11 ms·
The quiet renovation at Bitwarden
- megamike 5mo agowhat are some bitwarden alternatives?
- RockstarSprain 5mo agoProton Pass. Not ideal but actively developing and IMO its UX is way better than what I had with Bitwarden.
- wirybeige 5mo agoPersonal anecdote --- Proton Pass very quickly went from worse than Bitwarden to better with more reliable auto-fill.
- stock_toaster 5mo agoI think once url matching is added (which is now on their roadmap[1]), I'll try making the switch from my current password manager. [1]: https://proton.me/blog/pass-roadmap-spring-summer-2026 https://proton.me/blog/pass-roadmap-spring-summer-2026
- zeroonetwothree 5mo agoDoesn’t it cost much more than BW? I don’t really understand if the main complaint is people worrying about losing the free option (which hasn’t even happened)
- magicalhippo 5mo agoNot sure it makes sense on its own at $5 a month (currently discounted so $3), but as part of the Proton Ultimate package which gives you mail, VPN etc in addition it's not bad in my view. YMMV. Worked well for me, I use it for non-critical web accounts and such. KeePass for the few core accounts etc.
- arbitrarian 5mo agoKeepass or one of its variants are great. Pair it with a shared folder via SyncThing/GDrive/Dropbox/whatever and you'll be set.
- gonzalohm 5mo agoDepends on what you are looking for. I use keepass to store my password + syncthing to sync across devices
- hirvi74 5mo agoI left for Apples Passwords.app and never looked back. Of course, that has its own limitations if you are not bought into Apple's ecosystem.
- dpark 5mo agoApple apparently has an iCloud app for Windows that syncs passwords and provides extensions for major browsers. I had no idea.
- dannyphantom 5mo agoThe Windows app for iCloud Passwords works fairly well, no real complaints about it to share. It can sometimes be a bit clunky and slow, though that's likely related to my environment rather than the app itself. Would love it a ton more if it could offer an experience similar to BitWarden where you can view notes linked to logins or autofill credit card details with a single click from the browser extension. But overall it's really helpful.
- dabber21 5mo agoI went with the classic: KeepassXC + Syncthing All locally synced There are sharing options but they are not really convenient, not a problem for me since I mostly don't share passwords
- hamdingers 5mo agoFor the closest experience, self-host Vaultwarden and keep using the bitwarden clients you're used to. They're GPL-3.0 and aren't going anywhere (and could be forked if there was ever drama). If you want to fully disassociate from bitwarden, there are vaultwarden compatible 3rd party clients. I like Keyguard.
- Brendinooo 5mo agoKinda funny. I helped get passit.io off the ground YEARS ago but we pivoted away from it because Bitwarden more or less ate our lunch. They just moved way faster. Passit still works! Just as a webapp + chrome and FF extensions. I think we had an Android app too, dunno if that's still a thing. Maybe if the best open source option is a less viable option, I should poke at its creator to revive it...
- paulrudy 5mo agoI've been keeping my eye on AliasVault[1]. Open-source, self-hostable or pay for cloud hosting, handles both email aliases and passwords. I'll probably switch for password management once it has a proper security audit, and for email aliases once (if) they implement IMAP/SMTP or similar so reading emails isn't restricted to in-app. [1]: https://www.aliasvault.net/ https://www.aliasvault.net/
- FireInsight 5mo agoTried self-hosting it and importing passwords. UX was very good, but I had some understandable UI hiccoughs that made me not want to use it. The non-native Android app also felt pretty slow.
- dgavrilov 5mo agoPassbolt https://www.passbolt.com/ https://www.passbolt.com/
- throwaway270925 5mo agoNo they aren't. They have a minimum of 10 users on their cloud plans and no offers at all for individuals, except self hosting - and you can just use vaultwarden at that point anyway...
- cglan 5mo agoI don't think these companies are obligated to run a free tier. Someone has to pay the infra. It's a little shady that they didn't announce any of this though. But bitwarden is open source and you can host it all yourself
- flossly 5mo agoI use BitWarden because I'd never trust a password manager with close source clients. Before BitWarden I used a local manager: BitWarden made my life easier. The web interface I'd never use: I have no guarantee that my passphrase does not leave my computer. Same for the import feature: this also requires the passphrase to be sent to their servers. Needless to say I move to the next ethical e2ee password manager if BitWarden turns it's back on open source.
- deanc 5mo agoI don't see the problem here. It's a great product and if they want to make money then I don't mind. If it's too expensive, and they hike the price to something ridiculous then I'll vote with my wallet.
- mschuster91 5mo agoThe problem is the rug-pull. You can't go and proudly state "free forever", and then silently back down on that commitment. That is a textbook example for the enshittification cycle... lure users in with grand promises, sell out once you got enough of a following. (Well, technically, you can, but then don't complain about getting called out)
- craigmart 5mo agothey haven't backed down, you find the "Always free" claim in the very same webpage OP linked https://bitwarden.com/products/personal/#whats-the-difference-between-free-and-premium https://bitwarden.com/products/personal/#whats-the-differenc...
