cross-posted from: https://thelemmy.club/post/57178743

RyanL Bitwarden Employee

Hello everyone!

Starting in the next release, the Bitwarden apps published to the various stores will be the commercially licensed builds. No action is needed, and the apps will work exactly as they do today.

Bitwarden remains committed to open source security and transparency
The GPLv3 OSS licensed version continues to be updated and published on GitHub
All current features are available in both versions
License details are on GitHub
Bitwarden remains committed to a robust, free forever plan for everyone

If you have any questions, please ask them in this thread. Thanks all!

EDIT:

Bitwarden is not going closed-source
You can still fork Bitwarden
No change to self-hosting, the licensing change affects those who are repackaging and reselling Bitwarden
The free plan is here to stay permanently
  • 4grams@awful.systems
    link
    fedilink
    English
    arrow-up
    4
    ·
    35 minutes ago

    Goddamnit, enshittification comes for ALL paid services eventually. Looks like I have another service to start self hosting…

  • Fmstrat@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    2 hours ago

    Does this mean I will, or won’t be able to install the FOSS version through GitHub? Trying to stop repackagers from selling your project is one thing, but killing the source available installs would be another.

  • mrdrew@lemmy.today
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 hours ago

    “bitwarden apps will be the commercially licensed builds.” I don’t understand how this is going to change anything.

    I self-host vaultwarden. I use the official Bitwarden app, it works swimmingly. Going the self-hosted route you get enterprise features (I don’t use em).

    Doesn’t the licensing stuff connect with the backend not the app?

    https://hub.docker.com/r/vaultwarden/server

  • youmaynotknow@lemmy.zip
    link
    fedilink
    English
    arrow-up
    15
    ·
    5 hours ago

    It just blows my mind how so many comments use the term ‘purchase’ as if this new enshitification step still allowed for the dictionary meaning of the word.

    I used to suggest bitwarden to everyone, now it’s basically ‘start using KeePass, keep a copy of your db in a USB drive in your safe, have fun’.

    • Croquette@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      8
      ·
      2 hours ago

      The fact that bitwarden raised 100 millions from venture capitalists for “acceleration” and small changes towards a closed license for premium features is a steady step towards enshittification.

      The writing is on the wall and every announcement like that is a step further into enshittification to provide value for shareholders at the expense of thrle consumer base.

      I still haven’t switched yet because life is going fast and I didn’t come around to do my backup file server yet, but I would suggest anyone reading this to look for an alternative because it will get worst.

    • StateMachine@lemmy.zip
      link
      fedilink
      English
      arrow-up
      4
      ·
      3 hours ago

      Yep, have been using KeyPass or KeyPassX for at least a decade now and just syncing across all machines (via syncthing). 100% reliable in my experience.

  • NekoBeko@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    5 hours ago

    So, will you still be able to use the builds with the free license? Does that mean that the App Store builds will be locked down?

  • Guanlin@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    65
    ·
    12 hours ago

    Pretty much seen it coming when the new CEO came in and removed the words “Transparency” and “Always Free” from the official marketing.

    • Zagorath@quokk.au
      link
      fedilink
      English
      arrow-up
      12
      ·
      3 hours ago

      Whether you believe it or not is another matter, but this very post still includes the words “transparency” and “always free”.

      Bitwarden remains committed to open source security and transparency

      Bitwarden remains committed to a robust, free forever plan for everyone

      and a bonus:

      The free plan is here to stay permanently

      • nomy@lemmy.zip
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 hour ago

        You can already see them positioning themselves to start removing features with the phrase “free plan.”

        Nothing stopping them from limiting the number of passwords available in “the free plan” or something, pressuring users into “the pay plan.”

        But I’m pretty cynical.

        • giant_smeeg@feddit.uk
          link
          fedilink
          English
          arrow-up
          1
          ·
          37 minutes ago

          Aslong as it stays source available at a bare minimum for the paid offering/options I think I can live with that.

        • Zarobi@aussie.zone
          link
          fedilink
          English
          arrow-up
          10
          arrow-down
          1
          ·
          6 hours ago

          Bitwarden has much better enterprise options. KeePass is kind of dinky by comparison; even for a single user you immediately run into the problem “how do I sync my new password to my phone automatically?” Bitwarden was just an app that worked.

