Live data from Hacker News

Bitwarden SDK relicensed from proprietary to GPLv3

github.com

41–50 of 381 posts

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#41

People here are incredibly hard to please. Very clearly a packaging issue that got blown out of proportion. They've done largely the right things for _years_ in terms of security. They've operated pretty transparently in terms of open sourcing. They've allowed vaultwarden to exist, and eventually created a self hostable version as well. But one bad release with a license screw up and nobody is willing to give them an…

> But one bad release with a license screw up and nobody is willing to give them an inch?

I don't have a lot of context on the issue.

Is it clear it was just a packaging bug, rather than a move towards partially proprietary?

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#42
post #21

Earlier quoted context omitted.

Can it store TOTPs and passkeys as well? These are two things encountered even by "regular people" more and more. Especially keeping passkeys platform-independent is a huge advantage, in my view.

There will always be different opinions, but my opinion is that storing your TOTPs in your password manager is at best a reduction in security because you're reducing your 2 factors down to 1 factor. If the password manager gets compromised (even phished! It needn't involve the password manager's servers getting hacked), then you gain nothing by having 2FA enabled. I would strongly advise using something like Aegis o…

Sometimes the TOTP is forced on me for a service I really don't care about. That's most of mine, actually.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#43

Earlier quoted context omitted.

There will always be different opinions, but my opinion is that storing your TOTPs in your password manager is at best a reduction in security because you're reducing your 2 factors down to 1 factor. If the password manager gets compromised (even phished! It needn't involve the password manager's servers getting hacked), then you gain nothing by having 2FA enabled. I would strongly advise using something like Aegis o…

Doesen't having the seeds available on all of the devices make it not 2FA? You now need only one device to login at any given time.

The second factor isn’t a second device, it’s the TOTP code.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#44
post #10

Luckily if they die another will rise up. At this point I’m thinking I’ll just use the Apple Keychain if Bitwarden gets up to no good again.

It probably doesn't matter for you if you'll never be leaving Apple's ecosystem, but for anyone else, I think that's something to keep in mind before moving to a non-portable solution like Apple keychain.

I would love to use Apple keychain but you're right - as a mixed OS user, it's a tough sell.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#45
post #21

Earlier quoted context omitted.

Can it store TOTPs and passkeys as well? These are two things encountered even by "regular people" more and more. Especially keeping passkeys platform-independent is a huge advantage, in my view.

There will always be different opinions, but my opinion is that storing your TOTPs in your password manager is at best a reduction in security because you're reducing your 2 factors down to 1 factor. If the password manager gets compromised (even phished! It needn't involve the password manager's servers getting hacked), then you gain nothing by having 2FA enabled. I would strongly advise using something like Aegis o…

It's still 2 factors though, if someone discovers your password they don't automatically know the TOTP key. So I use TOTP in my password manager for sites where I wouldn't use 2FA otherwise (because using my phone would be inconvenient), so it's still a security improvement for me. And for critical accounts I do use Aegis on my phone.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#46

Thank you to Bitwarden for relicensing a thing to Free/Open License! Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good. But for anyone with more advance needs (or who doesn't trust a password manager built into a web browser, I always recommend Bitwarden because KeepassXC + syncing is way too difficult for normal people.

> because KeepassXC + syncing is way too difficult for normal people I've been debating for ages if this is a hurdle that can be overcome by packaging or even hand-holding support. When I show "normal people" my pass+sync setup they beg me to implement it for them. Once it's running it's near-zero maintenance.

can you share how do you set this up?

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#47

Earlier quoted context omitted.

> because KeepassXC + syncing is way too difficult for normal people I've been debating for ages if this is a hurdle that can be overcome by packaging or even hand-holding support. When I show "normal people" my pass+sync setup they beg me to implement it for them. Once it's running it's near-zero maintenance.

can you share how do you set this up?

I store the password vault in dropbox. Done.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#48
BitWarden has lost the trust. Besides recently there was a blocker bug on iOS and on Reddit I found out it happened earlier as well. They didn't even want to debug it and when I suggested this and asked whether they have any issue logged on Github where I could provide logs they went radio silent. Follow ups went completely unanswered. And yeah before that they had given a solution (because reinstall/re-login nothing had worked) - export your data, delete your account, create the account again, and re-import your data - that "should" work. Honestly it was worse than "restart your computer".

I guess it's time for another FOSS player here. It's fine, such things are cyclical I guess. Happened to Lastpass and Authy and someday it will happen to Ente and 2FAS and so on.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#49

Thank you to Bitwarden for relicensing a thing to Free/Open License! Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good. But for anyone with more advance needs (or who doesn't trust a password manager built into a web browser, I always recommend Bitwarden because KeepassXC + syncing is way too difficult for normal people.

> Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good Interesting, I've always felt that browser-based password managers provided remarkably little value for most people. Using them on mobile is tricky and platform dependent, it's easy to have local-only, non-synced data and then lose it, and being multi-device is trickier, especially in a work…

I'm not sure how it is on iOS, but I've been using firefox as my password maanger on android. It's a trivial change in the settings and works across all apps as well.

I also recommend it to my friend group, as they can use firefox with uBlock Origin, and also have their passwords synced.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#50

Thank you to Bitwarden for relicensing a thing to Free/Open License! Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good. But for anyone with more advance needs (or who doesn't trust a password manager built into a web browser, I always recommend Bitwarden because KeepassXC + syncing is way too difficult for normal people.

> Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good Interesting, I've always felt that browser-based password managers provided remarkably little value for most people. Using them on mobile is tricky and platform dependent, it's easy to have local-only, non-synced data and then lose it, and being multi-device is trickier, especially in a work…

Firefox password sync just works. It's one of those things I never think about.

Watching friends and family struggle with bespoke, poorly integrated password managers makes me cringe and is one of the big reasons I enjoy the seamless experience of the built-in Firefox password manager.

Post reply on HN