- dpark 5mo agoYou must be getting a different version of that page than me. The free tier is there but there’s no “always free” verbiage. There is “start free” verbiage. Edit: “always free” was hidden under a collapsed section
- darkwater 5mo agoIt's not super big but it is there in the comparison list. Pricing: Always free Ctrl+f for "Always"
- dpark 5mo agoI searched for the word “always”. It was not (and is not; I just checked again) there on the version of the page I was served. Edit: Actually, it is there, hidden from search under the collapsed pricing section.
- evanjrowley 5mo agoLately I've been scrutinizing Bitwarden after discovering a long history of memory leak problems in the GitHub issue tracker. It's an extention I use with all of my browsers. It seems to use an unusually high amount of RAM on Safari and I suspect it's why RAM just never stops growing in MS Edge. Overall it's not a problem for me if Bitwarden wants more money, but I have to draw the line at replacing top leadership with randoms from private equity and secret price hikes. I'm glad this is being highlighted and it's motivating me even more to find suitable FOSS-friendly alternative.
- xweb 5mo agoThank you for this post/link. I have been side eyeing Bitwarden since they started ensh*ttifying the desktop UX last year to make it more like everything else and take up too much space. It had been working perfectly well for browser autofill - super fast and staying out of the way. Now it is bloated white space, slow, standardized UX elements like any SaaS built by AI. Will check out Vaultwarden, Proton Pass, Keepass, I guess. But sadly - yet another tool that worked perfectly well that was ruined in contempt of its own users (LastPass, Authy, Google Reader, etc - the list goes on)
- zeroonetwothree 5mo agoI really don’t think a UI redesign is the intended meaning of enshittification. BW has had by far the best free option for password management since I started using them 8 years ago. Do I like the UI changes? Eh it’s not my favorite but I don’t use it that often to care.
- Refreeze5224 5mo agoAs mentioned, enshittifying doesn't mean "make shitty" or "make worse". It's a specific exploitative company MO, like taking a product like Bitwarden and the goodwill it's generated with open source contributions, free plans, etc., and exploiting that trust by selling it to private equity, unbeknownst to the users, in order to squeeze the most out of it they can and then scrap it.
- avhception 5mo agoI agree with you that "enshittification" has a more specific meaning than just "make worse". Yet, the enshittification of Windows doesn't really follow the mold you described, even though I'd also call it enshittification.
- modriano 5mo agoMSFT is the GOAT of enshittification, and Windows is a pretty fine example of that. The OS literally comes showing you ads by default.
- kwar13 5mo agocurious whether "always free" is only marketing or actually has some legal implications
- gerty 5mo agoNot disputing the overall feeling about the changes at Bitwarden but "Always free" phrase is still actually there if you're creating a personal Free account.
- deleted 5mo ago[deleted]
- notsylver 5mo agoI believe they added it back after people noticed, archive.org has versions where its gone
- accrual 5mo agoYeah, to me this isn't about whether or not it's "always free". It's about the rug pull. "They put some of the rug back!" isn't enough to restore goodwill in my case.
- dlev_pika 5mo agoYeah, I don’t trust their path anymore
- zeroonetwothree 5mo agoWhat did they pull exactly? Nothing has changed about the product except for a small price increase (but free version is still great)
- nodeflare 5mo agoThis feels more like an expectation management problem than a product problem.
- deleted 5mo ago[deleted]
- waysa 5mo agoIt still says "Always free" on the website for me. It's both on the billing page on the page linked in the article. I do share the concerns though. The change in leadership, the poor transparency, 100% price increase and the quiet change in core values. I was happy paying $10 yearly for Bitwarden. I'm still okay with $20 but there's a seed of doubt.
- misswaterfairy 5mo ago> It still says "Always free" on the website for me. It's both on the billing page on the page linked in the article. Just went to the website directly: says "Get Started Free". "Always Free" is only present at the bottom of the pricing page for personal customers. What concerns me more is that they've started using the same language that Adobe had been panned for: "$price a month, billed yearly". To me, thats weird language for a product that (now) costs $20.00 a year. Not hundreds or thousands. Twenty dollars. For non-enterprise users. The lack of transparency and quietly changing things around makes me wary.
- zeroonetwothree 5mo agoThe placement at the bottom of pricing is always where it was. Nothing has changed They did raise the price to $20 (but the free version is still amazing). But that’s still really cheap and pretty much all services have gone up in price in the past 10 years (inflation)
- zeroonetwothree 5mo agoThey mentioned in an update that they accidentally removed “always free” text during a website update and put it back quickly. Seems the article was written in the intervening period
- zug_zug 5mo agofunny, I just changed to bitwarden from 1-password after they had a big price increase (I probably otherwise would have been a lifetime customer if it could have been a leave it and never think about it again for the next 40 years deal). I'm not too worried, if bitwarden changes their price somebody is going to vibecode a decent enough solution for pennies on the dollar, or there's always apples built-in product.
