue to vote with my wallet, with other open-first solutions like ente and etesync. Part of why I do this is so that if the company changes direction, the community can potentially fill in. With the momentum behind vaultgarden, maybe open clients will flourish too.
- Brajeshwar 2y agoI was concerned about BitWarden when it started copying or acting like 1Password. Their marketing text, features, etc., are similar. I understand there isn’t much to differentiate between Password Management tools. BitWarden was supposed to be the Open-Source alternative to 1Password and better than Keepass. I’m a customer of both services. I started with 1Password since its early days and have been using the family plan for the past 5+ years. I used BitWarden when starting with Teams, as it is cheaper and presumably scalable. I hope that if things grow up, we can either host it ourselves or the pricing is affordable enough. If Bitwarden becomes as “successful” as 1Password, people/companies will actually just use 1Password. I think, now, the idea would be to start moving all critical ones to Keepass; and use a better UX client on top of the database.
- mdaniel 2y agoOngoing thread that points to gasp the actual GitHub issue and not some rando site's take https://news.ycombinator.com/item?id=41893994 https://news.ycombinator.com/item?id=41893994
- dang 2y agoRecent and related: Bitwarden is no longer free software - https://news.ycombinator.com/item?id=41893994 https://news.ycombinator.com/item?id=41893994 - Oct 2024 (71 comments)
- ChrisArchitect 2y agoRelated: Bitwarden is no longer free software https://news.ycombinator.com/item?id=41893994 https://news.ycombinator.com/item?id=41893994 BitWarden leaves open source community https://news.ycombinator.com/item?id=41896750 https://news.ycombinator.com/item?id=41896750