Live data from Hacker News

Bitwarden SDK relicensed from proprietary to GPLv3

github.com

21–30 of 381 posts

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#21

Thank you to Bitwarden for relicensing a thing to Free/Open License! Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good. But for anyone with more advance needs (or who doesn't trust a password manager built into a web browser, I always recommend Bitwarden because KeepassXC + syncing is way too difficult for normal people.

Can it store TOTPs and passkeys as well? These are two things encountered even by "regular people" more and more.

Especially keeping passkeys platform-independent is a huge advantage, in my view.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#22
post #21

Thank you to Bitwarden for relicensing a thing to Free/Open License! Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good. But for anyone with more advance needs (or who doesn't trust a password manager built into a web browser, I always recommend Bitwarden because KeepassXC + syncing is way too difficult for normal people.

Can it store TOTPs and passkeys as well? These are two things encountered even by "regular people" more and more. Especially keeping passkeys platform-independent is a huge advantage, in my view.

Yes, Bitwarden can store both.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#23
post #10

Luckily if they die another will rise up. At this point I’m thinking I’ll just use the Apple Keychain if Bitwarden gets up to no good again.

Two things are preventing me from doing that: I occasionally want to access my passwords in a browser (and I do not want to log in to iCloud on that machine), and I'd feel really bad about having my passkeys stored in an Apple service with absolutely no way of exporting them in case I ever do switch platforms. (Bitwarden at least includes passkeys in their JSON export format, as far as I know.)

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#24
post #22
post #21

Earlier quoted context omitted.

Can it store TOTPs and passkeys as well? These are two things encountered even by "regular people" more and more. Especially keeping passkeys platform-independent is a huge advantage, in my view.

Yes, Bitwarden can store both.

I was referring to Firefox with that question.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#25

Thank you to Bitwarden for relicensing a thing to Free/Open License! Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good. But for anyone with more advance needs (or who doesn't trust a password manager built into a web browser, I always recommend Bitwarden because KeepassXC + syncing is way too difficult for normal people.

> because KeepassXC + syncing is way too difficult for normal people

I've been debating for ages if this is a hurdle that can be overcome by packaging or even hand-holding support. When I show "normal people" my pass+sync setup they beg me to implement it for them. Once it's running it's near-zero maintenance.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#26

People here are incredibly hard to please. Very clearly a packaging issue that got blown out of proportion. They've done largely the right things for _years_ in terms of security. They've operated pretty transparently in terms of open sourcing. They've allowed vaultwarden to exist, and eventually created a self hostable version as well. But one bad release with a license screw up and nobody is willing to give them an…

You build a hundred solid bridges and you get called John the Good Bridge Builder. But lest you once screw up your software licensing and people notice and it blows up, you'll end up as John the Software Screwer in the annals of history... until next week.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#27
post #18

Doesn’t GPL mean that it can’t be forked and published into the Apple iOS app store? Presumably they are able to do it because they own the rights and can grant a non-GPL license to Apple for distribution. This seems to me to still be a “nobody can fork this [and still have a viable iOS app] but us”.

The last time anyone did a serious published review of the App Store terms for GPL compatibility was probably 10+ years ago.

I remember pre-COVID trying to validate the popular claim that the App Store terms were incompatible with GPLv3 but being unable to do so. None of the provisions that were originally called out by the FSF were in the App Store terms anymore at that point. Certainly nothing I found in the terms at the time indicated any incompatibility.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#30
post #28
post #10

Luckily if they die another will rise up. At this point I’m thinking I’ll just use the Apple Keychain if Bitwarden gets up to no good again.

What was the no good that Bitwarden got up to?

https://news.ycombinator.com/item?id=41893994
Post reply on HN