          That being said ~ I see the writing on the wall, and will be going back to the dinky option. Again. This isn’t the first time I’ve been burnt, but I never seem to learn. Self-hosting seems to be the only sustainable long-term option after all. Hopefully the migration isn’t too painful.

          I highly recommend anyone reading this get your export out while they still have a good export tool. First thing companies do in enshitification 101 is make it difficult to leave and trap you via inconvenience.

  • NGC2346@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    30
    arrow-down
    1
    ·
    15 hours ago

    If you are on Lemmy, theres very high probability that you also have the technical abilities required to self host Vaultwarden and stop relying on a greedy company for your most critical aspect.

    • 1984@lemmy.today
      link
      fedilink
      English
      arrow-up
      15
      arrow-down
      1
      ·
      8 hours ago

      I could but I don’t want. Self hosting something this important? I can’t login to any website without this software, including my email. It’s super critical.

      • giant_smeeg@feddit.uk
        link
        fedilink
        English
        arrow-up
        1
        ·
        36 minutes ago

        Yeah vaultwarden and photos are the 2 things i’m too nervous to selfhost. I do selfhost basically everything else but these 2 things are too important for me to mess up that I just don’t…

      • krysel@lemmy.ml
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 hours ago

        The vault gets synced to your devices. So even if your Backend goes down you dont lose access to your passwords in an instant

        • WhyJiffie@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          2
          ·
          52 minutes ago

          yeah, until the client logs you out randomly. it has an increased chance when the server behaves funky.

        • John@lemmy.ml
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 hour ago

          So you have basically a local copy on your phone, for example, that syncs when possible?

    • abc@suppo.fi
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      1
      ·
      7 hours ago

      Then again, if you can do that, why not just use pass

      • Lena@gregtech.eu
        link
        fedilink
        English
        arrow-up
        4
        ·
        6 hours ago

        There seems to be only one Android client, and it’s been archived on Github. I kinda need an android client for a password manager to be usable.

    • ImpulseDrive42@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      14 hours ago

      I have Vaultwarden, it works with the web app and browser extensions. But is there a vaultwarden specific android app? I know technically I can use the Bitwarden app. But sometimes they update the Bitwarden app too fast for all the changes to translate into Vaultwarden and then im kinda forced to use the web app.

      The web app is just a minor inconvenience to me so I continue to use it. Just wondering if there is an easier Vaultwarden specific solution for android.

    • Nullpwn@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      5
      ·
      9 hours ago

      Yes because using a different then normies app also means technical skills. In fact, haven’t your PhD diploma came along when you signed up for your Lemmy account?

  • Jubei Kibagami@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    2
    ·
    15 hours ago

    Fantastic. I’m tired of having to change password managers. DashLane, Keepass, LastPass, etc., they all end up shooting their own foot somehow.

      • blarth@thelemmy.club
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 hour ago

        Because the new CEO seems to really be wanting to find revenue and this step just reaffirms in my mind that he’s likely going to start reducing features for unpaid accounts.

    • giant_smeeg@feddit.uk
      link
      fedilink
      English
      arrow-up
      27
      ·
      21 hours ago

      Don’t even know where i’d switch.

      Proton -> I already use Proton suite and I like the seperation, the 2 password option doesn’t work for me either. I just need a seperate password.

      Keepass -> I use quite a few devices and the sync just seems like a nightmare…

      Any other options? For now i’ll stick as BW is still great but will start exploring others.

          • SepticModular@quokk.au
            link
            fedilink
            English
            arrow-up
            5
            ·
            9 hours ago

            But thousands of people have it working just fine. Not calling you out but it does work very well. Did you follow a step by step guide? I know websearch makes it hard to learn new tech things these days.

            Just keep in mind, set up a default folder and file (filename.kdbx) to share on one device, add Remote Device (QR code helps there), go to Sharing Tab and select Default Folder. If the Default Folder isn’t ticked on both devices in the Sharing Tab on each, nothing happens. When you work it out, that folder can be called anything and you can get advanced with how or when it shares or which direction the data goes (think photo backup from mobile to desktop).

            New Android app to use is:

            https://github.com/chenxiaolong/BasicSync

            Use Obtainium- https://github.com/ImranR98/Obtainium - to install it and keep it updated. Obtainium can update itself the same way.

            Convoluted, I know, but so is relying on a company to host for you in the cloud. They just hide all the complexity behind the interface. With Syncthing, once it’s set up between all your devices (and there is a way to quickly auto accept setup once further advanced/knowledgeable), it just chugs along in the background. Changes to keepass file appear almost instantly across each device once it’s opened.

