Bitwarden Dual License Model

(community.bitwarden.com)

120 points | by Cider9986 1 hour ago

20 comments

  • dannyw 1 hour ago
    I actually find this somewhat understandable; and I'll be continuing my subscription; as long as all source continues to be available and personal self-hosting remains a viable option.

    Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.

    Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.

    It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.

    I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.

    • selectodude 26 minutes ago
      The thing I always think about is that they wouldn't have to change the license and tighten the screws if people paid for it. Getting mad that the free hosted password manager has changed the deal a little bit I find to be quite arrogant.

      Pay the $20/yr or whatever to have them host it and the whole world keeps turning.

      • lstodd 12 minutes ago
        Hosted password manager is equivalent to publishing all your passwords outright.

        Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all.

        • techjamie 3 minutes ago
          People are going to try much harder to break into the main Bitwarden servers than they are my little Vaultwarden instance. Plus, I have the ability to lock it behind a VPN so it isn't even publicly exposed.

          But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.

          I'm not sure where your sentiment comes from here.

        • selectodude 10 minutes ago
          I mean, no it's absolutely nothing like "publishing all your passwords outright" but fine. Pay the $20/yr and don't have them host it, host it yourself. Just pay them the $20.
        • willmadden 7 minutes ago
          Do you have a quantum computer from the future and a file of passwords that haven't been changed in 50 years? Complete nonsense.
    • trentor 25 minutes ago
      I would be with you if they didn't change the owner to private equity in the last year.
    • solarkraft 1 hour ago
      I’m conflicted. On one hand I’m grateful for the years of trustworthy (and pay-what-you-want) password management. On the other this feels like an attempt to EEE the free version.
      • freedomben 1 hour ago
        That's my concern as well. I have no problem with the current license change if they continue to publish all the code as they claim. My concern is that this is usually step 1 in a boil-the-frog strategy to eventually split and break off enterprise features. I'll give them some trust until they give me a reason not to (I think they've earned it), but the concern remains.
        • 4ndrewl 1 hour ago
          They don't?

          "Some future components will be published under the commercial license and will exist only in that build."

          (From that thread)

    • merb 52 minutes ago
      Sorry but the elasticsearch thing was a big stupid take of elastic. It was big corpo against big corpo not the poor elastic company.

      Changing licenses is a sick move and companies doing that should be fucked over, because the license made them big. Changing it later on means that they got greedy nothing more nothing less.

      Without oss bitwarden would be a paid cloud like all the others that probably would’ve had a hard time getting trusted.

      • mcfedr 23 minutes ago
        elastics cloud offering was awful
    • amber71de 30 minutes ago
      [flagged]
  • rsyring 40 minutes ago
    Very insightful blog post listed by another user as a sub-comment. Worth posting as a top-level comment:

    https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden

    Previously discussed: https://news.ycombinator.com/item?id=48163389

    • Aardwolf 23 minutes ago
      Ok this is doing some damage. What's a possible alternative that works on both mobile and desktop, doesn't require yourself to run a server, and doesn't have worse reputation?
      • Lapel2742 7 minutes ago
        Proton Pass?

        I already have "Proton Unlimited" as a subscription but until now I never used Proton Pass. I thought about giving up on Bitwarden for some time and probably will try it now. AFAIK you can even import your Bitwarden logins.

      • terminalbraid 16 minutes ago
        keepassxc works across any major platform, mobile platforms have keepass2android and KeePassium. You don't have to run your own server, but you do need some type of file sharing system to keep them synced. I personally run a webdav share on a vps with some sync scripts to keep a backup on devices otherwise. OneDrive, google drive, dropbox, and others work.

        Also protonpass.