- dpark 5mo agoA password management system is one thing I definitely don’t want vibe coded.
- quantumwoke 5mo agoThis is terrifying, but I couldn't help myself from frustration at the LLM writing that only worsened over the course of the post. Bloggers, it's not subtle. Please, stop, or at least disclose it.
- welder 5mo agoI don't care about raising prices, I'm worried about the new CEO having a PE mindset. That means Bitwarden will now focus on extracting value while the product stagnates and degrades in quality. Time to jump ship before their security and quality goes down the drain.
- adfm 5mo agoPE? Private Equity is the slippery slope to Public Enshitification.
- j16sdiz 5mo ago+1 I am a paid subscriber. I am kind of ok with the price increase. The "coincident" with change of CEO and remove of "always free" tag worries me though.
- jnovek 5mo agoI just sent them a message along these lines. I’m happy to pay for good services, but M&A means cost-cutting measures to make the company look good for acquisition and that makes me uncomfortable with letting them store secure data for me. Switching is going to be a pain.
- bglusman 5mo agoIt is really easy to self-host, and do so securely...
- jnovek 5mo agoI’m not buying hosting from a password manager, I’m buying security. I don’t have complete confidence that I can secure a self-hosted password manager and it’s not an area where I want to take risks.
- xienze 5mo agoIt's very simple, just don't make it accessible outside your home network. Clients sync when the server is accessible and use last synced data otherwise.
- dust-jacket 5mo agoAh damn. I've only recently moved in to Bitwarden - paid - largely on the basis of a multiple-user shared vault and emergency grants to personal vaults. I'd really, really like them to not to ruin it or make it massively more expensive.
- Havoc 5mo agoAfter the LastPass fiasco I switched to selfhosting a password manager (bw). Rapidly starting to think even a vibecoded solution may be a better plan relying on commercial options. High risk of don’t roll your own crypto mistakes but realistically that’s not the threat model here anymore for the random individual. It’s online breaches or perhaps a wrench attack not highly skilled crypto adversary. Plus there are probably ready made crypto modules so wouldn’t be a true handroll
- schnitzelstoat 5mo agoThe LLMs also help a script kiddie become a highly skilled crypto adversary though. Especially if the concerns around Mythos are well founded.
- krupan 5mo agoThe concerns around Mythos are not well founded
- Havoc 5mo agoTrue. No chance of me putting a DIY password manager on the open internet though. Would be behind WireGuard etc
- ptdorf 5mo agoI wouldn't worry. The mythical Mythos can't even find Claude code bugs before releases.
- ViAchKoN 5mo agoI don't think concerns around Mythos are well founded. Highly doubt it will happen.
- LetsGetTechnicl 5mo agoVibecoding a password manager might be the worst idea ever. You'd be better off with an encrypted Excel sheet. But otherwise, 1Password is great imo and there are other free open source password managers.
- RyJones 5mo agoThank you for pushing me to migrate away from Bitwarden. I've used them for years but I was moving away slowly; now I've moved.
- nemomarx 5mo agoOut of interest, where are you moving?
- RyJones 5mo agoApple's passwords app. It's what I use almost everywhere. I use 1password for work but I'd prefer not to mix work and personal life.
- oarsinsync 5mo ago1Password for Business accounts all get an additional 1Password for Families license (5 seats), so you can absolutely keep your work and personal life separate.
- Goofy_Coyote 5mo agoWhat happens when you leave that business account? (e.g. change jobs, leave the company, get acquired and consolidate etc)
- 1123581321 5mo agoYou keep your personal account, but it goes into either a read-only or trial mode until you subscribe or connect another free account source. You can export everything out if you want to switch to a different tool.
- deleted 5mo ago[deleted]
- red369 5mo agoI have been considering this since Apple Passwords implemented a way to export. I've just seen that the iPhone Passwords app has an export to another app you have installed on your phone, but I previously tested the export from Safari method. I realise that this is moving even more of my eggs into Apple's basket, and even further from self-reliance towards convenience, but today it doesn't seem significantly worse to just trust Apple with this, than Bitwarden. But isn't it a pain to use those passwords on any other non-Apple device? Am I missing something, or is that just not an issue for your use-case? Ah! I've just learned/relearned about iCloud Passwords through iCloud for Windows, but nothing for Linux?
- therealfigtree 5mo ago[flagged]
- dewey 5mo agoThe "First time?" meme would be appropriate here. Companies change their policies all the time. Most recent example: https://cal.com/blog/cal-com-goes-closed-source-why https://cal.com/blog/cal-com-goes-closed-source-why
- SV_BubbleTime 5mo ago[flagged]
- brycewray 5mo agoIt has a very “AI-written”-ish feel to it, FWIW.
- faccacta 5mo agoEnshittification is properly viewed as a cybersecurity risk, a category of insider threat. You defend against it, when possible, by using open source software and open, documented file formats. That way, if open source enshittifies, the community can defend by forking. I’m so grateful for KeepassXC.
