Live data from Hacker News

Bitwarden SDK relicensed from proprietary to GPLv3

github.com

281–290 of 381 posts

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#281

Earlier quoted context omitted.

I'm glad that Bitwarden moved quickly to resolve this. At least for me, Firefox's password manager isn't really a replacement. Bitwarden is approved by my employer, self-hostable, and supports logins for the litany of apps across my browsers and mobile devices. Whether it's the mobile app, mobile website, or site in my browser, Bitwarden just works for the most part. It's also quite nice that Bitwarden can store arbi…

Its Bitwarden only for personal use. Do they have a solution for Multi-use password sharing?

in Vaultwarden you can have "organizations" that are like groups of people and you can have passwords there that are accessible by members

No idea how this maps into Bitwarden's own offerings though but all clients support this kind of thing

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#282
I’m relieved. Maybe the company would have survived this somehow, but they sure wouldn’t have been the techies’ darling anymore and that was going to be expensive.

I hope they realized that being FOSS is their moat and it nets them a lot of goodwill (it’s the whole reason I bother with their not-quite-the-best product in the first place). The bold claim „the most trusted password manager“ was kind of justifiable while it was FOSS (if we don’t count keepass), without it not at all.

I’m still not sure how I feel about them now. I can now somewhat trust that the applications will remain free software, but trust in the company has eroded a bit. I still haven’t seen official communication about this.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#283
post #276

Earlier quoted context omitted.

Switching is decisively a pain. But apparently this episode was what I needed to start looking seriously into VaultWarden.

Huge VaultWarden fan here. It's been running absolutely unattended for about 3 years from a machine in my basement now, and it's great. I back things up fairly often, but otherwise I would have no idea I'm not just using the enterprise grade Bitwarden license. Things just work, features are there. Side-note - VaultWarden is incredibly reliable for a self-hosted free solution (I have 1 pod restart 27 days ago due to a…

Tacking onto this comment as another thumbs up for vaultwarden. "incredibly reliable" is exactly the way to describe it, in the world of tech headaches the password manager is the last thing you want to be worrying about and I can say with confidence that vaultwarden is a reliable well-oiled machine.

Backups are also fairly easy so if need be a DR can be done (and automated) with very little hassle. The vaultwarden backend does depend upon the bitwarden apps for client devices but also features it's own web UI.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#285

Earlier quoted context omitted.

Huge VaultWarden fan here. It's been running absolutely unattended for about 3 years from a machine in my basement now, and it's great. I back things up fairly often, but otherwise I would have no idea I'm not just using the enterprise grade Bitwarden license. Things just work, features are there. Side-note - VaultWarden is incredibly reliable for a self-hosted free solution (I have 1 pod restart 27 days ago due to a…

Tacking onto this comment as another thumbs up for vaultwarden. "incredibly reliable" is exactly the way to describe it, in the world of tech headaches the password manager is the last thing you want to be worrying about and I can say with confidence that vaultwarden is a reliable well-oiled machine. Backups are also fairly easy so if need be a DR can be done (and automated) with very little hassle. The vaultwarden b…

Your comment was marked dead FYI, I vouched for it.

Normally this would mean you are shadow banned, but I don't see any other comments in your history getting this treatment - perhaps this comment caught the ire of some anti-spam algorithm.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#286
post #96

Earlier quoted context omitted.

What finally brought me to using BW was that I simultaneously needed to backup/sync my TOTPs across mobile/desktop devices, and came to have the need for sharing an increasing number of passwords with my SO. It delivered beautifully on all of that.

This isn't an area I know much about, but wouldn't there be a security risk involved with storing the TOTP seeds alongside the passwords? Or is that not a real concern?

Totally correct, the lame excuse being that it didn't make the situation worse for the reason that those factors were anyway authenticated using the same device previously already. But at least I am now in much less trouble in case this device gets lost/broken/stolen/…

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#287

Earlier quoted context omitted.

Yeah, likewise. I'm a Bitwarden subscriber but I'd been looking into alternatives recently because of the licensing kerfuffle. But switching password managers is a pain, so I'm glad to not feel like I have to now.

Are there other alternatives that are 1) open source 2) offer the same integration to begin with and finally 3) have been audited or are popular enough to be under constant scrutiny? There is of course the KeePass ecosystem, but that is why I included my second point, as with KeePass you are responsible for vault syncing, having clients for all platforms, etc. I suppose that it is good to be aware of other options. A…

i use the keepass ecosystem with app.keeweb.info. Its an open source webclient that can directly pull from your google drive (and other places!). I use a google drive through keeweb for syncing, 2 clicks and its syncd. Auto pulls when past pw.

keepass works in browser (how I use it on a computer), can work offline (which is good in air-gapped instances, one of my reqs) and works directly on my android phone without issue.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#288

Thank you to Bitwarden for relicensing a thing to Free/Open License! Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good. But for anyone with more advance needs (or who doesn't trust a password manager built into a web browser, I always recommend Bitwarden because KeepassXC + syncing is way too difficult for normal people.

All the browser password managers are not really secure enough and give a false sense of security.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#289

Earlier quoted context omitted.

Huge VaultWarden fan here. It's been running absolutely unattended for about 3 years from a machine in my basement now, and it's great. I back things up fairly often, but otherwise I would have no idea I'm not just using the enterprise grade Bitwarden license. Things just work, features are there. Side-note - VaultWarden is incredibly reliable for a self-hosted free solution (I have 1 pod restart 27 days ago due to a…

Tacking onto this comment as another thumbs up for vaultwarden. "incredibly reliable" is exactly the way to describe it, in the world of tech headaches the password manager is the last thing you want to be worrying about and I can say with confidence that vaultwarden is a reliable well-oiled machine. Backups are also fairly easy so if need be a DR can be done (and automated) with very little hassle. The vaultwarden b…

Old versions of vaultwarden broke recently (for just about everyone?) due to incompatible changes on the iOS client.

Breakage is not ideal, but here's how they handled the second, more subtle compatibility break:

https://github.com/dani-garcia/vaultwarden/issues/5069

I haven't worked up the courage / time to back up my database and upgrade the docker container; will probably get to it this weekend. However, I can't imagine using bitwarden with the official server (too bloated to be trustworthy), or with their cloud thing. I got burnt by lastpass. I'm not putting my passwords in a giant high-value target again.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#290
post #108

Earlier quoted context omitted.

The original Firefox sync worked like this (with a unique code and pairing instead of an explicit account) (this is so on the nose I suspect you may know this). This blog post goes over some of that history: https://blog.mozilla.org/services/2014/04/30/firefox-syncs-n...

Didn't expect to click on that link and end up on a blog post I wrote 10 years ago! The old Firefox Sync / PAKE stuff was fantastic for getting sync going between devices... but people wanted backup, not sync. I wonder if we'd do anything differently confronted with the same challenge today.

Hey I love the syncing
Post reply on HN