Live data from Hacker News

Bitwarden SDK relicensed from proprietary to GPLv3

github.com

91–100 of 381 posts

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#91
post #80

Earlier quoted context omitted.

But does it work for non-website passwords like the PIN for the door at your workplace or the usernames and passwords for your computers?

Yes. You can add whatever passwords. It asks you for a URL but you can put anything in.

> It asks you for a URL but you can put anything in.

Well, that’s kind of the problem isn’t it?

Yes, you can put bogus URLs, but it’s far from a great user experience

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#92

Thank you to Bitwarden for relicensing a thing to Free/Open License! Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good. But for anyone with more advance needs (or who doesn't trust a password manager built into a web browser, I always recommend Bitwarden because KeepassXC + syncing is way too difficult for normal people.

I used Firefox password manager for years, and moved to Bitwarden for: - Passkey syncing - Bitwarden on Android works properly, compared to Firefox's dedicated password app that's abandoned. - TOTP support (to use with some apps I don't want the strongest security)

But you are maybe right, if the only browsers you use are Firefox desktop/mobile.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#93
post #26

People here are incredibly hard to please. Very clearly a packaging issue that got blown out of proportion. They've done largely the right things for _years_ in terms of security. They've operated pretty transparently in terms of open sourcing. They've allowed vaultwarden to exist, and eventually created a self hostable version as well. But one bad release with a license screw up and nobody is willing to give them an…

You build a hundred solid bridges and you get called John the Good Bridge Builder. But lest you once screw up your software licensing and people notice and it blows up, you'll end up as John the Software Screwer in the annals of history... until next week.

Well it is kinda blasphemy to swear with evil proprietaryness in a loving FOSS community

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#94
post #85
post #29

I don't know why people are saying this is a bad thing.

Choosing GPL over AGPL for this kind of project combined with the previous recent CTO messaging is very telling if you consider the architecture of the software(s).

Telling what?

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#96

Thank you to Bitwarden for relicensing a thing to Free/Open License! Unfortunately, I no longer recommend Bitwarden for normal people because the built-in password manager in Firefox is too good. But for anyone with more advance needs (or who doesn't trust a password manager built into a web browser, I always recommend Bitwarden because KeepassXC + syncing is way too difficult for normal people.

What finally brought me to using BW was that I simultaneously needed to backup/sync my TOTPs across mobile/desktop devices, and came to have the need for sharing an increasing number of passwords with my SO. It delivered beautifully on all of that.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#97
post #37
post #20

Earlier quoted context omitted.

For a long time their KDF was bad and the iteration count was low. When I reported it to them they got really hostile and evasive about it. Years later they switched to Argon, somehow solving all of the blocking problems they had repeatedly claimed they couldn’t fix. I don’t trust the org at all. The software is ok but I only use it because it sucks marginally less than all my other options. People who care about sof…

> When I reported it to them they got really hostile You're not the one who first reported it, but I did see your comments at the time. Calling them hostile is really the pot calling the kettle black, uh?

To me the story also sounds a bit like GP was a bit impatient and felt a bit ignored while the company was already working on the issue but just didn't respond promptly to per personally.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#99
post #10

Luckily if they die another will rise up. At this point I’m thinking I’ll just use the Apple Keychain if Bitwarden gets up to no good again.

If I wasn't busy playing with AI stuff then I would be very tempted to build my own password manager cloud service, it feels like a chance to shine shows up at least once every two years in that space. I don't know what it is, but password managers just love the high-speed enshittification train.

Its not very easy and you shouldn't do it unless your domain is cryptography. This is something I've tried to do myself as well and realized it's better off left to the pros.

Re: Bitwarden SDK relicensed from proprietary to GPLv3

#100

Once an organisation has tried once they invariably do it again and again until they find a way to getting what they want. The customers tire of complaining over and over about little enshitifcations and eventually the company wins. Once they start it always goes the same way it just often takes a few goes before most give in. It will years until it becomes awful but the process has started. It's really a shame every…

If that would be the case, I wouldn't have expected them to change it back. I don't think it was that bad of an impact for them, they are already big enough in non-hardcore-open-source communities that they could pull it off and afford to lose some customers to go propietary. I'm actually really positively surprised by them that they actually picked up on this issue raised by the community and that they fixed it very promptly.

Yes the trust was seriously damaged, but this move does restore it largely for me.

Post reply on HN