- kn100 5mo agoGood post. I switched from Bitwarden to KeepassXC / KeepassDX / Syncthing across my Android phone, Linux PC, and Windows PC. This was the setup I had prior to using Bitwarden for the first time. The Keepass experience is significantly better these days! Importing from Bitwarden is trivial too. Recommended!
- kennywinker 5mo agoWhich variant of keepass tho?
- flanbiscuit 5mo agoI was using this but when I switched to iOS I switched to Bitwarden. What are you using for Syncthing on Android? There used to be an official Syncthing app for Android but then they stopped maintaining it. There was a popular fork but then that person stopped as well. I looked into using Syncthing on iOS but there was only Möbius Sync and it didn’t run in the background. This is was made me finally switch to Bitwarden. But of course now I need figure what to do next.
- Keeblo 5mo agoI have had an excellent experience with Sushitrain/Synctrain on iOS [0]. It’s honestly the nicest Syncthing client I’ve used, although to be fair desktop-oriented clients have different design goals than mobile clientsm [0] https://github.com/pixelspark/sushitrain https://github.com/pixelspark/sushitrain
- kreyenborgi 5mo agoI use syncthing-fork from fdroid, works great
- IG_Semmelweiss 5mo agosame. Recommend as long as the house doesn't catch fire, or as long i run outside with 1 of my syncthing devices (have several), local cloud is the best.
- antran22 5mo agoWhen I first learnt about Bitwarden about 3 years ago, I started hosting Vaultwarden right away. Right now I have one instance for myself and another for my friend's company. Everything runs as smooth as butter. If you can self-host something, do self-host a Vaultwarden instance. If you are (like me) somewhat paranoid about the fact that Vaultwarden hasn't got a proper security audit on its codebase, just run it behind a VPN, it will probably be fine. I'm not particularly worried about Bitwarden going belly up because it has already have such a well-established open-source replacement. The worst-case scenario is that Bitwarden make the clients incompatible with Vaultwarden, and like how OP already mentioned in the post, somebody in the community will fork them as soon as this happen.
- buggeryorkshire 5mo ago[flagged]
- mctt 5mo agoForm the article; "The real safety net is that Bitwarden’s clients are Apache 2.0 licensed."
- yegle 5mo agohttps://github.com/bitwarden/android https://github.com/bitwarden/android
- zeroonetwothree 5mo agoI don’t understand why people post incorrect statements that are trivial to check
- renegade-otter 5mo agoI am very happy self-hosting Vaultwarden. I got really tired of being a refugee of one password manager or the next. Either the price goes up, or the service goes away. I am looking at YOU - Dropbox.
- jerf 5mo agoI'm running Vaultwarden because while on the one hand I'd like to just pay a company to make my password problem go away, I don't know who I can actually trust to not try to take advantage of the fact they have all the keys to all my kingdoms at some point. I see some people complaining about "Private Equity", with justification, and before that it was the "Harvard MBA" mindset, where businesses are encouraged to think of their customers as a resource to be stripmined rather than relationships to cultivate. I don't like being considered a resource to be stripmined by any company, but some are worse than others by the nature of our relationship. I do not need a company greedily looking at my bank password, my Google password, my brokerage account password, and even having them be tempted to look at my set of passwords with them and start valuating which password they can "intermediate" and charge me more for using. I don't even want them pondering the question of how they can break exports ("oops, sorry, passkeys can't be exported because $SECURITY_BLATHER, guess you won't be migrating" - to be fair, while I think Bitwarden had that for a bit I believe it's no longer true, but AFAIK it is true of other things that will hold passkeys for you) so that they can extract the value of my passwords to me. I don't trust Private Equity or the Harvard MBA mindset to be allowed to hold on to my passwords. I don't trust any company holding passwords to not eventually be acquired by PE/HMBA types looking to stripmine my passwords. I don't trust any company that is, once you trace the entire value chain down, basically taking out real debt with my passwords as collateral. They get the money, I get the risk. Hard pass. So I'm not happy about self-hosting my password vault in some sense... but who else can I trust?
- kennywinker 5mo agoIt seems like it’s probably time for a bitwarden client alternative. I’m already running vaultwarden, it’d be nice to have a community-run client. The bitwarden client apps are so mid already - it seems like it couldn’t be that hard to out do them.
- lxgr 5mo agoI'd definitely give a Bitwarden client alternative a try, but I really hope this isn't the start of client fragmentation like it happened for Keepass, especially given that a server is involved here.
- mk12 5mo ago[flagged]
- colordrops 5mo agoCan someone just fork BitWarden into another open source project already? Maybe MorselGuardian lol
- 0x262d 5mo agoI just read the linked Fast Company article [0]. One question that particularly frustrates me about this process is: why are the former leadership of companies that become enshittified so quiet about it? Do they just get paid out with restrictive NDAs? One of the only exceptions to this I can remember is the founder of Whatsapp, who gave an interview pretty critical of Meta some years back after it acquired Whatsapp. [0] https://www.fastcompany.com/91542655/bitwarden-scrubs-always-free-and-inclusion-values-from-its-website-as-longtime-execs-step-down https://www.fastcompany.com/91542655/bitwarden-scrubs-always...
