18 ms·
Bitwarden SDK relicensed from proprietary to GPLv3
- petterroea 2y agoThank you Bitwarden for listening. This kind of stuff gives me hope for the business model of Open Source.
- chx 2y ago[flagged]
- attendant3446 2y agoHow would you explain that[1]? 1. https://github.com/bitwarden/sdk/issues/898#issuecomment-2222992484 https://github.com/bitwarden/sdk/issues/898#issuecomment-222...
- petterroea 2y agoThey still handled the situation in a serious and responsible manner, clearly communicating what had happened and why. They then followed up later when the problem was fixed. To me it seems clear that they understood the seriousness of the situation, and why people were initially pissed. I think this is the correct way of handling a rugpull scare, bug or not.
- ferbivore 2y agoAlso: https://github.com/bitwarden/clients/issues/11611#issuecomment-2436287977 https://github.com/bitwarden/clients/issues/11611#issuecomme... Previously: https://news.ycombinator.com/item?id=41893994 https://news.ycombinator.com/item?id=41893994
- teach 2y agoThank you. I had missed this story and was struggling to piece things together from the varied comments.
- Scipio_Afri 2y agoWell that’s one way to handle that effectively and in what seems to be open source way without fuckery; glad to hear it cause that was going to be a bit annoying migrating away from them.
- weikju 2y agoProps for them to step in the right direction, it wasn’t obvious at all for a few days what they would do.
- chx 2y agoRepeatedly: when people post shit like this they more or less guarantee the next company won't even try. People! this is one of the few companies which open sources their product. The time to doubt and preach is not here yet... by far.
- AdmiralAsshat 2y agoNot really. It was keeping them honest. This wasn't like the Winamp thing. Bitwarden has proudly proclaimed itself as "Open Source" from day one. It's right on their front page. It's in their marketing materials. It's in their podcast advertisements. I pay for Bitwarden based on the premise that it is open source. If it tries to pull a Meta and decide that "open source" suddenly means whatever they want it to mean in defiance of the commonly-understood meaning, I want to know about it. I'm glad they righted the ship on this.
- threatofrain 2y agoGPLv3 is interesting because it means to use their code in a commercial setting, then you must also have the guts to open source too.
- hk1337 2y agoI don’t believe that is entirely accurate. I believe it depends on the application and what you’re doing with it whether or not you would be required to open source it. Like, if you’re distributing the application as a product, not necessarily saas application?
- HeatrayEnjoyer 2y agoYes, this is why AGPL is superior.
- nine_k 2y agoYes, GPL3 only works for directly distributed software. But an important part of BitWarden is exactly such software, in the form of a browser extension.
- odo1242 2y agoNot necessarily. You can run a “Bitwarden hosting service” or something like that without violating GPL. You’d only have to make your changes available on request if you changed the actual Bitwarden source code or linked some other library into it and shared that modified version with someone else (just running it on a server doesn’t mean you need to open source changes, for example)
- hedora 2y agoYeah; GPLv3 seems designed to give pure *aaS companies an unfair advantage over people that want to give users the option to buy commercially supported hardware that runs the company's software. For instance, Google can use bash in their backend infrastructure, but Apple cannot ship it on MacBooks or iOS anymore.
- minebreaker 2y agohttps://github.com/bitwarden/clients/issues/11611#issuecomment-2436287977 https://github.com/bitwarden/clients/issues/11611#issuecomme... > We have made some adjustments to how the SDK code is organized and packaged to allow you to build and run the app with only GPL/OSI licenses included. The sdk-internal package references in the clients now come from a new sdk-internal repository, which follows the licensing model we have historically used for all of our clients (see LICENSE_FAQ.md for more info). The sdk-internal reference only uses GPL licenses at this time. If the reference were to include Bitwarden License code in the future, we will provide a way to produce multiple build variants of the client, similar to what we do with web vault client builds.
- deleted 2y ago[deleted]
- jdlyga 2y agoBitwarden is still excellent, but keep an eye on them over the next few years. Remember that Bitwarden was originally a LastPass alternative without the fuckery.
- deleted 2y ago[deleted]
- odo1242 2y agoI mean, it still is. It’s honestly gotten better too - for evidence, it’s the one password manager that never gets recommended by sponsored YouTubers but always gets recommended by non-sponsored YouTubers.
- afavour 2y agoIt depresses me that Bitwarden has also taken VC funding, just like 1Password. It’s still a great product but as with any VC product I’m just waiting for the other shoe to drop when it’s revenue generation time.
