https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden
Previously discussed: https://news.ycombinator.com/item?id=48163389
rsyring 7 hours ago
https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden
Previously discussed: https://news.ycombinator.com/item?id=48163389
nugget 7 hours ago
turtletontine 6 hours ago
birksherty 5 hours ago
doodlesdev 5 hours ago
missmewiththatl 5 hours ago
Oxodao 5 hours ago
nine_k 3 hours ago
cortesoft 5 hours ago
torzer321 4 hours ago
nine_k 3 hours ago
rascul 2 hours ago
SV_BubbleTime an hour ago
tappio 5 hours ago
Barrin92 3 hours ago
SV_BubbleTime 2 hours ago
If you believe that the technology works, that encryption is happening and that the decryption is only happening on your local machine then why in the fuck would I host this myself?
You need to believe that it does not work when they do it, but does work when you do it.
I have not seen any evidence of that.
jazzyjackson 4 hours ago
sliken 5 hours ago
I'm curious why other self hosters think it's a bad idea.
movsx 4 hours ago
rented_mule 3 hours ago
movsx 3 hours ago
Thanks for sharing.
nh2 3 hours ago
So probably its RSS usage is just mostly its own executable code?
ulimn 3 hours ago
dwedge 3 hours ago
What will you use when this stops working in the near future?
haellsigh 3 hours ago
BrandoElFollito 31 minutes ago
nightski 3 minutes ago
jchw 4 hours ago
jonny2811 3 hours ago
mostly i was missing power user features and especially ux for the browser plugin, namely you can't operate it fully with the keyboard, with keepassxc you can
zikduruqe 33 minutes ago
No reason to use anything more complicated.
backlit4034 6 hours ago
https://www.glassdoor.com/Reviews/Bitwarden-Reviews-E4337610...
alt227 6 hours ago
Guess I'll never be visiting Glass Door again then.
to11mtm 5 hours ago
Not sure if still the case but normally you have to not only 'sign in' but also feed them information (e.x. salary at a position, write a review, etc.) in order to be able to view much of anything.
They also do not give a shit about obvious 'juicing' (i.e. when it is obvious that upper management and/or HR is adding reviews where the 'con' reads like one of those softball warning phrases in a job description.)
encom 5 hours ago
The most egregious example I've found was that the Danish postal service had something like a 4,8/5,0 rating on Trustpilot. You'll be hard pressed to find a more inept, corrupt and universally hated company. So in an attempt to improve their public image, they decided to game the ratings, instead of actually delivering mail properly.
chanux 5 hours ago
However they may have proved that they are indeed.. trash. Maybe even a few times.
One such case was https://www.forrester.com/blogs/glassdoors-mishandling-of-cu...
In my eyes they are in the same class of Facebook, uservoice, Pinterest, Quora etc.
happosai 5 hours ago
waltbosz 4 hours ago
happosai 3 hours ago
Fundamentally it's all a game of whack-a-mole for admins unless some kind of microtransaction system is invented. Then a DDOS scraping event is just extra revenue.
nine_k 3 hours ago
wiether 3 hours ago
latchkey 5 hours ago
e40 an hour ago
jazzyjackson 4 hours ago
dwedge 3 hours ago
pas 3 hours ago
or pooling together tokens and asking Claude nicely to make a mobile app
limagnolia 3 hours ago
dwedge 2 hours ago
jventura 4 hours ago
What's happening with Namecheap? I've been a user for a long time and haven't noticed anything.. Maybe I'm one of the frogs being boiled!
ygjb 4 hours ago
alasano 2 hours ago
The switch to Vaultwarden was insanely easy.
movsx an hour ago
28304283409234 an hour ago
Wowfunhappy 6 hours ago
> And it never comes in a single dramatic announcement. It comes in layers. A feature post with a price change inside it. A LinkedIn update nobody made a press release about. A values page that says something slightly different than it did last week. If you’re still on Bitwarden cloud and this is giving you pause — it should. [...] Whether self-hosting stays viable long-term is the real question worth sitting with.
dizhn 6 hours ago
alt227 6 hours ago
tuwtuwtuwtuw 5 hours ago
alt227 3 hours ago
tuwtuwtuwtuw 3 hours ago
subscribed 3 hours ago
Everything else is just a nonsense, watermark and fluff, scamming from time and attention - there's NO value in the filler.
