Live data from Hacker News

Concerns raised over Bitwarden moving further away from open source

phoronix.com

21–30 of 61 posts

Re: Concerns raised over Bitwarden moving further away from open source

#21
I'm paying for BitWarden because I want to support them. But it's pretty clear that they're backsliding.

This is understandable, the password manager market is saturated and implementing new features like Passkeys is far from trivial.

Still, they are the only real option for a one-click mostly open source password manager that works across all the major platforms and that supports modern features.

Re: Concerns raised over Bitwarden moving further away from open source

#22
post #12

What alternatives do you recommend?

KeepassXC. https://keepassxc.org/ Recently switched over from a premium Bitwarden account to it. Import from Bitwarden was a breeze. Note that KeepassXC only writes to a local encrypted db file. Syncing that across devices is left to you. I used Syncthing for that.

I think the thing we need to learn about security is that usability matters.

I think this is easy for pretty much anyone that's an active HN user, but is it for your parents or grandparents? It's they who matter a lot. It's why WhatsApp was so successful, it passed the Grandma check. Signal might, but onboarding is "hard" (and the nerds argue and that's all others hear and then do what... Use telegram? Lol). But it's why Matrix isn't gaining popularity, because frankly until creating servers is a one click install it's not going to get mass appeal (same for any federated app).

It's the old PGP joke: how do you decrypt a PGP email? You email the sender "I can't decrypt, can you send it without encryption?"

Re: Concerns raised over Bitwarden moving further away from open source

#23
post #19
post #16

Earlier quoted context omitted.

No support for passkeys, either.

It does support passkeys.

iOS application doesn't: https://github.com/keepassium/KeePassium/issues/297 Neither does the Android app: https://github.com/PhilippC/keepass2android/issues/2099

Re: Concerns raised over Bitwarden moving further away from open source

#25

Disappointing that a website that touts itself for, among other things, "Open Source News", is missing the core definition issue in that headline: what is at issue here has zero to do with how open or closed the source code is. It's only related to how free/libre the license is. That's a big deal to some, no doubt, but it's important to be precise about language in cases like this, especially since folks will undoubt…

The licence is the definition of Open Source.

Re: Concerns raised over Bitwarden moving further away from open source

#26

I wonder when they are going to start blocking official clients from using things like vaultwarden.

I haven't looked at their clients repo [1] thoroughly, but I guess it's a good thing the bulk of their client apps are licensed under GPLv3 and can be easily forked.

[1] https://github.com/bitwarden/clients

Re: Concerns raised over Bitwarden moving further away from open source

#27
This is disappointing. I use gopass for my personal passwords, but had moved family passwords to Bitwarden, and selected that hosted provide becauser it was open source.

I will continue to vote with my wallet, with other open-first solutions like ente and etesync.

Part of why I do this is so that if the company changes direction, the community can potentially fill in.

With the momentum behind vaultgarden, maybe open clients will flourish too.

Re: Concerns raised over Bitwarden moving further away from open source

#28

Earlier quoted context omitted.

KeepassXC. https://keepassxc.org/ Recently switched over from a premium Bitwarden account to it. Import from Bitwarden was a breeze. Note that KeepassXC only writes to a local encrypted db file. Syncing that across devices is left to you. I used Syncthing for that.

I think the thing we need to learn about security is that usability matters. I think this is easy for pretty much anyone that's an active HN user, but is it for your parents or grandparents? It's they who matter a lot. It's why WhatsApp was so successful, it passed the Grandma check. Signal might, but onboarding is "hard" (and the nerds argue and that's all others hear and then do what... Use telegram? Lol). But it's…

> Signal might, but onboarding is "hard" (and the nerds argue and that's all others hear and then do what... Use telegram? Lol).

I refuse to use Signal because their message history functionality is too restrictive for me.

Telegram strikes a good balance, and wins at the UI/UX game.

Re: Concerns raised over Bitwarden moving further away from open source

#29
post #12

What alternatives do you recommend?

KeepassXC. https://keepassxc.org/ Recently switched over from a premium Bitwarden account to it. Import from Bitwarden was a breeze. Note that KeepassXC only writes to a local encrypted db file. Syncing that across devices is left to you. I used Syncthing for that.

You can use Vaultwarden. And official server implementation is open-source still.

Re: Concerns raised over Bitwarden moving further away from open source

#30
post #4

Earlier quoted context omitted.

What dark patterns have you observed that I should keep an eye out for?

Making it seem like you can use a premium feature, only to present you with a "You need to upgrade" view after a few steps. Eg for Keypass and authenticator.

I'm also not sure what utility the premium features are.

There's the encrypted files, but they don't live in a vault. It seems that most obvious use case (being that you only get 1G) is to attach photos to IDs. But the implementation is silly. It's encrypted on their cloud where you download a copy and it then lives unencrypted on your device.

It seems silly that this is the implementation considering your passwords live in a local vault where you don't need a network connection.

Idk, I do want to support them but it does concern me when developers do not think about details, especially when it comes to security. The little things matter a lot.

Post reply on HN