- KPGv2 2y agoI honestly don't think the password manager market could bear more than $3–5/mo for an individual user or family. I used 1Password for years until they went from one-time payment to monthly sub and removed local sync so you could only use multiple devices by paying them. I think a big decision there was that they wanted $10/mo or something. I can't remember, but at the time it seemed ludicrous. Years later, when my new laptop couldn't run the final local-sync version of 1Password, I finally decide to look into password managers again, and lo and behold $3/mo. I signed up immediately.
- prophesi 2y agoThe LastPass fuckery was long and frankly egregious. Though I don't understand why this git commit is what's linked here. I'd rather hear the discussions on it. https://github.com/bitwarden/clients/issues/11611 https://github.com/bitwarden/clients/issues/11611
- ok_dad 2y agoLuckily if they die another will rise up. At this point I’m thinking I’ll just use the Apple Keychain if Bitwarden gets up to no good again.
- lxgr 2y agoTwo things are preventing me from doing that: I occasionally want to access my passwords in a browser (and I do not want to log in to iCloud on that machine), and I'd feel really bad about having my passkeys stored in an Apple service with absolutely no way of exporting them in case I ever do switch platforms. (Bitwarden at least includes passkeys in their JSON export format, as far as I know.)
- ValentineC 2y agoAs another commenter has mentioned, Apple Passwords allows export to simple CSV: https://support.apple.com/en-us/guide/passwords/mchl35b12625/mac https://support.apple.com/en-us/guide/passwords/mchl35b12625... What I dislike about Apple Passwords is how tightly coupled everything is. I just tried to set it up on my Windows 10 machine with a local account, but it requires Windows Hello to be turned on, which can't be done except with a Microsoft account. Kinda ridiculous of them to force arbitrary restrictions on us.
- lxgr 2y ago> Apple Passwords allows export to simple CSV Not of passkeys, to my knowledge. > What I dislike about Apple Passwords is how tightly coupled everything is. That’s definitely also discouraging me as well.
- rascul 2y agoWhat was the no good that Bitwarden got up to?
- abathur 2y agohttps://news.ycombinator.com/item?id=41893994 https://news.ycombinator.com/item?id=41893994
- MisterKent 2y agoPeople here are incredibly hard to please. Very clearly a packaging issue that got blown out of proportion. They've done largely the right things for _years_ in terms of security. They've operated pretty transparently in terms of open sourcing. They've allowed vaultwarden to exist, and eventually created a self hostable version as well. But one bad release with a license screw up and nobody is willing to give them an inch? I will continue to use bitwarden, and am willing to give them the benefit of the doubt. Especially considering this action above. They are a company that is perfectly toeing the free/oss and commercial line.
- sneak 2y agoFor a long time their KDF was bad and the iteration count was low. When I reported it to them they got really hostile and evasive about it. Years later they switched to Argon, somehow solving all of the blocking problems they had repeatedly claimed they couldn’t fix. I don’t trust the org at all. The software is ok but I only use it because it sucks marginally less than all my other options. People who care about software freedoms don’t release proprietary software. Organizations like this or Microsoft are just engaging in open source cosplay.
- gertop 2y ago> When I reported it to them they got really hostile You're not the one who first reported it, but I did see your comments at the time. Calling them hostile is really the pot calling the kettle black, uh?
- gitaarik 2y agoTo me the story also sounds a bit like GP was a bit impatient and felt a bit ignored while the company was already working on the issue but just didn't respond promptly to per personally.
- j_crick 2y agoYou build a hundred solid bridges and you get called John the Good Bridge Builder. But lest you once screw up your software licensing and people notice and it blows up, you'll end up as John the Software Screwer in the annals of history... until next week.
- PaulKeeble 2y agoOnce an organisation has tried once they invariably do it again and again until they find a way to getting what they want. The customers tire of complaining over and over about little enshitifcations and eventually the company wins. Once they start it always goes the same way it just often takes a few goes before most give in. It will years until it becomes awful but the process has started. It's really a shame every company has to do this with otherwise good products.
- gitaarik 2y agoIf that would be the case, I wouldn't have expected them to change it back. I don't think it was that bad of an impact for them, they are already big enough in non-hardcore-open-source communities that they could pull it off and afford to lose some customers to go propietary. I'm actually really positively surprised by them that they actually picked up on this issue raised by the community and that they fixed it very promptly. Yes the trust was seriously damaged, but this move does restore it largely for me.