To reiterate: there's no value in this sort of the LLM garbage. There's value in the information, especially when formatted and provided in the humane format.
stavros 6 hours ago
formerly_proven 5 hours ago
Aardwolf 6 hours ago
orta 6 hours ago
terminalbraid 6 hours ago
Also protonpass.
GordonS 6 hours ago
tkuraku 6 hours ago
qwerpy 5 hours ago
Arrowmaster 6 hours ago
Bitwarden was the no nonsense choice because it just worked.
philsnow 5 hours ago
How does this work with keepassxc? Does it depend on your file syncing primitive?
Arrowmaster 5 hours ago
Lapel2742 6 hours ago
I already have "Proton Unlimited" as a subscription but until now I never used Proton Pass. I thought about giving up on Bitwarden for some time and probably will try it now. AFAIK you can even import your Bitwarden logins.
InsideOutSanta 6 hours ago
mpern 5 hours ago
For me, Pass works much better, especially passkeys on Android. Bitwarden was very flaky in that regard, Proton Pass "just works".
I use Pass for personal logins and sharing family-related accounts with my wife.
rpozarickij 5 hours ago
attendant3446 3 hours ago
frevib 5 hours ago
Proton ticks all good-company boxes. E2ee, majority owned by the Proton foundation, all client-side code is OSS, and some other structures in place to protect themselves from corp greed. Best I could find.
sylos 5 hours ago
AlexandrB 5 hours ago
fph 4 hours ago
Bloating 3 hours ago
whynotmaybe 5 hours ago
TeMPOraL 5 hours ago
Seriously. About as secure, if you're honest about the actual threat model (vs one security aficionados would like you to assume), and paper can't be enshittified.
dexterdog 4 hours ago
Diti 42 minutes ago
[1]: https://en.wikipedia.org/wiki/Bruce_Schneier
[2]: https://www.schneier.com/blog/archives/2005/06/write_down_yo...
alt227 6 hours ago
rsyring 6 hours ago
alt227 6 hours ago
Cort3z 6 hours ago
zackmorris 5 hours ago
https://docs.ipfs.tech/concepts/persistence/#pinning-service...
Maybe someone could write a provably private client-based browser decryption script, hosted on various websites. We might need a new browser spec that sandboxes pages until they're unsandboxed, allowing them no egress/ingress or even local storage or cookies.
Or better yet, take that choice away from browser vendors, and create a runtime in the browser that simply can't be observed, perhaps by using zero-knowledge proofs.
Writing this out, I wonder if the issue is due to longstanding incomplete browser architecture, going back to when the web went mainstream in the mid-1990s. Or maybe it's still just an open problem.
Solve private distributed durable storage, along with a base level of secret computation eventually running about the speed of a 6502, 286 or 68000, and we wouldn't need free services that inevitably get privatized and ensh!ttified.
I have no idea if something like this already exists, I'm just speculating as to what base functionality it might need from first principles.
Also I wonder if similar techniques could be recruited to build an OS around cryptocurrency. That way a meta economy could run alongside the corrupt economy, and shield users from currency devaluation and other wealth inequality drivers used by the ultra-wealthy to increase the value of the means of production that they own relatively, so that they can buy more.
Arguably the process of wealth concentration is so fundamental that it puts a countdown on capitalism, driving it towards the late-stage capitalism that we've had since about 1970 when productivity diverged from wages, and eventually revolution which results in socialism/communism or even permanent authoritarian dystopia like on Star Wars. In a way, it's in the best interests of the ultra-wealthy to build meta economies, which of course makes those economies suspect and probably vulnerable to exploits, especially in the AI age. We've seen how crypto has created black markets capable of capturing governments, so maybe we should be careful what we wish for.
