Live data from Hacker News

Bitwarden SDK relicensed from proprietary to GPLv3

github.com

351–360 of 381 posts

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#351

Earlier quoted context omitted.

To be fair, Bitwarden clients are mostly GPL and can be forked, and there's Vaultwarden for self-hosting. We just need to rally together a community that would maintain such a fork.

The iOS client can never be meaningfully forked, ironically due to the GPL. If Bitwarden goes fully hostile that's lost forever.

I don't understand; isn't the repo licensed under GPLv3?

https://github.com/bitwarden/ios?tab=GPL-3.0-1-ov-file

Is proprietary config required to build the IPA file?

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#352
post #155

Earlier quoted context omitted.

Someone else linked the GitHub issue that triggered this change and most of the replies are in the same tone as the comment you're responding to. Which is all the more ridiculous as this looks like it wasn't really a big license change decision but more of a "forgot to change the license on a component from our internal default". Assuming malice seems like the most boneheaded reaction to this given that there are no…

> forgot to change the license on a component from our internal default". https://gitlab.com/fdroid/fdroiddata/-/merge_requests/15353#... > Additionally, one thought that came to mind in evaluating this that might make this not possible is that our rust SDK, a dependency, is not published under an OSS license. See https://github.com/bitwarden/sdk . I assume that is a problem that might disqualify us from the main [fd…

> [O]ur goal is to make sure that the SDK is used in a way that maintains GPL compatibility.

This does, though:

https://github.com/bitwarden/sdk/issues/898#issuecomment-242...

It seems they reconsidered after the change impacted their F-Droid release. They've always been Open Core not fully Open Source so the SDK not being OSS isn't surprising. It just seems like they didn't think about the consequences of integrating a non-OSS SDK into their OSS clients.

Your first quote actually explicitly says that this incompatibility only became apparent after the fact:

> one thought that came to mind in evaluating this

So, yeah, a mistake although it's not so much they "forgot to change the license" but didn't consider which license it should use and stuck with the default.

> There are no plans to adjust the SDK license at this time

This doesn't mean it was an intentional choice or well thought out. It would have been pretty stupid to say "yeah, we actually just went with proprietary because it's the internal default and didn't think about the pros and cons of keeping it that way" so in lieu of wanting to make a decision then and there or signaling radio silence, that's just a standard corporate non-answer.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#353
post #277

Earlier quoted context omitted.

I have no affiliation, just found them this week, but https://psono.com/ exists. So 1 and 2 are met and 3 is half-way there maybe? It's a self-audit but they have been around a while. Apache2 licensed. Again, I literally found them the other day, and other than a cursory check to make sure the UI/UX is friendly enough to compete with BW or 1P, I haven't had a chance to look through their code at all yet. I have no id…

Hi, Sascha here, the main developer behind Psono. Psono has been audited multiple times so far, usually on a yearly bases. The last one here https://psono.com/blog/security-audit-2024 (you will also find a link to the audit itself)

Thanks! I missed that!

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#354
post #323

Earlier quoted context omitted.

Yeah; GPLv3 seems designed to give pure *aaS companies an unfair advantage over people that want to give users the option to buy commercially supported hardware that runs the company's software. For instance, Google can use bash in their backend infrastructure, but Apple cannot ship it on MacBooks or iOS anymore.

> Yeah; GPLv3 seems designed to give pure *aaS companies an unfair advantage over people that want to give users the option to buy commercially supported hardware that runs the company's software. SaaS didn't exist when the GPL was drafted. If that's an issue for you, there's the AGPL.

> SaaS didn't exist when the GPL was drafted

If you mean v3, this isn't true. AGPLv3 is written the same time as GPLv3, and references each other to maintain compatibility (a special provision that lets you use code in the other license provided you follow the other license for that component)

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#355
post #310

Earlier quoted context omitted.

KeePassXC (and I assume the other versions) can import an encrypted JSON Password Protected (NOT Account Restricted) export from Bitwarden. I use them both. I have KeePassXC for my local machine, and Bitwarden for things I may need out and about. With the browser plugins for both it's not that hard to manage them both, at least in my opinion. I was hoping to see some course correction on this from Bitwarden, even if…

There is little chance I’ll ever move to keepassxc as that requires me to maintain it myself and take the chance on deleting something very precious. I’ll stick with the cloud solutions for now.

Synchronizing is not too difficult. You can use syncthing or any cloud-based storage solutions you are already using. You can also back stuff up. Given it has a recycle bin I wouldn't think accidentally deleting stuff is any more likely than a cloud solution. It's probably harder to back up a cloud solution as you don't have direct access to the file.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#356

Earlier quoted context omitted.

I have the opposite problem. If I forget to log into bitwarden, passwords just get saved into firefox / chrome, so now I've got some passwords in bitwarden, some in chrome, some in firefox, and worst of all bitwarden doesn't seem to have an easy way to unify these databases.

That's a bit much to put on a 3rd party password manager.

I have the plugin installed in my browser, why does it wait for me to log in the come to life?

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#357
post #8

Bitwarden is still excellent, but keep an eye on them over the next few years. Remember that Bitwarden was originally a LastPass alternative without the fuckery.

Despite being proprietary, 1Password still hasn’t had any fuckery that I am aware of. I have been tempted to switch to an open source solution many times but I think I’ll be parking right here for a few more years yet.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#358
post #310

Earlier quoted context omitted.

Yeah, likewise. I'm a Bitwarden subscriber but I'd been looking into alternatives recently because of the licensing kerfuffle. But switching password managers is a pain, so I'm glad to not feel like I have to now.

KeePassXC (and I assume the other versions) can import an encrypted JSON Password Protected (NOT Account Restricted) export from Bitwarden. I use them both. I have KeePassXC for my local machine, and Bitwarden for things I may need out and about. With the browser plugins for both it's not that hard to manage them both, at least in my opinion. I was hoping to see some course correction on this from Bitwarden, even if…

A caveat that bears mentioning is that an export of a Bitwarden vault does not contain attachments.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#359
post #126

Earlier quoted context omitted.

It is not.

Would you care to elaborate? It also matters what counts as "bad password manager" to you - Poor crypto? Poor UX? A reddit post ;-)? LastPass? With passkeys, both the website and the user can be pretty sure that the "password" is secure. The website knows that it's based on enough entropy, and the user knows that the website can not loose it. Of course if I use a random generated 80 char password I only mildly care i…

Management, not password manager.

I'm not talking about technical merits, we all know passkeys are so complex they might work decently as obfuscation alone ;)

No, all that crap is meaningless when you give all your keys to an entity that simultaneously locks you in and couldn't give a fuck about you.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#360

Earlier quoted context omitted.

> store the password vault in dropbox No local backup? Do you rely on the network working all the time? I do something similar on the mobile phone (the reasining is, if there's no network, there's nothing I need to login to) but I also keep a local copy on my laptop (that I sometimes operate with limited connectivity). Without any automatic syncing, one of the two copies will be stale.

> No local backup? Do you rely on the network working all the time? Normal dropbox behavior keeps a copy on every computer.

> Normal dropbox behavior

Ah, you mean by using some app or daemon. I excluded that possibility because on at least one of my laptops I'm not allowed to install anything, so for me "normal" behavior is using Dropbox as a container for files to download when needed.

Post reply on HN