- aturek 5mo ago> Do they just get paid out with restrictive NDAs? Yes, that's a very common part of an exit package for executives. Speaking from some first- and second-hand experience, you can get paid a hefty sum (6-12mo of salary worth of cash) for signing an agreement that has some amount of limits on what you can say, to whom. There's also some kind of what I think of as a LinkedIn effect - there's a disincentive to talk trash about any organization publicly, since that's now attached to your name and might make future employers/organizations leery of hiring someone who might air their dirty laundry.
- jrm4 5mo agoPassword protection by a for-profit (where the password protection is the product that you can't have unless you pay for it) is a fundamentally stupid and dangerous business model. Waiting for everyone to understand this.
- varbhat 5mo agoI have moved to KeepassXC[1] on my desktop from Bitwarden. On phone, I use KeepassDX[2] which is Android client compatible with KeepassXC. On browser, I use KeepassXC Browser extension which connects with the desktop client. Since KeepassXC operates on a single file, you can use any Filesystem syncing tool to sync that file between devices or to store it in the cloud. I am really happy with the move. [1]: https://keepassxc.org https://keepassxc.org [2]: https://www.keepassdx.com https://www.keepassdx.com
- plutokras 5mo agoThis is my exact plan too, if I ever have to leave the Apple ecosystem.
- Suffocate5100 5mo agoKeePassXC is cross-platform FYI
- dangus 5mo agoKeePass is such a backwards step in usability and features that I don’t even consider it a competitor. The whole reason I moved to 1Password was to get away from how easy it was to accidentally lose data with the KeePass clients. For example, one client I used had a temporary bug that just lost the notes field entirely. It was quickly fixed but it still affected me. I’m currently using 1Password, which I still think is the best product overall as I’ve tried just about all the rest. For this product category I’m happy to pay the highest price to get the best product.
- deleted 5mo ago[deleted]
- baal80spam 5mo agoYou are right that 1Password is probably the best overall product in this space. It's non-free though, which for me is a deal breaker.
- 5mo ago
- dd8601fn 5mo agoIt does seem like most password managers have no moat for import/export, so I’m kinda banking on the idea that I can quickly migrate to Proton Pass or vaultwarden if things get ugly. I just don’t want to self-host if I can avoid it. Staying on top of managing the application and the environment is a whole different level of diligence when the thing I’m self hosting is the keys to my life. At a minimum it would have to be behind something like a wireguard tunnel to a trusted machine, and that’s an added headache for daily use.
- nine_k 5mo agoDoes Proton Pass use a wireguard tunnel? Or does Bitwarden? TLS should suffice. Yes, you want to guard the machine that hosts your passwords. You can even physically keep it at home, and only proxy its port 443 wherever you have a presence in the public Internet.
- dd8601fn 5mo agoThose at least have people whose literal jobs are to protect that stuff. The service, the clients, the transport, the environments, etc. That’s what I don’t have if I self host. That’s not to say anything is bulletproof… nothing useful is… just that I don’t entirely trust myself to be 100% on top of something like that as a hobby hosting endeavor.
- fridder 5mo agoI started looking for a replacement when I noticed how much RAM the extension was using. >1GB for a password manager seems ridiculous. I'm currently debating between Keepassium and Strongbox but I wonder if there is something better.
- havaloc 5mo agoStrongbox already got bought out, but it's still very good and you can store the file wherever you want.
- borborigmus 5mo agoI just set up Strongbox on MacOS and iOS. Both re pointing to the same file using SFTP (using key based auth). I’ve also got an additional key file on each client which isn’t on the SSH server. It’s working pretty nicely. Bye bye Bitwarden.
- jillesvangurp 5mo agoI got my parents using bitwarden a few years ago. This was a massive improvement over them writing passwords in a little notebook in a drawer (yes, really!). But Keepass is a bridge too far for them. I'm not that enthusiastic about it myself to be honest. The UX is a bit meh (for the clients/extensions I've tried) and file syncing and handling is not something I can in good conscience push to a non technical user. It's just too many moving parts and you just have to do this, that, and the other thing. It's not really fit for purpose with normal users as far as I can see. Like much OSS stuff, UX for normal people seems to be a bit of an afterthought with Keepass. The key selling point of Bitwarden was that it is free-ish and it is easy enough to work with for somebody that is not too technical. My father is an Android user and my mother has an iphone and ipad. They need access to each other's passwords so they share the same password manager. They are both in their seventies and I need something that is similarly useful and ideally without me self hosting a lot of stuff on their behalf. I don't want to be their system administrator. And I don't want to have to sit them down to migrate their passwords every few years either. Right now the best move to me seems to be to stick with Bitwarden. I don't really gain anything from moving them over to some other solution and there isn't really anything out there that is materially better as far as I can see.
