I actually find this somewhat understandable; and I'll be continuing my subscription; as long as all source continues to be available and personal self-hosting remains a viable option.
Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.
Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.
It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.
I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.
I’m conflicted. On one hand I’m grateful for the years of trustworthy (and pay-what-you-want) password management. On the other this feels like an attempt to EEE the free version.
That's my concern as well. I have no problem with the current license change if they continue to publish all the code as they claim. My concern is that this is usually step 1 in a boil-the-frog strategy to eventually split and break off enterprise features. I'll give them some trust until they give me a reason not to (I think they've earned it), but the concern remains.
Sorry but the elasticsearch thing was a big stupid take of elastic. It was big corpo against big corpo not the poor elastic company.
Changing licenses is a sick move and companies doing that should be fucked over, because the license made them big. Changing it later on means that they got greedy nothing more nothing less.
Without oss bitwarden would be a paid cloud like all the others that probably would’ve had a hard time getting trusted.
Okay, it’s good they have the open source because if you rewrite the Chrome extension you can get it to load in under 100 ms after you click the button. If you use the standard Chrome extension you’re not having that happen on an M1 Max. Their stuff is far too heavy. Full JS framework to display a small box.
IMO Bitwarden really isn't that well engineered software, and I now use Keyguard on Android/Vaultwarden server instead. Reminds me of Subsonic, with many competing clients/servers. Hopefully someone will write a third party browser extension as the current one is quite slow/buggy.
Circa earlier this year I found this blog post, and have – as a paying customer nonetheless, mind you – continued to expect a 180-degree turn (which to be clear, this not yet is) ever since:
This is enshittification but I'm not gonna drop Bitwarden unless they do something really bad. I'm already on the F-Droid version from their GitHub for my GrapheneOS phone because that one has no Google services/telemetry.
One of the family members I set up with Bitwarden has said it changed their life and they can't imagine not using it. I would guess that would apply to any crossplatform password manager but Bitwarden is quite good and the one that stuck.
I probably wouldn't move to one of these [1] because I don't like the UI of Proton Pass. I'm interested in AliasVault as it seems to be a more privacy-focused password manager, which is cool, but I'd have to look more into it.
Well seems like Bitwarden is dying. A clear move towards enshittification. I was fine with the premium subscription existing while i was self-hosting Vaultwarden, but now every step seems to make that worse.
Now new features will be under the commercial license an everything else will be slowly neglected. Time to jump ship.
The problem with this license change is that it is unenforceable, now that developers believe they can vibe-code their own.
Only a matter of time until we see "OpenWarden", just like we saw the migration from Redis to Valkey.
But let's be honest. "enshittification" here really means "I don't want to pay for my tools and want it completely for free forever."
Just look a Firefox and a single UI change gets them complaining or even if you charge them $1 to remove tracking it is somehow "enshittification" because $1 is too much to pay for software maintenance.
I actually find this somewhat understandable; and I'll be continuing my subscription; as long as all source continues to be available and personal self-hosting remains a viable option.
Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.
Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.
It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.
I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.
I’m conflicted. On one hand I’m grateful for the years of trustworthy (and pay-what-you-want) password management. On the other this feels like an attempt to EEE the free version.
That's my concern as well. I have no problem with the current license change if they continue to publish all the code as they claim. My concern is that this is usually step 1 in a boil-the-frog strategy to eventually split and break off enterprise features. I'll give them some trust until they give me a reason not to (I think they've earned it), but the concern remains.
They don't?
"Some future components will be published under the commercial license and will exist only in that build."
(From that thread)
Sorry but the elasticsearch thing was a big stupid take of elastic. It was big corpo against big corpo not the poor elastic company.
Changing licenses is a sick move and companies doing that should be fucked over, because the license made them big. Changing it later on means that they got greedy nothing more nothing less.
Without oss bitwarden would be a paid cloud like all the others that probably would’ve had a hard time getting trusted.
Okay, it’s good they have the open source because if you rewrite the Chrome extension you can get it to load in under 100 ms after you click the button. If you use the standard Chrome extension you’re not having that happen on an M1 Max. Their stuff is far too heavy. Full JS framework to display a small box.
Very insightful blog post listed by another user as a sub-comment. Worth posting as a top-level comment:
https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden
IMO Bitwarden really isn't that well engineered software, and I now use Keyguard on Android/Vaultwarden server instead. Reminds me of Subsonic, with many competing clients/servers. Hopefully someone will write a third party browser extension as the current one is quite slow/buggy.
What about it isn't well engineered?
Isn't Vaultwarden using the same clients?
Keyguard appears to be alternative Bitwarden compatible clients.
Yes but this person is using an alternative Android client as well.
This was always inevitable when they took funding.
Correct.
Circa earlier this year I found this blog post, and have – as a paying customer nonetheless, mind you – continued to expect a 180-degree turn (which to be clear, this not yet is) ever since:
https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden
I’m willing to commit money to a project committed to release free builds without these shenanigans.
Bitwarden is still releasing free builds but yeah you'd need a new project with a new name to use it from the Play Store or App Store.
Turns out Keyguard, an alternative Bitwarden client is already on the Play Store.
https://github.com/AChep/keyguard-app
This is enshittification but I'm not gonna drop Bitwarden unless they do something really bad. I'm already on the F-Droid version from their GitHub for my GrapheneOS phone because that one has no Google services/telemetry.
One of the family members I set up with Bitwarden has said it changed their life and they can't imagine not using it. I would guess that would apply to any crossplatform password manager but Bitwarden is quite good and the one that stuck.
I probably wouldn't move to one of these [1] because I don't like the UI of Proton Pass. I'm interested in AliasVault as it seems to be a more privacy-focused password manager, which is cool, but I'd have to look more into it.
[1] https://www.privacyguides.org/en/passwords
[2] https://discuss.privacyguides.net/t/aliasvault-open-source-e...
This seems like the beginning of the end, what password manager is recommended now?
KeepAssXC + SyncThing works well if you don't mind tinkering and like independence from corporations
Otherwise 1Password if you like paying money
Rust based vaultwarden awaits.
Unless they pull the LastPass crap, this is not a big deal for regular users.
Well seems like Bitwarden is dying. A clear move towards enshittification. I was fine with the premium subscription existing while i was self-hosting Vaultwarden, but now every step seems to make that worse. Now new features will be under the commercial license an everything else will be slowly neglected. Time to jump ship.
I have been eyeballing PassPony[0] as a replacement.
The fact that they still do not support Yubikeys is holding me back from switching, but I expect this to be ironed out soon.
[0]: https://passpony.app/
Looks far too sloppy for me to trust this software with my passwords...
Any suggestions or ideas for where to?
I don't understand the point or the motivation. They don't list any.
It's very badly explained what actually changes
The problem with this license change is that it is unenforceable, now that developers believe they can vibe-code their own.
Only a matter of time until we see "OpenWarden", just like we saw the migration from Redis to Valkey.
But let's be honest. "enshittification" here really means "I don't want to pay for my tools and want it completely for free forever."
Just look a Firefox and a single UI change gets them complaining or even if you charge them $1 to remove tracking it is somehow "enshittification" because $1 is too much to pay for software maintenance.
Yet another elasticsearch. Or terraform. Or redis. I guess?
Oss trying to protect itself from scalpers?
The new owners are just seeing how gradually they can boil the frog before the userbase moves elsewhere. Gotta maximize returns.