Live data from Hacker News

Bitwarden SDK relicensed from proprietary to GPLv3

github.com

181–190 of 381 posts

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#181

Thank you to Bitwarden for relicensing a thing to Free/Open License! Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good. But for anyone with more advance needs (or who doesn't trust a password manager built into a web browser, I always recommend Bitwarden because KeepassXC + syncing is way too difficult for normal people.

> Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good Interesting, I've always felt that browser-based password managers provided remarkably little value for most people. Using them on mobile is tricky and platform dependent, it's easy to have local-only, non-synced data and then lose it, and being multi-device is trickier, especially in a work…

I have the opposite problem. If I forget to log into bitwarden, passwords just get saved into firefox / chrome, so now I've got some passwords in bitwarden, some in chrome, some in firefox, and worst of all bitwarden doesn't seem to have an easy way to unify these databases.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#182
post #146

No good thing ever lasts, especially in the world of tech. So, I'll be sticking with Bitwarden until they somehow eventually fuck it up and something else takes its place.

What will be ideal is a FOSS competitor. At least in personal usage segment until. Until they also start looking at big money and enterprise/professional (which is fine), then another competitor will come in. As long as the chain of export-import-export doesn’t break.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#183

Thank you to Bitwarden for relicensing a thing to Free/Open License! Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good. But for anyone with more advance needs (or who doesn't trust a password manager built into a web browser, I always recommend Bitwarden because KeepassXC + syncing is way too difficult for normal people.

Can someone also comment on how secure the built in password in manager in Firefox is to unsophisticated malware attacks that simply copy your browser extension data and such. Compared to bitwarden which requires a password to unlock it, and as I understand stores everything encrypted on disk.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#184
post #179
post #156

Such a pity they are starting to try to move to proprietary model. I have been using them for years. I thought they were different than other "open-source" companies (e.g. Redis). What are the alternatives for an open-source cross-platform password manager? Anybody has used Vaultwarden already?

No, they are not. They have a separate product which is closed source and there was a accidental mixup between the dependencies of the two. They fixed it quick. As I posted repeatedly in this issue: we need to be much much more lenient and supportive of one of the very few companies which still try. If this is the support they get why would anyone else even bother?

This was not an accidental mixup. Have you actually read the previous issue threads? Their stance was that "there are no plans to adjust the SDK license" before the backlash.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#185
post #150

Earlier quoted context omitted.

The LastPass fuckery was long and frankly egregious. Though I don't understand why this git commit is what's linked here. I'd rather hear the discussions on it. https://github.com/bitwarden/clients/issues/11611

After reading through the issue thread and the final reply by Bitwarden, I think the only context this provides is that the headline should rather be something like "Bitwarden SDK fixes dependency licensing issue". The opening comment and the final reply are the only valuable contributions in that issue. Everything in between is random people jumping in to feign outrage or telling people to use Vaultwarden (which btw…

> (which btw recently was in the news for more significant negative reasons)

Do you by chance mean CVE-2024-{39924, 39925, 39926}?

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#186
post #50

Earlier quoted context omitted.

Firefox password sync just works. It's one of those things I never think about. Watching friends and family struggle with bespoke, poorly integrated password managers makes me cringe and is one of the big reasons I enjoy the seamless experience of the built-in Firefox password manager.

Can Firefox password manager work in other apps on Android?

Looks like yes[1]

1. https://support.mozilla.org/en-US/kb/end-of-support-firefox-...

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#187
post #55
post #48

BitWarden has lost the trust. Besides recently there was a blocker bug on iOS and on Reddit I found out it happened earlier as well. They didn't even want to debug it and when I suggested this and asked whether they have any issue logged on Github where I could provide logs they went radio silent. Follow ups went completely unanswered. And yeah before that they had given a solution (because reinstall/re-login nothing…

[flagged]

[flagged]

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#188

Earlier quoted context omitted.

It's still 2 factors though, if someone discovers your password they don't automatically know the TOTP key. So I use TOTP in my password manager for sites where I wouldn't use 2FA otherwise (because using my phone would be inconvenient), so it's still a security improvement for me. And for critical accounts I do use Aegis on my phone.

That's not 2FA, that's two of the same factor. The factors are: - Something you know - Something you have - Something you are (biometrics)

Not sure what you mean, it's still a second unique token that an attacker would need to know to access my account, so it's improving my security even when stored in my password manager. This was in response to grandparent's opinion that it's "at best a reduction in security".

I'm not talking about my password vault getting breached, in that case I'd be fucked either way.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#189
post #54

Earlier quoted context omitted.

You can use syncthing too. Works just as well.

Is there a robust Syncthing app for iOS? Last time I checked there was only an affiliate project and their story wasn't convincing.

it was just discontinued for android :(

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#190
post #156

Such a pity they are starting to try to move to proprietary model. I have been using them for years. I thought they were different than other "open-source" companies (e.g. Redis). What are the alternatives for an open-source cross-platform password manager? Anybody has used Vaultwarden already?

I've been using KeePass (mostly through third-party clients) for years and never saw a reason to switch to anything else.

It doesn't sync between devices by default, but I see that as an advantage, you can use a cloud provider like Dropbox, your own server, FTP, Syncthing, whatever you're comfortable with.

Post reply on HN