- jp191919 5mo agoI switched from KeepassXC and KeepassDX to Vaultwarden, primarily to make it easier to get family members to transition to using password managers.
- vitally3643 5mo agoPasswords in a notebook are arguably the most secure option. The notebook exists in exactly one place, behind locked doors, and cannot be leaked or hacked externally. Notionally a password manager is more secure, but is there anything stopping Bitwarden from updating the app to silently send your master password up to the mothership and selling your unencrypted vault? Even supposing they stay open source and get caught, they will still have thousands of user's data ready to sell before the rug is pulled and the game collapses. (And besides, where do you keep your recovery codes? If some cabinet or drawer in your house is safe enough for that, it's safe enough for your book of passwords.)
- grim_io 5mo agoI am tired of this bullshit. Want to raise the price? Fine, be honest about it and make sure it stays sustainably stable for a long while. I am not leaving because of the price, but because of the dishonest behaviour around something so central and vital to my daily life.
- jeromechoo 5mo agoEven if the clients go closed source and forked, there's still the very serious issue of closed app ecosystems on iOS and Android. It's one thing to self-host a Vaultwarden instance, it's another entirely to pay Google and Apple $100 a year to publish your own app.
- bergheim 5mo ago> That’s not a software guy who happened to raise some money. That’s someone whose stated specialty is the PE integration and exit process. Holy smokes has that's not just -> THAT IS become one of my trigger words.
- ffsm8 5mo agoIt's almost certainly ai written though. All the regular tells are there... Though he likely edited some out, like that "just" Also if it was handwritten, it'd have been a third in length, the rest was LLM fluff
- bergheim 5mo agoCorrect, that was my point
- ffsm8 5mo agoI see, i actually like these tells. It let's us easily distinguish garbage from someones thoughts. And you can also see how brainrotten someone's gotten when they start accidentally sneaking in these tells into their normal communication. As a matter of fact, after a full workday in which I'm essentially forced to read LLM garbage for 9h a day... I sadly notice myself adding the same fluff pointlessness to how I express myself. like I caught a viral contagion that's actively siphoning my humanity away. And expectedly, when coming back to those opinions with a less infected mindset, I frequently have to reevaluate these thoughts later on
- danparsonson 5mo agoDo we need to keep pointing this out though? LLMs are not going anywhere any time soon and people will keep using them to generate articles. If the content is also nonsense then that's worth talking about, but otherwise comments about LLM style are about as interesting as remarks about typos.
- HomeDeLaPot 5mo ago
- yoyohello13 5mo agoWhat a shame. I've been a paying Bitwarden customer since 2018. I really don't have time to move off yet, but I'll need to keep an eye out for where to jump. It sucks that this seems to just be the logical conclusion of all great projects.
- zeroonetwothree 5mo agoLiterally nothing has been taken away from BW yet, it’s all just speculative for now
- grougnax 5mo agoWe all know where it's going
- gverrilla 5mo agoYes, speculative, for sure. In the same way if I hold a rock in my hand and let it go, it's speculative that it will fall to the ground.
- yoyohello13 5mo agoBetter to look for exit strategies before the need arises.
- Balvarez 5mo agoOmg, do we really need to make another app suck? I left last pass years ago, I'll leave again but wow I'm tired of this cycle. Private equity is truly the destroyer of value. The next time will be self hosted. Anyone know of a password manager that can encrypte and live in say Google drive?
- lillesvin 5mo ago> Anyone know of a password manager that can encrypte and live in say Google drive? Can't most of the many KeePass variants do that?
- worksonmine 5mo agoHow portable do you need it to be? I use pass[1] and it is good. Just a shell script wrapper to gpg and the passwords are encrypted files you can backup and sync anyway you want. [1]: https://www.passwordstore.org/ https://www.passwordstore.org/
- aorth 5mo agoAnother vote for pass. I've been using it for ten years with a git repository. I sync to all my machines and use https://github.com/agrahn/Android-Password-Store https://github.com/agrahn/Android-Password-Store on Android. Not a solution for non-technical people though...
- RyeCombinator 5mo agoDupe https://news.ycombinator.com/item?id=48157588 https://news.ycombinator.com/item?id=48157588
- cwoolfe 5mo agoThe Bitwarden chrome extension just randomly stopped working for me the other day. This is after years of working flawlessly. I had to remove the extension and add it back to get it working...What a shame. Hosting a password manager isn't a game; these are people's real lives and businesses at stake.
- tskj 5mo agoI've had similar issues, it's ridiculous!
- jiveturkey 5mo agoAh! Curse your sudden but inevitable betrayal!
- grougnax 5mo agoThis is terrible news. Jump off the ship while it's still possible!
