cross-posted from: https://thelemmy.club/post/57178743

RyanL Bitwarden Employee

Hello everyone!

Starting in the next release, the Bitwarden apps published to the various stores will be the commercially licensed builds. No action is needed, and the apps will work exactly as they do today.

Bitwarden remains committed to open source security and transparency
The GPLv3 OSS licensed version continues to be updated and published on GitHub
All current features are available in both versions
License details are on GitHub
Bitwarden remains committed to a robust, free forever plan for everyone

If you have any questions, please ask them in this thread. Thanks all!

EDIT:

Bitwarden is not going closed-source
You can still fork Bitwarden
No change to self-hosting, the licensing change affects those who are repackaging and reselling Bitwarden
The free plan is here to stay permanently
  • Jubei Kibagami@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    6 minutes ago

    Fantastic. I’m tired of having to change password managers. DashLane, Keepass, LastPass, etc., they all end up shooting their own foot somehow.

  • Rose@slrpnk.net
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    1
    ·
    6 hours ago

    When Bitwarden got a meh “refresh” of the user interface and started vibe coding stuff (I’m not some super hard-line anti-AI person, but dammit, you absolutely should not vibe code security-critical apps), I switched to KeePassX. It was like coming back home! I used to use KeePass and KeePass 2, switched to Bitwarden for a long while, and while it was neat, KeePassX is just neater. (Doesn’t have cloud sync, but syncing the vault files with LocalSend is easy enough.)

      • Rose@slrpnk.net
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 hours ago

        Yup, I was supposed to say KeepassXC. (…I mean I probably considered using KeepassX at some point, it’s XC’s predecessor after all. But as I recall Keepass 2 worked well enough on Mono, so I didn’t need to switch.)

        Also, whoopsies on XC’s AI use. At least they don’t seem to embrace it as much as Bitwarden, but still makes me go hmm.

  • AppleMango@lemmy.world
    link
    fedilink
    English
    arrow-up
    15
    ·
    7 hours ago

    I think all of us can just using Vaultwarden, it seems to fix all the problems that are there even in the old free version of Bitwarden.

  • ture@lemmy.ml
    link
    fedilink
    English
    arrow-up
    41
    arrow-down
    1
    ·
    9 hours ago

    That’s quite the disappointment. Probably need to prepare to switch away from bitwarden or at least research options for open source clients for my vaultwarden backend.

    • superglue@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      28
      ·
      9 hours ago

      Someone can correct me, but this change seems to be targeting people who are repackaging bitwarden and selling it. It does feel like we are trending the wrong direction though.

      • ture@lemmy.ml
        link
        fedilink
        English
        arrow-up
        30
        ·
        7 hours ago

        If you read their announcement carefully you’ll find things like

        All current features are available in both versions
        

        Which strongly implies that the different versions will start to diverge over time. Then at one point they will just be like maah it’s not worth putting more work into the open source thing, we’ll focus on building new cool features yada yada yada. And this is how all the open to partly open to closed source rug pulls worked in the last years.

        (If you want to do this the worst way possible like MinIO you also squash / delete the Git history the moment you announce you’re only working on closed source)

      • ture@lemmy.ml
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        7 hours ago

        Before Bitwarden / Vaultwarden I went with Keepass (it was some fork don’t remember the exact name KeepassXC probably) synced via Nextcloud. It’s not as convenient as Bitwarden plus at least back then it didn’t support passkeys. So yeah, I don’t know what is actually out there. Honestly I don’t think it’s super urgent to start hunting for alternatives but probably we should have at least some ideas in case the Bitwarden team does some weird moves.

  • dmtalon@lemmy.world
    link
    fedilink
    English
    arrow-up
    17
    arrow-down
    1
    ·
    9 hours ago

    Sigh… I hope this isn’t the first move of enshitifying bitwarden. I read the comments/replies and hope this is benign but I’m now nervous

    • scytale@piefed.zip
      link
      fedilink
      English
      arrow-up
      29
      ·
      7 hours ago

      The first move was when they hired a CEO who comes from private equity. This is the second move.

    • Mike Wooskey@lemmy.thewooskeys.com
      link
      fedilink
      English
      arrow-up
      28
      arrow-down
      1
      ·
      8 hours ago

      I think it is the next move (not the first) in enshittifying bitwarden. I think the first move was the leadership change announced in May.

  • woelkchen@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    8 hours ago

    App store EULAs and GPLv3 frequently clash. This change only affects the app store binary releases.

      • woelkchen@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        51 minutes ago

        So, 99% of users.

        How? It’s not like the source code if no longer under GPL, it’s just that this specific compiled binary is under a different license but it doesn’t change anything for anyone in real life.

  • E_coli42@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    arrow-down
    2
    ·
    8 hours ago

    I have a proton membership anyways so proton pass seems good since they have SimpleLogin

  • Foni@piefed.zip
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    5
    ·
    9 hours ago

    What would be the reason for using this and not Keepass from the beginning?

    • dmtalon@lemmy.world
      link
      fedilink
      English
      arrow-up
      19
      ·
      8 hours ago

      Well, a big reason I ended up with bitwarden is being able to have a family group that I can help foster, encourage, force my family to use a password manager by having/showing them how these work , why they should use them and continually point them to the app to save and/or retrieve passwords.

      The barrier to entry for non technical users is much lower. I don’t want to manage making sure everyone’s db is safe/synced etc… either

      • Foni@piefed.zip
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        3
        ·
        7 hours ago

        I don’t know, my wife (0 technical knowledge) works perfectly, with daughter and personal databases. Of course, it’s true that I set everything up myself and I make sure the database is on the family NAS. I’m not judging you or anything, but while it’s true that setting it up is a bit more difficult, using it, in my opinion, is not at all.

        • dmtalon@lemmy.world
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 hours ago

          I do run a number of self hosted things, (nextcloud, immich, plex). I had my own pw manager, and had tried keepass myself and when it came time to push the family to using a pw manager I just opted for bitwarden here vs taking ownership of managing that too!

          Hell, it’s still a literal fight/push to make them understand the importance of it <sigh>

      • mbirth 🇬🇧@lemmy.ml
        link
        fedilink
        English
        arrow-up
        3
        ·
        8 hours ago

        I’m using Strongbox on macOS and iOS. Uses a KeePass2 database in the background, does TOTP (so does KeePassXC), syncs via iCloud (but also supports SFTP, WebDAV, OneDrive, Google Drive, and Dropbox) and also keeps my Passkeys. And it supports Apple’s AutoFill API, so it works in basically any input field across the systems and feels “native”. No browser extensions (at least for Safari) needed.

        And if it goes rogue, I can switch to e.g. KeePassium or any other KeePass-compatible app.

      • Foni@piefed.zip
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        1
        ·
        7 hours ago

        I might be a bit paranoid (or an idiot) but I think having the password and the totp in the same database (and app) somewhat negates the point of two-factor authentication.

        • devfuuu@lemmy.world
          link
          fedilink
          English
          arrow-up
          10
          ·
          4 hours ago

          It does negate the big issue of passwords leaking from the websites and that’s the most important part of even having totp.

          Nobody is going to spend time to separate the 2 and maintain backups of two different things and all that extra effort when 90% of people don’t even use password managers.

          Don’t let perfection be the enemy of improvement.