- sneak 2y agoDoesn’t GPL mean that it can’t be forked and published into the Apple iOS app store? Presumably they are able to do it because they own the rights and can grant a non-GPL license to Apple for distribution. This seems to me to still be a “nobody can fork this [and still have a viable iOS app] but us”.
- cxr 2y agoThe last time anyone did a serious published review of the App Store terms for GPL compatibility was probably 10+ years ago. I remember pre-COVID trying to validate the popular claim that the App Store terms were incompatible with GPLv3 but being unable to do so. None of the provisions that were originally called out by the FSF were in the App Store terms anymore at that point. Certainly nothing I found in the terms at the time indicated any incompatibility.
- FateOfNations 2y agoWhenever I've heard about someone having problems publishing a fork on the App Store, it was a trademark rather than a copyright issue. If you fork it, you must completely re-brand it to publish it on the App Store.
- throwaway290 2y agoDon't forget disclosing the source to users!
- master-lincoln 2y agoEverybody can fork this and build an iOS app. You just can't distribute through the app store as far as I understand. Would be good now if there were other means to install an app on iOS for non-devs, but users chose to ignore that issue when they joined the walled garden that is Apple Inc Maybe the European Union comes to the rescue... (for Europeans)
- blendergeek 2y agoThank you to Bitwarden for relicensing a thing to Free/Open License! Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good. But for anyone with more advance needs (or who doesn't trust a password manager built into a web browser, I always recommend Bitwarden because KeepassXC + syncing is way too difficult for normal people.
- lxgr 2y agoCan it store TOTPs and passkeys as well? These are two things encountered even by "regular people" more and more. Especially keeping passkeys platform-independent is a huge advantage, in my view.
- Uvix 2y agoYes, Bitwarden can store both.
- freedomben 2y agoThere will always be different opinions, but my opinion is that storing your TOTPs in your password manager is at best a reduction in security because you're reducing your 2 factors down to 1 factor. If the password manager gets compromised (even phished! It needn't involve the password manager's servers getting hacked), then you gain nothing by having 2FA enabled. I would strongly advise using something like Aegis on Android, or Gnome Authenticator on desktop (or both). I like to duplicate/backup my seeds so that I'm not SOL if my phone breaks, but I do it by having them on my laptop, desktop, and phone. That way as long as I have one of the three devices, I can always get in, and then they're not "in the cloud." Though, "in the cloud" is still better than "in the cloud alongside all my passwords."
- AzzyHN 2y agoI don't know why people are saying this is a bad thing.
- crossroadsguy 2y agoSimilarity to past experiences of start of the declines of service/apps.
- Capricorn2481 2y agoWhat app got worse after going open source that you're thinking of?
- crossroadsguy 2y ago> after going open source I wasn't thinking that at all. BW started as open source afaik.
- Capricorn2481 2y agoThat's the point.
- alt227 2y agoIts not 'going open source' as they were always open source, its change of license. Plenty of other products started slipping downhill after management saw a need to change the license. Why else would you change your license terms if its not to then be able to change your business practises down the road?
- Capricorn2481 2y agoI was posing a hypothetical for people that seem to think they were never open source. They packaged a proprietary part of Bitwarden into the app and quickly relicensed it to GPL. I don't see how you think introducing a GPL license is gonna lead to worse business practices? Unless you don't know what the license is.
- jgauth 2y agoThis update is great news. I was disappointed to see the issue that got raised last week, and I had started to consider looking for alternatives. I’m going to assume an honest mistake on their end and keep recommending their product. However, if they make a similar move again, I will assume the worst and move on.
- ValentineC 2y agoTo be fair, Bitwarden clients are mostly GPL and can be forked, and there's Vaultwarden for self-hosting. We just need to rally together a community that would maintain such a fork.
- ferbivore 2y agoThe iOS client can never be meaningfully forked, ironically due to the GPL. If Bitwarden goes fully hostile that's lost forever.
- ValentineC 2y agoI don't understand; isn't the repo licensed under GPLv3? https://github.com/bitwarden/ios?tab=GPL-3.0-1-ov-file https://github.com/bitwarden/ios?tab=GPL-3.0-1-ov-file Is proprietary config required to build the IPA file?
