Live data from Hacker News

Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

fastcompany.com

101–110 of 150 posts

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#101
post #83
post #76

Earlier quoted context omitted.

Did Lastpass have a project like Vaultwarden behind it at the time? I'm hoping against hope that that will keep us with an open vault.

vaultwarden is great, but password managers are security critical software that need consistent maintenance and constant updates. if bitwarden is acquired and the new owner decides an open source version of their product is not a business necessity, without someone actively supporting the salaries of engineers it’s unlikely to continue to be secure for much longer.

> vaultwarden is great, but password managers are security critical software that need consistent maintenance and constant updates.

You’re acting like this isn’t the case already with vaultwarden? (and it’s easier to host as well, making for easier updates) https://github.com/dani-garcia/vaultwarden/releases

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#102

How does the GPL licensing affect future versions of the open source clients? I use Vaultwarden right now. Part of the reason was that I wanted something where there was a minimum guarantee. In the case of Vaultwarden, I can always fall back to the web interface if needed. It wouldn't be convenient, but it guarantees no one can take away my password vault. I really hate the per user per feature per byte per year pric…

It doesn't. All third-party contributions must assign copyright to Bitwarden.

https://contributing.bitwarden.com/contributing/

https://cla-assistant.io/bitwarden/clients

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#104
> Bitwarden has also stopped listing “Inclusion” and “Transparency” as tentpole values on its careers page.

I'm pretty sure I have never cared about what values a company listed on its careers page, unless I am considering working there.

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#105

Actually, the part of the article that made me prick my ears up was this paragraph: In February, longtime CEO Michael Crandell moved to an advisory role, according to LinkedIn, with no announcement from the company. His replacement, Michael Sullivan, former CEO of both Acquia and Insightsoftware, touts his experience with “all facets of mergers and acquisitions” on his own LinkedIn page, including experience working…

When did they remove DEI language? And how is that relevant, either way?

It's relevant because it was ostensibly a value of Bitwarden's at some point, but they've thrown it under the bus now that they're looking for a buyer.

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#106
post #93
post #71

Earlier quoted context omitted.

Useable yes, but trustable? Not without some serious backing and regular auditing from some public security experts. IMO that fact that the existing Vaultwarden system relies on Bitwarden clients and therefore caries Bitwardens secure reputation is its main selling point. Take that away and Vaultwarden is nothing more than some random back end software that can not really be trusted.

Maybe, I don't think that reputation really should transfer anyway, and it's not something I would consider necessary for using it. (I mean, some scrutiny is obviously good, but I don't think it needs to be as big as Bitwarden).

> I don't think that reputation really should transfer anyway

Why not? The most important security bits are implemented client-side which is developed by Bitwarden. If the clients are secure then my database is safe even if Vaultwarden turns out to be evil.

Switching from Bitwarden Client to Vaultwarden Client would require about 3 orders of magnitude more trust than switching the server which primarily deals with encrypted blobs. If the client turns out to be malicious then it's game over.

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#107

> Bitwarden has also stopped listing “Inclusion” and “Transparency” as tentpole values on its careers page. I'm pretty sure I have never cared about what values a company listed on its careers page, unless I am considering working there.

Even then you should be sceptical. These values change when convenient, and big businesses will demonstrate different values in different countries. A value you stick to as long as its in your interest to do so is meaningless.

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#108

Earlier quoted context omitted.

When did they remove DEI language? And how is that relevant, either way?

It's relevant because it was ostensibly a value of Bitwarden's at some point, but they've thrown it under the bus now that they're looking for a buyer.

[flagged]

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#109

Earlier quoted context omitted.

I know it's not open-source, but I've been happy with Protonpass.

At least the clients are, it's something. https://github.com/protonpass

And they get audited, last one quite recently[1]:

The audit confirmed Proton Pass security is exceptionally robust:

- No remote exploits found: Users cannot be hacked simply by visiting a malicious website or clicking a link.

- No encryption bypasses identified: Attackers can’t use shortcuts, backdoors, or weak keys to bypass the encryption layer.

Take it for what it's worth.

[1]: https://proton.me/business/blog/proton-pass-audit-2026

Re: Bitwarden scrubs 'Always free' and 'Inclusion' values from its site

#110
I stopped paying them when they started closing their clients. If they remain good stewards of FOSS I have no problem with starting again - Bitwarden provides serious value to me.

But I’ll probably have to rethink recommending it to people, since any type of friction is seriously harmful here.

Post reply on HN