But really I just don't want to type my password anymore.
haruka_ff 2 hours ago
atomicUpdate 5 hours ago
Or is it just software that has zero value to you because it’s intangible and you intentionally ignore the time and effort other people spend on it?
vuldin 4 hours ago
lokar an hour ago
Someone has to pay for ongoing maintenance.
Cort3z 4 hours ago
TitaRusell 3 hours ago
parineum 5 hours ago
lisp2240 2 hours ago
halfcat an hour ago
axelthegerman 5 hours ago
> The price is updating to $1.65/month, billed annually.
Followed by a 25% discount for this reveal only.
Have to go back to my old invoice to see it was $10/y and now the new one $19.80/y
I never liked that I needed to pay premium just for 2FA but this abuse of trust is definitely the end of it.
Too bad I won't get a refund for my Oct 1st renewal but I'll happily cancel as soon as I get vaultwarden hosted.
theturtletalks 5 hours ago
The argument here is always why would people spend all this time and money to build custom software when they can just pay a company $20-100 bucks a month? Because that product will become enshittified. It's not a question of if, its a question of when. I thought open-source SaaS would be immune, but clearly not.
TeMPOraL 5 hours ago
If you excuse a Warcraft-y metaphor.
snailmailman 3 hours ago
But it is worrying that they might intentionally break vaultwarden in the future.
microflash 5 hours ago
hannasanarion 4 hours ago
It's somewhat concerning to me that none of the security conscious people in this thread seem to notice that they are changing their privacy practices based on the advice of a language model pretending to be a person.
ok_dad 4 hours ago
Fuck bitwardens creators for selling out. I want them to know they fucking suck.
dannyw 7 hours ago
Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.
Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.
It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.
I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.
solarkraft 7 hours ago
freedomben 7 hours ago
4ndrewl 7 hours ago
"Some future components will be published under the commercial license and will exist only in that build."
(From that thread)
merb 7 hours ago
Changing licenses is a sick move and companies doing that should be fucked over, because the license made them big. Changing it later on means that they got greedy nothing more nothing less.
Without oss bitwarden would be a paid cloud like all the others that probably would’ve had a hard time getting trusted.
mcfedr 6 hours ago
vanviegen 3 hours ago
Or just trying hard to keep the company afloat?
Just because they published Open Source code at some point, you feel that you're entitled to free updates for the rest of your life?
selectodude 6 hours ago
Pay the $20/yr or whatever to have them host it and the whole world keeps turning.
lstodd 6 hours ago
Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all.
selectodude 6 hours ago
willmadden 6 hours ago
techjamie 6 hours ago
But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.
I'm not sure where your sentiment comes from here.
technolo-g 6 hours ago
atherton94027 6 hours ago
yjftsjthsd-h 5 hours ago
iohvvbhdyh 6 hours ago
judge2020 6 hours ago
A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me. I much prefer 1Password's approach where they have a usually-hidden second secret (the "Secret Key") that both (A) isn't shown unless you're setting up another device, and (B) acts as extra data needed to form the decryption key for your vault.
The main threat model I'm thinking of protecting against is a 1password vault data breach of some kind (or possibly cooperation with government agencies) + password exposure in some way (be it from CCTV-extracted password entries, over-the-shoulder watching, etc), as even with both of those factors, they would somehow need to get your secret key to decrypt vaults.
Like, all of those lastpass vaults obtained during the Lastpass hack would be de-facto useless even with a correct password if their design included some sort of hidden secret secret.
movsx 4 hours ago
orf 6 hours ago
ricericerice 6 hours ago
by that logic, every time you send a password over a TLS connection, you're publishing it outright too
trentor 6 hours ago
zeroonetwothree 6 hours ago
behringer 6 hours ago
dare944 4 hours ago
donmcronald 3 hours ago
Everything will get chipped away piece by piece. It’s been happening continuously for well over a decade at this point and everyone should understand the strategy by now.
dare944 13 minutes ago
At least with bitwarden, if the value they're trying to extract becomes more than the product is worth, in terms of real cost, lockin or transparency, at least the code is open now and for the foreseeable future. And when it comes time to fork it, AI will make it easier for the future maintainer(s) to keep the fork alive at minimal expense.
compsciphd 5 hours ago
1) bundle the "source available" modules as part of redis source distribution 2) enable people who only want bsd code to be able to build a "redis_core" 3) commit to the community that the core will remain BSD licensed and that they are committed to making it the best key/value store. 4) increase the amount of source available code that until then had been kept closed (including what we called big redis/RedisOnFlash/MultiTier) 5) Require anyone using the redis trademarks in a commercial setting to ship the entire Redis (which includes the source available portions, so Amazon et al would no longer be able to use the Redis trademarks without a license deal.