        • GordonS 2 minutes ago
          Any good reason to use keepassxc rather than regular KeePass?
      • orta 19 minutes ago
        I like Enpass
    • nugget 32 minutes ago
      Great find. This blog post - and specifically the background of the new management team - convinced me to start looking for a Bitwarden alternative. I’m watching the same “boil the frog” strategy unfold at Namecheap, and erode much of the brand trust they had built up over a decade, and it’s a shame.
    • Cort3z 7 minutes ago
      I hate this. So much software I love keeps doing this. redis, docker, now bitwarden. I was so happy with bitwarden. Been a premium subscriber for many years. I have helped convert many people, including whole companies, to use this. Now they are doing us such a disservice. We need a completely free, no-nonsence, alternative. I wonder if it is possible to do a ipfs/torrent version without a central authority to permanently prevent this type of issue.
    • alt227 15 minutes ago
      I feel like this blog post deserves its own submission to HN
    • dizhn 24 minutes ago
      Started humany but degraded into LLM speak towards the end. Especial the Vaultwarden section.
      • stavros 4 minutes ago
        It's all LLMese, start to finish. I found it hard to get through. Could have just been a bulleted list and it would have been better.
      • alt227 6 minutes ago
        So? It was useful information, who cares how it was written.
    • Wowfunhappy 27 minutes ago
      [dead]
  • arjie 50 minutes ago
    Okay, it’s good they have the open source because if you rewrite the Chrome extension you can get it to load in under 100 ms after you click the button. If you use the standard Chrome extension you’re not having that happen on an M1 Max. Their stuff is far too heavy. Full JS framework to display a small box.
    • Ecco 26 minutes ago
      Any more details on this? Like did anyone build a better extension or are you just guessing?
      • lloydatkinson 25 minutes ago
        I’d be interested in hearing about this too.
  • 0l 53 minutes ago
    IMO Bitwarden really isn't that well engineered software, and I now use Keyguard on Android/Vaultwarden server instead. Reminds me of Subsonic, with many competing clients/servers. Hopefully someone will write a third party browser extension as the current one is quite slow/buggy.
  • figmert 1 hour ago
    This was always inevitable when they took funding.
  • solarkraft 1 hour ago
    I’m willing to commit money to a project committed to release free builds without these shenanigans.
    • Cider9986 53 minutes ago
      Bitwarden is still releasing free builds but yeah you'd need a new project with a new name to use it from the Play Store or App Store.

      Turns out Keyguard, an alternative Bitwarden client is already on the Play Store.

      https://github.com/AChep/keyguard-app

      • alt227 13 minutes ago
        So if we now have Vaultwarden + keyguard can these things move away from Bitwardens api and pursue their own?
  • contravariant 7 minutes ago
    I'm a bit confused what they're actually doing. Their code is now covered by two different licenses with each file licensed under one of the two and they claim the resulting application is using the commercial Bitwarden license and not the GPL license?

    How on earth does that work? Is that something the GPL license even allows?

    This sounds like they're just taking a GPL licensed application and using it for themselves to make money.

  • Cider9986 1 hour ago
    This is enshittification but I'm not gonna drop Bitwarden unless they do something really bad. I'm already on the F-Droid version from their GitHub for my GrapheneOS phone because that one has no Google services/telemetry.

    One of the family members I set up with Bitwarden has said it changed their life and they can't imagine not using it. I would guess that would apply to any crossplatform password manager but Bitwarden is quite good and the one that stuck.

    I probably wouldn't move to one of these [1] because I don't like the UI of Proton Pass, the convenience of KeyPass, and 1Passsword is obvious. I'm interested in AliasVault as it seems to be a more privacy-focused password manager, which is cool, but I'd have to look more into it.

    [1] https://www.privacyguides.org/en/passwords

    [2] https://discuss.privacyguides.net/t/aliasvault-open-source-e...

  • mindracer 49 minutes ago
    This seems like the beginning of the end, what password manager is recommended now?
    • pprotas 40 minutes ago
      KeepAssXC + SyncThing works well if you don't mind tinkering and like independence from corporations

      Otherwise 1Password if you like paying money

      • Mashimo 33 minutes ago
        > KeepAssXC + SyncThing works

        From a quick look, that seems to be Desktop only.

        • pprotas 27 minutes ago
          Not desktop only, KeePass uses an encrypted file, all you need is a way to decrypt it. You can store it in iCloud or whatever you like to sync files between devices.

          iOS has a good open source app KeeForge to open the encryped password files. I use SyncTrain on my phone to connect to my SyncThing network.