- ferbivore 2y agoI was under the impression that Apple requires apps to be distributed under terms which conflict with the GPLv3, so the copyright holders effectively need to dual-license an app for it to be suitable for the App Store. Uploading your own version of bitwarden/ios would then open you up to a takedown notice from Bitwarden Inc. since they didn't consent to this. Looking into it again, it seems like the Apple Media Services T&C now has provisions for distributing apps under a "Custom EULA", but it still has weird clauses like the one saying you can't "scrape, copy, or perform measurement, analysis, or monitoring of, any portion of the Content", which their definition of includes apps. (Ridiculous clause since it prohibits so much as looking at an app with Activity Monitor, but whatever.) The GPLv3 has a provision saying users can ignore additional restrictions, but you as an App Store uploader aren't in a position to grant that right, so... the situation still seems legally iffy enough that I'm not sure you could win against Bitwarden if they objected to a fork.
- shelled 2y agoBitWarden has lost the trust. Besides recently there was a blocker bug on iOS and on Reddit I found out it happened earlier as well. They didn't even want to debug it and when I suggested this and asked whether they have any issue logged on Github where I could provide logs they went radio silent. Follow ups went completely unanswered. And yeah before that they had given a solution (because reinstall/re-login nothing had worked) - export your data, delete your account, create the account again, and re-import your data - that "should" work. Honestly it was worse than "restart your computer". I guess it's time for another FOSS player here. It's fine, such things are cyclical I guess. Happened to Lastpass and Authy and someday it will happen to Ente and 2FAS and so on.
- chx 2y ago[flagged]
- Capricorn2481 2y ago> BitWarden has lost the trust. Besides... I'm confused what you're responding to. You're making it sound like this was a bad decision and your anecdote was another thing for the pile, but this is a good decision.
- hnbad 2y agoSomeone else linked the GitHub issue that triggered this change and most of the replies are in the same tone as the comment you're responding to. Which is all the more ridiculous as this looks like it wasn't really a big license change decision but more of a "forgot to change the license on a component from our internal default". Assuming malice seems like the most boneheaded reaction to this given that there are no other indications Bitwarden was trying to do anything nefarious and the previous license state would have made every single library or tool depending on it non-free. This is different from criticisms of Mozilla for example which often boil down to "Mozilla positioned itself as privacy-focused but adds a privacy-violating feature you have to opt out of while claiming it's actually fine". Bitwarden never was 100% FLOSS to begin with but introducing downstream license problems is clearly against their own interest. Unless you believe Bitwarden is run by evil idiots who do evil things for no good reason (business or otherwise) whatsoever and then quickly cover their tracks only when called out, "oops" is the only explanation that passes the sniff test. Here's what someone from Bitwarden said in that issue: https://github.com/bitwarden/clients/issues/11611#issuecomment-2436287977 https://github.com/bitwarden/clients/issues/11611#issuecomme... I think the submission should be rephrased as "Bitwarden SDK fixed license of sub-component" or something. Which of course sounds less bold and interesting and newsworthy because it really isn't.
- Always42 2y agoI have been using bitwarden for some time, and actually pay for it because i like it so much. should i switch?
- nocoder 2y agoWhat would be a good way to backup the passwords stored in Bitwarden? I am worried that someday suddenly bitwarden could stop working and I will lose access to all the stored passwords? Should I have a physical copy of all the passwords stored in a vault at home?
- s2l 2y agoDesktop: keepass variants. Android: Keepass2 android. Use syncthing to stay in sync.
- cja 2y agoHow to use Syncthing on Android now that the app has gone?
- TheFreim 2y agoThere is a fork: https://github.com/Catfriend1/syncthing-android https://github.com/Catfriend1/syncthing-android
- s2l 2y agoFor this type of data, preference could be toward fully open source stack (i.e. fdroid, etc). Another thing I recommend is to enable versioning on syncthing for the database. This way accidental changes can be reverted easily.
- nichos 2y agoExport your BE vault and import it into key pass. Then store that file somewhere safe.
- fy20 2y agoIf you have some sort of home server, I'd recommend hosting vaultwarden (an open-source implementation of the BitWarden server). It works fine with the official apps. Their enterprise model requires a standard API, so it's not going to break anytime soon.
- RyeCombinator 2y agoCan somebody ELI5?
- wmf 2y agoAFAIK they went closed source the other day which triggered backlash and now they're opening back up.
- jth1 2y agoMy understanding is they were never closed source. Some of their code is GPL and some is proprietary, but all is source-available on GitHub. There was a bug where you couldn't build their client without a proprietary dependency, but they have fixed that so you can now build their client with only GPL code again.