Another alternative was to simply go to AGPL (which they went to anyways awhile later).
I failed to convince the leadership about this. I honestly think they squandered huge value in community engagement, but perhaps that's what they wanted. I left a bit after these changes were made as it became clear that the new US led leadership of the company wasn't particularity interested in what was the soul of redis. (previously was heavily Israeli led and a critical mass there was invested in redis as an open source product).
Funny story, the then new/current CEO used to be the head of WebEx at Cisco. We had a Q&A when he was hired and I asked, what did he learn from his time at WebEx about how to maintain market position (as they lost everything to zoom et al). His response at the time wasn't that convincing, but I was willing to give him the benefit of the doubt. I feel its fair to ask if the same thing occurred again.
farlight 5 hours ago
ignoramous an hour ago
Business will have to try different things at different points due to external & internal pressures. Some decisions are reversible (at cost), some aren't. Decisions (chaotic / complex / complicated ones, at least) are not made merely based on available data and analysis, but also based on intuition, experiments, and predictions. Then, to look at the outcome rather than the process is missing the point. When the circumstance / situation isn't clear-cut, the feedback (the outcome of a decision) is in itself more valuable to the organization (than never having taken the decision, at all), especially when the costs (to reverse / change it) are bearable.
arjie 7 hours ago
Ecco 6 hours ago
lloydatkinson 6 hours ago
mimischi 3 hours ago
InsideOutSanta 6 hours ago
AlbinoDrought 6 hours ago
talon8635 6 hours ago
ulimn 3 hours ago
aetherspawn 7 minutes ago
0l 7 hours ago
schleck8 7 hours ago
Cider9986 7 hours ago
Timshel 7 hours ago
alright2565 6 hours ago
sigio 5 hours ago
tmulcahy 7 hours ago
0l 6 hours ago
Admittedly the mobile clients have since been rewritten to be native (they were _really_ slow before), but Keyguard is still much faster/lighter.
I started using 1Password at work and it's just a.. nicer experience? It does all this and more. Everything is fast, the browser extension is more proactive/recognises fields better (Bitwarden can't really do multi step logins), and the desktop client isn't a chore to use.
The best comparison I would give is comparing Immich and Jellyfin (if you've used these), they are miles apart in terms of end user experience/polish/efficient design. One is engineered, the other feels like it's been hacked together by hobbyists.
jttnr an hour ago
mceachen 6 hours ago
Saris 5 hours ago
And it frequently fails to detect login fields, or does detect but fails to fill them with a generic error.
movsx 5 hours ago
maxo133 5 hours ago
Try to bring it up on bitwarden reddit sub, they will eat you alive
Avamander 5 hours ago
figmert 7 hours ago
msdz 7 hours ago
Circa earlier this year I found this blog post, and have – as a paying customer nonetheless, mind you – continued to expect a 180-degree turn (which to be clear, this not yet is) ever since:
lucideer an hour ago
I love that Bitwarden exists, but as an "open source" project, it's always been a trad-corporate type code maintenance, rather than community-driven source contributions (exactly why we've seen things like Vaultwarden pop up) & that has generally just left all of their clients in that really awkward space where they're just good enough to be able to imagine their potential, but their maintenance is stagnant enough to ensure they'll never reach it.
Imo the community needs this kick to motivate the development of alt vaultwarden clients. Bitwarden gives us a great starting point but we need to break away.
bigbaguette 5 hours ago
Then the community says it's okay, people are going to fork their clients, but that's gonna take trusting the future maintainers.