          • mindracer 10 minutes ago
            I use syncthing for my Linux devices but though it didn’t work on iOS. Will check out SyncTrain, thanks!
        • upboundspiral 17 minutes ago
          It's unfortunate that its a bit fragmented but there are Android / iOS complements as well - respectively keepassDX and keepassium.
  • inexcf 1 hour ago
    Well seems like Bitwarden is dying. A clear move towards enshittification. I was fine with the premium subscription existing while i was self-hosting Vaultwarden, but now every step seems to make that worse. Now new features will be under the commercial license an everything else will be slowly neglected. Time to jump ship.
    • movsx 59 minutes ago
      I have been eyeballing PassPony[0] as a replacement.

      The fact that they still do not support Yubikeys is holding me back from switching, but I expect this to be ironed out soon.

      [0]: https://passpony.app/

      • 0l 51 minutes ago
        Looks far too sloppy for me to trust this software with my passwords...
        • movsx 34 minutes ago
          I do not like the idea of self-hosting VaultWarden because I generally do not like the idea of application software requiring so much random access memory for even the simplest tasks. So, my idea was to use something like pass[0] or passage[1] (pass[0] + age[2]) on a remote server, but the problem arises when Yubikeys come into play.

          I am in no way, shape, or form, endorsing this PonyApp thingy and cannot vouch for it as I haven't audited it. But judging by what it says on the tin, it does appear like a candidate to solve the specific problem I have.

          [0]: https://www.passwordstore.org/

          [1]: https://github.com/FiloSottile/passage

          [2]: https://github.com/FiloSottile/age

    • blahlabs 52 minutes ago
      Any suggestions or ideas for where to?
  • karel-3d 45 minutes ago
    I don't understand the point or the motivation. They don't list any.

    It's very badly explained what actually changes

  • charcircuit 9 minutes ago
    I don't see hours this business strategy works post LLMs. Someone's just going to immediately prompt into existence any commercial feature you make into the open source side.
  • anilgulecha 43 minutes ago
    Rust based vaultwarden awaits.
  • scotty79 28 minutes ago
    I'll be moving to PearPass ... there's really no reason for any company to hold my passwords for me.
  • caaqil 39 minutes ago
    Unless they pull the LastPass crap, this is not a big deal for regular users.
  • petterroea 1 hour ago
    Yet another elasticsearch. Or terraform. Or redis. I guess?

    Oss trying to protect itself from scalpers?

    • Rebelgecko 1 hour ago
      The new owners are just seeing how gradually they can boil the frog before the userbase moves elsewhere. Gotta maximize returns.
  • rvz 40 minutes ago
    The problem with this license change is that it is unenforceable, now that developers believe they can vibe-code their own.

    Only a matter of time until we see "OpenWarden", just like we saw the migration from Redis to Valkey.

    But let's be honest. "enshittification" here really means "I don't want to pay for my tools and I want it completely for free forever."

    Just look at the reactions towards the single UI change made in Firefox on HN [0] and already the complaints are there. Even if you charge your users $1 to remove tracking it is somehow "enshittification" because $1 is too much to pay for software maintenance.

    The real cost of maintenance is the amount raised in VC capital (Bitwarden raised $100M) or $600M a year (Google paying Firefox). Donations won't cover the capital needed to fund Firefox or Bitwarden's development at all.

    "Open source" is only sustainable when someone else is paying for that maintenance. Small donations will only take you so far until one core developer says that they are underpaid.

    [0] https://news.ycombinator.com/item?id=49892721

    • alt227 9 minutes ago
      > But let's be honest. "enshittification" here really means "I don't want to pay for my tools and I want it completely for free forever."

      That is completely the opposite of what is happening here. Lots of us pay premium Bitwarden subscriptions and are not happy with the way the company is headed, especially for a security company that holds the keys to many of our kingdoms.

      "enshittification" here means a company that we trusted is now started to make decisions which erode that trust. Its happened before and it will happen from here unto eternity.

  • hn3ufz62f7 1 hour ago
    [flagged]