- palata 2y agoI don't think it was a bug. They dismissed it and clearly said that they had no intention to adjust the license: https://github.com/bitwarden/sdk/issues/898 https://github.com/bitwarden/sdk/issues/898.
- renewiltord 2y agoTo be honest, it looks like he just had an internal model of “internal code no gpl”, “external code gpl” and mindlessly answered based on that. The fact that it made the latter impossible seems to have been successfully impressed on him. Overall, I’ll stay a Bitwarden customer. People fuck up and I’m a tit-for-tat-with-random-forgiveness tactic user, not grim-trigger.
- palata 2y agoI could accept that he doesn't understand how open source licenses work, or doesn't care, and that it was not meant as a shady move. But still I wouldn't call it a bug, and it does not inspire confidence. Still it's not LastPass-bad. This said, I still recommend Bitwarden to my family. I moved to pass (https://www.passwordstore.org/ https://www.passwordstore.org/) a while ago just because it corresponds better to my needs and I have more control.
- aussieguy1234 2y agoI started using BitWarden as my main password manager after the LastPass security breaches.
- powersnail 2y agoIt's a welcome change. It still feels like they are trying to be too smart on licensing, especially how to combine GPL and proprietary licensed code, which I think is the root cause of the whole drama. The open core model works better as a hosted service, where you are not distributing the amalgamation of GPL and proprietary. Open core in client code seems a bit too rife for potential misunderstandings and confusions. Hope it works out for them, though. It's a good product.
- amszmidt 2y agoNot entirely there yet ... Some parts of have been re-licensed, some have been licensed under the old non-free software SDK license. E.g, https://github.com/bitwarden/sdk-internal/commit/db648d7ea85878e9cce03283694d01d878481f6b#diff-0ca981bc602631e2973c89ed8b66861de8fbf1ff42a62d3424cc49af711cc6afR55 https://github.com/bitwarden/sdk-internal/commit/db648d7ea85...
- ferbivore 2y agoThe non-GPLv3 bits are for their separate Secrets Manager product. It doesn't look like that's advertised as open-source. Bitwarden has always been open-core and not fully GPLv3, and that seems understandable; they need something to sell after all.
- rochak 2y agoNo good thing ever lasts, especially in the world of tech. So, I'll be sticking with Bitwarden until they somehow eventually fuck it up and something else takes its place.
- crossroadsguy 2y agoWhat will be ideal is a FOSS competitor. At least in personal usage segment until. Until they also start looking at big money and enterprise/professional (which is fine), then another competitor will come in. As long as the chain of export-import-export doesn’t break.
- mbix77 2y agoSuch a pity they are starting to try to move to proprietary model. I have been using them for years. I thought they were different than other "open-source" companies (e.g. Redis). What are the alternatives for an open-source cross-platform password manager? Anybody has used Vaultwarden already?
- tmpfs 2y agoWe have been working on a open-source, cross-platform alternative called SOS[1]. The source code is on github[2] and includes a self-hostable server for syncing. It is well documented[3] for those that want go build on top of it. Would love your feedback if you can take it for a spin! [1] https://saveoursecrets.com/ https://saveoursecrets.com/ [2] https://github.com/saveoursecrets/sdk https://github.com/saveoursecrets/sdk [3] https://docs.rs/sos-sdk/latest/sos_sdk/ https://docs.rs/sos-sdk/latest/sos_sdk/
- chx 2y agoNo, they are not. They have a separate product which is closed source and there was a accidental mixup between the dependencies of the two. They fixed it quick. As I posted repeatedly in this issue: we need to be much much more lenient and supportive of one of the very few companies which still try. If this is the support they get why would anyone else even bother?
- ferbivore 2y agoThis was not an accidental mixup. Have you actually read the previous issue threads? Their stance was that "there are no plans to adjust the SDK license" before the backlash.
- NicuCalcea 2y agoI've been using KeePass (mostly through third-party clients) for years and never saw a reason to switch to anything else. It doesn't sync between devices by default, but I see that as an advantage, you can use a cloud provider like Dropbox, your own server, FTP, Syncthing, whatever you're comfortable with.
- jay999 2y ago[flagged]
- itfossil 2y agoNice to see Bitwarden make a course correction here. I wasn't looking forward to switching to another password manager, so I'm quite happy.