- ltr_ 5mo agois there an enshittification watch site? or something to track acquisition and red flags in products/oss projects? itsenshittifiedyet.info if not, what would it take to do that? i think it can be vibed in a weekend. edit: s/of/and
- websap 5mo agoHow hard is it to fully migrate from Bitwarden to Apple Passwords / Google Passwords? I guess I'm going to have to spend 2 hours on this next weekend.
- studentdriver 5mo agoWonder if Sullivan is the same Sullivan involved in the Autonomy lawsuit
- kmoser 5mo agoIANAL but if a company advertises "always free" and then starts charging, how is that not either false advertising and/or a breach of contract?
- sircastor 5mo agoIt’s a “always a free option” which doesn’t clarify what you get with the free version. IIRC LastPass did this by slowly reducing how many devices and what kinds you could sync. They made the free option increasingly painful.
- j-bos 5mo agoIAANAL, but always free sounds like it could fall under puffery: https://uslawexplained.com/puffery https://uslawexplained.com/puffery
- baggachipz 5mo agoSay what you will, but the Apple ecosystem's Passwords app and integration works great. It locks me into their services (iCloud), but I don't see them ever charging for it or sunsetting it. (watch me eat my words in the near future)
- moepstar 5mo agoPassword App surely is a good alternative, however i don’t think there are clients for Linux or Windows? …and that is where Bit/Vaultwarden comes into play.
- baggachipz 5mo agoThat's correct; I only use MacOS and iOS.
- ZekeSulastin 5mo agoI can't speak for Linux, but it's now part of their iCloud for Windows suite with browser access via extension[1]. Exporting from Bitwarden to Passwords (on an iPhone at least) is (as of this post) a simple Export Vault operation, but non-passwords/passkeys are not supported. 1: https://support.apple.com/guide/icloud-windows/set-up-icloud-passwords-icw2babf5e03/icloud https://support.apple.com/guide/icloud-windows/set-up-icloud...
- Postosuchus 5mo agoGoogle's is even better, as it is cross-platform (although same caveat of having even more dependency on your account is still true). Plus (not sure about Apple) but Google also does (portable) passkeys and OTP.
- baggachipz 5mo agoApple does portable passkeys and OTP as well. I know you're going to laugh at me since I'm using Apple, but I don't trust Google with anything. Apple at least pretends to care about keeping my information in-house.
- bodge5000 5mo agoI could quite easily ignore all this in the interest of not going through the pain of finding yet another password manager, but having your new CEO specialise in M&A is really hard to ignore.
- karel-3d 5mo agoCrap. I just switched to Bitwarden as it was the only password manager that Just Worked and didn't seem scammy. Oh well
- carabiner 5mo agoWe've got to remove "quiet" as GPTism. It's a renovation. That's it.
- kjuulh 5mo agoAt this point it is too high of a risk to store my password elsewhere. I've been screwed over by dashlane, lastpass, potentially bitwarden now, I am with 1password now, but I've had my passwords in all these places, and I've had to change them each time, probably missing a few. I like 1password, it is by far the highest quality product I've used in this category. I moved from BitWarden back then because their browser integration was quite poor. I think I'll move to something custom, or a selfhosted keepass server, with the rugpulls, incidents, and whatnot, it is becoming too high of a risk.
- dpacmittal 5mo agoFor the same reasons, I imported all my passwords to Firefox and I'm satisfied with it. I have the option to self host if I don't trust Mozilla
- _karie_ 5mo agoAny malware or LLM with user-level filesystem access can attack the outdated KDF [1] and/or wait for Firefox to be running with an unlocked credential store and read the decrypted passwords from Firefox's process memory. [1] https://bugzilla.mozilla.org/show_bug.cgi?id=973759 https://bugzilla.mozilla.org/show_bug.cgi?id=973759
- ozten 5mo agoHow were you screwed over by these products?
- holysoles 5mo agoWhile I agree with the concerns raised in this article, I did not enjoy the writing style of it. Almost all of it feels AI generated, and is written in a very combative tone.
- HomeDeLaPot 5mo agoYou start reading. Then it hits you. The short, choppy sentences. The stock phrases. This wasn't written by a human — this was generated by AI.
- cheriot 5mo agoWild to me that Bitwarden raised > $100m from VC. Seems like the kind of thing that would make a nice lifestyle business. The enterprise version never went beyond password management so I'm not sure how this could have generated a viable ROI.
- DANmode 5mo ago> Seems like the kind of thing that would make a nice lifestyle business. Don’t see too much of this talk around the comments, anymore! If you’re seeing this comment: Are lifestyle businesses on your radar? Please do share.
- rafterydj 5mo agoMaybe this is me being a little wet behind the ears, but I don't know if lifestyle businesses are really possible to start at the moment, given the uncertainty of the current software sector. See this thread from a few days ago: https://news.ycombinator.com/item?id=48118727 https://news.ycombinator.com/item?id=48118727 The economics of software creation is changing, so it stands to reason how people engage with software will change too. Finding a niche may be a game of luck more than observation/perspiration at this stage, similar to discovering oil on your "barren" property rather than building a farm. As someone who's generally independent, though: I'd love to be wrong here!
