Bitwarden's new CEO has a Private Equity background, removed 'Inclusion' and 'Always Free' from their website -- because of course he did (www.fastcompany.com)
from german@pawb.social to selfhosted@lemmy.world on 15 May 19:05
https://pawb.social/post/44237085

In the latest episode of “they will always sell you out” - they sold you out! Who would’ve thought.

Hoping for a good alternative client to appear, the writing is on the wall. Vaultwarden can’t exist without “leeching” off of Bitwarden.

#selfhosted

threaded - newest

evil_andy@sh.itjust.works on 15 May 19:25 next collapse

Well, poop.

otter@lemmy.ca on 15 May 19:45 next collapse

I think the original title was more helpful because it shows that this is a recent development. Maybe you can add “new CEO”?

Bitwarden scrubs ‘Always free’ and ‘Inclusion’ values from its website as longtime execs step down

In February, longtime CEO Michael Crandell moved to an advisory role, according to LinkedIn, with no announcement from the company. His replacement, Michael Sullivan, former CEO of both Acquia and Insightsoftware, touts his experience with “all facets of mergers and acquisitions” on his own LinkedIn page, including experience working with leading private equity firms.

CFO Stephen Morrison also left Bitwarden in April, replaced by former InVision CEO Michael Shenkman. Both Crandell and Morrison joined the company in 2019. Kyle Spearrin, who started Bitwarden as a fun hobby project in 2015, remains the company’s CTO.

german@pawb.social on 15 May 21:37 collapse

You’re right, changed

Shortstack@reddthat.com on 15 May 19:45 next collapse

That’s troubling, I don’t like what this portends.

The new CEOs background especially suggests they’re spiffing up the company for a later sellout, why else would they pick a merger specialist for the role?

irmadlad@lemmy.world on 15 May 19:48 next collapse

<img alt="" src="https://lemmy.world/pictrs/image/3ee0c4e2-e070-4c12-9e61-9def6ae45864.png">

bitwarden.com/pricing/

I kind of find the headline a bit disingenuous. However, if they do move to a non-free model, I’d still pay for it. I mean $1.65/Month USD. Sure, I don’t even have to think about it.

Bluegrass_Addict@lemmy.ca on 15 May 20:34 next collapse

yeah fuck that… fuck subscriptions ALL OF THEM. fucn these companies, ALL OF THEM.

stop giving any of these pricks any slack. none of them deserve it, nor money.

today it’s 1.65… tomorrow it’s 4.99… next week it’s 12.99… stop being a mindless sheep giving them any sort of leeway. you’re enabling the scammers to literally scam you more, and more and more.

I’m relocating all my shit right now because we’ll… fuck em. I am loyal to NO COMPANY. none of them deserve anything but bankruptcy at a minimum.

irmadlad@lemmy.world on 15 May 20:41 next collapse

today it’s 1.65… tomorrow it’s 4.99… next week it’s 12.99… stop being a mindless sheep giving them any sort of leeway. you’re enabling the scammers to literally scam you more, and more and more.

‘Mindless sheep’. That’s hilarious. But I get it. Nobody likes to pay for shit.

skeezix@lemmy.world on 15 May 20:49 next collapse

Baaaaaaa.

irmadlad@lemmy.world on 15 May 20:53 collapse

Man, I tell you, I wish I could live in a fantasy world where everything is free.

skeezix@lemmy.world on 15 May 20:55 collapse

Not sure about “everything”, but plenty of password managers are.

irmadlad@lemmy.world on 15 May 21:02 collapse

There are a handful of things I do not self host.

  • arr stack
  • password managers
  • anything financial
circuitfarmer@lemmy.world on 15 May 20:55 collapse

I mean, when we see the same pattern of endless subscription creep and price hikes on virtually every service… saying “but it’s only [insert dollars here]” does sound pretty out of touch.

irmadlad@lemmy.world on 15 May 21:01 next collapse

It’s not ‘out of touch’. It’s paying for (if it comes to that) a service that houses all of my business accounts, investment accounts, personal accounts, etc, and all with a pretty damn good track record. As with any technology, you must constantly evaluate it to see if what you are spending is justified for the service you are receiving. If at such time I feel the service isn’t worth the price, then sure. As of now, it’s not really an issue to me.

circuitfarmer@lemmy.world on 15 May 21:06 collapse

Sure. I think a lot of people just see that constant evaluation as postponing the inevitable, though (again, because the same pattern is everywhere). It’s not acknowledging that part which seems out of touch.

irmadlad@lemmy.world on 15 May 21:34 collapse

It’s not acknowledging that part which seems out of touch.

I assure you, I am fully cognizant of what for-profit corporations do. It’s one of the reasons I turned off the TV over two decades ago. There just wasn’t any ROI for me.

akwd169@sh.itjust.works on 15 May 22:50 collapse

Hmm nice profile pic

circuitfarmer@lemmy.world on 15 May 23:05 collapse
iamthetot@piefed.ca on 15 May 21:31 next collapse

I’ve cut down my subscriptions by a lot over the past few years, and I’ve gotten very close to what I consider a minimum. Whenever possible, I like to buy outright.

However, surely you can understand how not every product can function as a one time purchase. For something like a password manager, they are providing an ongoing service. They are storing and serving your data.

You can self host, sure, and I’m doing a lot of that lately. But not everyone has the capacity or desire to.

All that said, this leadership shakeup is concerning and I think I’ll be migrating to Proton, since I already have a Duo plan.

Flagstaff@programming.dev on 15 May 22:42 collapse

You don’t need to self-host at all! Daisy-chain your needed files via Syncthing and Syncthing-Fork. That’s literally what I do with KeePassXC and KeePassDX, keeping everything offline.

hellmo_luciferrari@lemmy.zip on 15 May 23:53 collapse

I am totally in line with not agreeing with everything being a subscription. And I absolutely dont agree with subscription creep.