- ryukafalz 2y agoYeah, likewise. I'm a Bitwarden subscriber but I'd been looking into alternatives recently because of the licensing kerfuffle. But switching password managers is a pain, so I'm glad to not feel like I have to now.
- creesch 2y agoAre there other alternatives that are 1) open source 2) offer the same integration to begin with and finally 3) have been audited or are popular enough to be under constant scrutiny? There is of course the KeePass ecosystem, but that is why I included my second point, as with KeePass you are responsible for vault syncing, having clients for all platforms, etc. I suppose that it is good to be aware of other options. At the same time, jumping ship so easily also doesn't seem realistic or ideal behavior to me.
- Glazui 2y agoI‘ve recently learned about PassBolt, but it doesn’t meet criteria 3 I’m afraid
- KPGv2 2y agoThe audited part is going to be tough to meet because it's a very niche skill people generally won't do constantly for free.
- zie 2y agoI have no affiliation, just found them this week, but https://psono.com/ https://psono.com/ exists. So 1 and 2 are met and 3 is half-way there maybe? It's a self-audit but they have been around a while. Apache2 licensed. Again, I literally found them the other day, and other than a cursory check to make sure the UI/UX is friendly enough to compete with BW or 1P, I haven't had a chance to look through their code at all yet. I have no idea if the promises they document are met.
- Beijinger 2y agoI may check it out again. But I love the commercial product enpass.io (I use the free version, don't need it on my cell phone).
- la_fayette 2y agoWe moved to passbolt and we are happy with it.
- AdmiralAsshat 2y agoSo, crisis averted?
- solarkraft 2y agoI’m relieved. Maybe the company would have survived this somehow, but they sure wouldn’t have been the techies’ darling anymore and that was going to be expensive. I hope they realized that being FOSS is their moat and it nets them a lot of goodwill (it’s the whole reason I bother with their not-quite-the-best product in the first place). The bold claim „the most trusted password manager“ was kind of justifiable while it was FOSS (if we don’t count keepass), without it not at all. I’m still not sure how I feel about them now. I can now somewhat trust that the applications will remain free software, but trust in the company has eroded a bit. I still haven’t seen official communication about this.
- whimsicalism 2y agothe gh or had official communication. it was obviously a dep issue blown out of proportion
- apitman 2y agoI'm cautiously optimistic, but still concerned about the long term. * I just don't see how taking $100 million can be good for users in the long run. By far the most likely outcomes are bloat or enshittification. * bitwarden does not appear to be very forkable, ie it's a complex system written in C#. The existence of Vaultwarden helps a lot with this, but what about the client apps? Forkability is the second most important protection against user-hostile action, behind being open source in the first place. I hope it works out. I'm a recent adopter of bitwarden, and so far the UX has blown keepass out of the water.
- _bin_ 2y agoThe client apps can pretty easily be forked and maintained. We probably wouldn't see much feature growth but I also don't think we need that so much. Lots of OSS projects have been messed up by fundraising and communities often just fork them and keep them around so I'm not too worried. Besides, garbage features could probably just be unsupported by Vaultwarden, which has worked extremely well for me and been nothing but stable.
- 2y ago
- reptation 2y agoI looked into Bitwarden but hard to see what it offers over Psono and the pricing is significantly steeper.
- aiono 2y agoGood to see this. Bitwarden is one of the few companies that I actually like. And even them can dissappoint when profitability requires it seems.
- funvill 2y agoAs a exercise I created my own password manager in response to the license issues with BitWarden last week. Its rough, but functional, an exercise not a real product, never expected to be a real product. https://github.com/funvill/FancyGorillaPasswordManager https://github.com/funvill/FancyGorillaPasswordManager The tech is easy. Website, Browser extension, iOS, Android, Windows, Linux, MacOS apps done in less then a day. Gaining trust is hard, who is going to trust a random guy on the internet.
- Thoreandan 2y agoThe summary says "SDK relicensed from proprietary to GPLv3", the linked commit puts the Bitwarden license into LICENSE_SDK.txt, not GPLv3. Am I missing something?
- mananaysiempre 2y agoThe change to package.json of the sdk-internal package indicates it’s now GPL3. This comment might be more illuminating: https://github.com/bitwarden/clients/issues/11611#issuecomment-2436287977 https://github.com/bitwarden/clients/issues/11611#issuecomme...
- imaginebit 2y agodoes it potentially compromise the data security?
- berry_sortoro 2y ago[dead]