- DANmode 5mo agoI’m betting the farm that you are =] Your accountant will be configuring their own work software. Your project manager will be developing their own work software. Custodians will not necessarily be developing work software. Most non-tech desk-staff start to lose focus after the fifth reply on a social media thread… I do not believe they’re going to be able to perform the three required steps for building software solutions: 1. Know what you need (vs want). 2. Know how to ask for it. 3. Have a process for validating it. I also don’t think it gets too much simpler than Docker et al for self-hosting, yet those concepts are genuinely a foreign language to even “tech-savvy” consumers. I think we’re in a bubble, here, and I am personally betting on one niche (of many) where value ($$$$) is still placed upon having another team to outsource responsibility to. Responsibility for keeping an important tool up-to-date, keeping it able to capture data, and most importantly: rigorously tested to ensure it’ll perform calculations correctly. Responsibility for peak tooling, so a busy end-user can stay responsible for their craft without taking a sabbatical to build software is not going anywhere. Whether these “peak tools” will be (validated, packaged, delivered to the user, maintained) by me, or OpenAI/Anthropic instant-agents in 10 years, is what I believe we should be watching.
- nout 5mo agoThis will probably finally push me to migrate away from Bitwarden. Somehow over the years the UI was getting worse and worse too. It's more steps to add custom hidden fields than it used to, etc.
- DANmode 5mo agoI started getting banner ads for them, as well.
- class3shock 5mo agoFor people looking for an alternative, Proton Pass is one, Keepass + Syncthing is another.
- aussieguy1234 5mo agoIf the price ever became unresaonable i'd host my own VaultWarden instance. I'm sure if BitWarden ever went closed source, it would be forked and maintained by the community and that most would migrate to the open source solution. BitWarden being open source and auditable is one of the main reasons I use it, no hidden backdoors from them or three letter government agencies.
- mmonaghan 5mo agoTried everything and love 1pass. Dont want to have to think about it too much. I think this is tentatively good for bitwarden - making money means you can more easily invest in the team and product. Counter to the prevailing notion in comments here, I much prefer a vc/paid product for security-critical tools. Hope they didn't wait too long before deciding to kill the free tier.
- glub103011 5mo ago[dead]
- asmodeuslucifer 5mo agoI believed Steve Gibson about lastpass, then about bitwarden.
- tamimio 5mo agoBesides vaultwarden, I have been testing both AliasVault and peerpass, there’s also passbolt for self hosting. That being said, keep a copy of your vault in keepassXC, and better, don’t put your eggs in one basket so 2FA in keepassXC and passwords in one of the above.
- inquirerGeneral 5mo ago[dead]
- Centigonal 5mo agoThankful for people like the author who surveil tech companies that take this well-worn path toward greater monetization
- cawksuwcka 5mo ago[dead]
- reassess_blind 5mo ago"The phrase “Always free” disappeared from the personal password manager page in mid-April." It's still on the pricing page, albeit not as prominently. "Just getting started? Get basic password management today. Always free."
- TheCapeGreek 5mo agoThere is one underrated feature that I switched to Bitwarden for, away from KeePass: the emergency contact access. You can designate contacts that can request access to your account. If you don't deny the request within a time frame, they are granted access. So much of our lives is now digital. Important accounts of all kinds, banking, etc. Waiting on several giant corps to grant your loved ones access after they go through the bureaucratic hole of documentation is... rough. Putting my master password in my will feels the same as just writing it on a note on my desk. Putting it in a note in a safety deposit box is high effort and cost. Anyone got a better alternative way to set this up if self-hosting and not going with Vaultwarden?
- borborigmus 5mo agoThere seems to be a gap in the market for a Vaultwarden compatible iOS client, if this is the start of enshitification. I’ve self-hosted Vaultwarden in the past and I’m planning to do it again. The lack of an iOS client is the only thing making me explore alternative solutions altogether.
- porshia 5mo agoWell that explains a lot, saw their stall at a conference a few weeks ago. And was intrigued as I always thought they were purely FOSS software. I just self-host it...
- Cyan488 5mo ago> A 2022 blog post by Crandell — “Defining and sustaining value for Bitwarden users” — was quietly edited. The GRIT list in the body now shows the new values: Innovation and Trust. You can assume incompetence for some things ("gosh I really didn't know I should communicate organizational changes more clearly!"), but re-writing history is a deliberate and conscious act of deception.
- cryptos 5mo agoPassbolt https://www.passbolt.com/ https://www.passbolt.com/ might be an interesting alternative. The feature set looks pretty good at first sight. The only real downside I see so far is that it doesn't have macOS and Linux apps. Other than Bitwarden it is real open source.
- throwaway270925 5mo agoDoesnt have individual plans, you can only selfhost it unless you subscribe for at least 10 users or more - makes it basically useless as a personal bitwarden alternative unfortunately.