            • ImmortalColeSlaw@lemmy.today
              link
              fedilink
              English
              arrow-up
              2
              ·
              54 minutes ago

              I’m probably going to try it again in the near future and hopefully it’s better than it was. Saving your comment, thank you.

              • SepticModular@quokk.au
                link
                fedilink
                English
                arrow-up
                1
                ·
                13 minutes ago

                Oh, I hope not. It’s not really that clear. I’ve been on it for a long, long time so would have got through that stage you tested with no issues. Having Basicsync now is nice, it’s just the webui on your phone with some quality of life improvements like when it turns on etc. Very simple and familiar across multiple devices.

                Try comparing what I said with the official guide from “Configuring” downwards. Hits more than what I tried to communicate and has screenshots if you get lost.

                https://docs.syncthing.net/intro/getting-started.html

                When I first started with it, I just set it up on my phone with the Default Folder (and file inside) at /sync and then walked around to the other devices, open up Show ID on the new one I’m at, add remote from my phone and QR scan the new device. You then get a notification to accept the device, then make sure Default Folder in Sharing is ticked for both. You can just find devices on the network too.

                The more devices, the greater redundancy on the keepass file if you lose a device or it fails. Sometimes there are conflicts with files that haven’t been synced properly (none of my family’s iOS devices sync always on in the background and I don’t use iOS so it’s not my problem and hasn’t been troubleshot) but you can merge conflicts in Syncthing in Keepass by merging both files together. Set up Simple File Versioning and 5-10 copies when you are confident with it. If you have a device that’s always on like a server, it tends to be the arbiter of truth and catches sync issues. Android/Linux/Windows just work for me.

                Good luck.

        • dreamkeeper@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          38 minutes ago

          Proton pass works just as well if not better for me. The autofill is much more reliable on Android than bitwarden was, although I did switch about a year ago.

  • ture@lemmy.ml
    link
    fedilink
    English
    arrow-up
    67
    arrow-down
    1
    ·
    1 day ago

    That’s quite the disappointment. Probably need to prepare to switch away from bitwarden or at least research options for open source clients for my vaultwarden backend.

    • superglue@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      43
      ·
      1 day ago

      Someone can correct me, but this change seems to be targeting people who are repackaging bitwarden and selling it. It does feel like we are trending the wrong direction though.

      • ture@lemmy.ml
        link
        fedilink
        English
        arrow-up
        57
        ·
        22 hours ago

        If you read their announcement carefully you’ll find things like

        All current features are available in both versions
        

        Which strongly implies that the different versions will start to diverge over time. Then at one point they will just be like maah it’s not worth putting more work into the open source thing, we’ll focus on building new cool features yada yada yada. And this is how all the open to partly open to closed source rug pulls worked in the last years.

        (If you want to do this the worst way possible like MinIO you also squash / delete the Git history the moment you announce you’re only working on closed source)

          • ture@lemmy.ml
            link
            fedilink
            English
            arrow-up
            3
            ·
            5 hours ago

            Yeah well, didn’t know this. I’m still running some old minio instances on my home server. Need to check if the docker images are still around otherwise I urgently need a backup plan…

            Fucking hell, why didn’t they at least leave the old code available 😭

      • ture@lemmy.ml
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        22 hours ago

        Before Bitwarden / Vaultwarden I went with Keepass (it was some fork don’t remember the exact name KeepassXC probably) synced via Nextcloud. It’s not as convenient as Bitwarden plus at least back then it didn’t support passkeys. So yeah, I don’t know what is actually out there. Honestly I don’t think it’s super urgent to start hunting for alternatives but probably we should have at least some ideas in case the Bitwarden team does some weird moves.

  • Rose@slrpnk.net
    link
    fedilink
    English
    arrow-up
    22
    arrow-down
    2
    ·
    21 hours ago

    When Bitwarden got a meh “refresh” of the user interface and started vibe coding stuff (I’m not some super hard-line anti-AI person, but dammit, you absolutely should not vibe code security-critical apps), I switched to KeePassX. It was like coming back home! I used to use KeePass and KeePass 2, switched to Bitwarden for a long while, and while it was neat, KeePassX is just neater. (Doesn’t have cloud sync, but syncing the vault files with LocalSend is easy enough.)