Also, even though they commit to keep maintaining an open source channel, we won't be able to verify the builds anymore.
jellyroll42 4 hours ago
donmcronald 3 hours ago
josephcsible 4 hours ago
zeroonetwothree 6 hours ago
talon8635 6 hours ago
ffsm8 5 hours ago
anyway, the bigger issue ive with this is the doubling of the price right from the get-go.
with private equity on the steering wheel, i suspect this will keep going up every year from now on, so ... while i too have been a loyal customer to date, i suspect ill be driven out within the next 1-2 years, because if they double the price again next year, its gonna be way beyond the value i get out of it given how decent the alternative have become since.
Avamander 5 hours ago
j1elo 5 hours ago
Is that possible, does that exist?
Cider9986 5 hours ago
j1elo 4 hours ago
Cider9986 4 minutes ago
diavolodeejay 4 hours ago
solarkraft 7 hours ago
Cider9986 7 hours ago
Turns out Keyguard, an alternative Bitwarden client is already on the Play Store.
https://github.com/AChep/keyguard-app
Edit: turns out Keyguard is source available but fully copyrighted.
alt227 6 hours ago
InsideOutSanta 6 hours ago
chrismorgan 5 hours ago
embedding-shape 3 hours ago
Cider9986 7 hours ago
One of the family members I set up with Bitwarden has said it changed their life and they can't imagine not using it. I would guess that would apply to any crossplatform password manager but Bitwarden is quite good and the one that stuck.
I probably wouldn't move to one of these [1] because I don't like the UI of Proton Pass, the convenience of KeyPass, and 1Passsword is obvious. I'm interested in AliasVault as it seems to be a more privacy-focused password manager, which is cool, but I'd have to look more into it.
[1] https://www.privacyguides.org/en/passwords
[2] https://discuss.privacyguides.net/t/aliasvault-open-source-e...
brachkow 3 hours ago
mnahkies 5 hours ago
I'm not immediately upset about the licensing change - I get the need to protect from low effort/value add reselling and things like that. I do still worry if this is a canary for future changes that run counter to the reasons I migrated to bitwarden in the first place (open, robust, trustworthy).
Counter to many other commenters I personally prefer bitwarden over 1password, and certainly over lastpass and roboform, etc.
My only gripe is having to unlock the desktop app separately from the browser extension, which after adopting the ssh agent functionality became kinda annoying.
mindracer 7 hours ago
pprotas 7 hours ago
Otherwise 1Password if you like paying money
Mashimo 7 hours ago
From a quick look, that seems to be Desktop only.
pprotas 6 hours ago
iOS has a good open source app KeeForge to open the encryped password files. I use SyncTrain on my phone to connect to my SyncThing network.
mindracer 6 hours ago
upboundspiral 6 hours ago
pprotas 6 hours ago
Zambyte 6 hours ago
Saris 5 hours ago
LeBit 6 hours ago
dannyw 5 hours ago
cricalix 6 hours ago
tcfhgj 4 hours ago
aetherspawn 6 minutes ago
inexcf 7 hours ago
movsx 7 hours ago
The fact that they still do not support Yubikeys is holding me back from switching, but I expect this to be ironed out soon.
0l 7 hours ago
movsx 7 hours ago
I am in no way, shape, or form, endorsing this PonyApp thingy and cannot vouch for it as I haven't audited it. But judging by what it says on the tin, it does appear like a candidate to solve the specific problem I have.
[0]: https://www.passwordstore.org/
blahlabs 7 hours ago
andrewjneumann 5 hours ago
I’m not sure why growth at all costs needs to be the business model for every company?… make a great product, if you need to charge more over time cool, but don’t rug pull.
economic9725 an hour ago
Beijinger 4 hours ago
They had/have(?) cybersale recently but did not offer the lifetime version. Otherwise I would have bought it. It is not open-source but it is damn convenient.
snapplebobapple 3 hours ago
karel-3d 7 hours ago
It's very badly explained what actually changes
MisterMunchkin 5 hours ago
karel-3d 2 hours ago
anilgulecha 7 hours ago
EasyMark 2 hours ago
robertlane0 6 hours ago
basilgohar 5 hours ago