So I minimize what I pay for. And let me say, in no means am I defending the change in Bitwarden here. I would never.

It isn’t a realistic expectation to expect any hosted service to be free. Especially in capitalism. Someone will come along and fuck with pricing.

Not everyone has the time, knowledge, or finances to fund self hosting everything.

But to automatically assume everyone is a sheep for using a service that benefits them is a bit of a jump.

Yes, I myself value privacy, security, and the merits of self hosting as much as I can with my resources. And I have had conversations with people on these topics, and there are the folk that lack the understanding of the importance of the hill many of the folk like me stand on. So I have seen the wide spectrum of people who pay for services.

Wild take dude.

yAlL aRe ShEeP blah blah blah…

TheTrueColonel@lemmy.world on 15 May 21:35 next collapse

Funny thing is I clicked the link and “Always free.” was gone. Refreshed the page and it was back. Definitely something going on.

irmadlad@lemmy.world on 15 May 21:37 next collapse

<shrug> It was there when I went and took a screen shot without refreshing.

german@pawb.social on 16 May 00:09 collapse

It’s so deceptive, and clearly designed to be so. They saw the backlash and added two words, real backhanded vibes.

phx@lemmy.world on 16 May 05:16 collapse

Yeah it’s not about not paying for me, it’s about being able to host my own with my protections and controls

irmadlad@lemmy.world on 16 May 12:15 collapse

That is totally awesome and cool bro. You’ll never hear me throw shade on someone for charting their own course in life or choosing a different path. In fact, to drop a little relevant Hendrix up in here:

“I’m the one who has to die when it’s time for me to die. So, let me live my life the way I want.”

As long as my life doesn’t interfere with your life, we’ll be just jippity jippity. Rock on! Git sum! It’s a big world. We can all coexist.

Mister_Hangman@lemmy.world on 15 May 20:06 next collapse

Clue me in on why vaultwarden can’t exist without it?

baduhai@sopuli.xyz on 15 May 20:16 collapse

It can, but vaultwarden, as it currently is, is an implementation of the server only. So if bitwarden decides to go closed source all the way, they’d haver to start either creating their own clients or fork the current bitwarden clients.

scott@lem.free.as on 15 May 22:14 collapse

That’s fine. We just treat it as a fork from this point onwards.

Flagstaff@programming.dev on 15 May 22:41 collapse

Okay. You first.

RonnyZittledong@lemmy.world on 15 May 20:11 next collapse

Jesus, I’m tired of switching password managers.

tordenflesk@lemmy.world on 15 May 20:36 next collapse

Took me like 5 minutes to move back to KeepassXC.

duckshuffgoose@piefed.social on 16 May 03:47 collapse

i want to switch back to KeepassXC, but I very heavily use aliases in Proton Pass and can’t figure out a good way to still create those on the fly AND use Keepass as my default pass provider

slate@sh.itjust.works on 15 May 20:37 next collapse

KeePass isn’t going anywhere. They’re also dragging their feet on passkey support, so you might go with KeepassXC.

zeitverschreib@freundica.de on 15 May 20:46 next collapse

@slate

Wasn't there some commotion a few weeks about KeepassXC and vibe coding?

@RonnyZittledong

Dumhuvud@programming.dev on 15 May 21:04 next collapse

Yeah, there was. It was forked because of that, actually: codeberg.org/ChiPass

Viceversa@lemmy.world on 16 May 00:27 next collapse

404

Dumhuvud@programming.dev on 16 May 09:16 collapse

I edited the comment, see my reply to @wiccan2@thelemmy.club.

wiccan2@thelemmy.club on 16 May 09:33 collapse

Yep works now.

wiccan2@thelemmy.club on 16 May 00:30 collapse

Link gives 404

HappyFrog@lemmy.blahaj.zone on 16 May 08:54 next collapse
Dumhuvud@programming.dev on 16 May 09:15 collapse

I edited the comment. It ended with a period before, I assume your client thought it was a part of the link. Does it work now?

blackbrook@mander.xyz on 16 May 01:58 collapse

Their AI policy looks very reasonable, and they certainly aren’t vibe coding. Everything is rigorously reviewed and tested by a handful of experienced, competent humans.

eightys3v3n@lemmy.ca on 15 May 21:16 next collapse

They also don’t effectively allow collaboration though, which is my cheif reason for using a cloud hosted password manager.

Flagstaff@programming.dev on 15 May 22:39 next collapse

What is “collaboration” in this context?

eightys3v3n@lemmy.ca on 16 May 00:13 next collapse

Sharing passwords between groups of people so everyone always has the up to date version. Not breaking the world if two people try to modify the same entry as some file syncing solutions do.

Flagstaff@programming.dev on 16 May 01:03 collapse

Hmm, interesting, though isn’t that a fault of the organization not having an account-linking system so that each person could have their own credentials but can still access the unified content? This workaround seems… flimsy, unless I’m not picturing a legit scenario in which no other method is as good, or something.

FreedomAdvocate@lemmy.net.au on 16 May 02:36 next collapse

You know why most cloud based services charge money? For stuff like this, because it’s not free to implement and maintain.

Easy and fault-proof password sharing and syncing needs software and hardware to do. You either set it up and maintain it yourself, or pay for a product that does it - like Bitwarden.

Flagstaff@programming.dev on 16 May 07:54 collapse

But your argument falls apart against something like Syncthing’s discovery networks combined with send-/receive-only folder types, which use no cloud yet allow the automatic, passive propagation of file updates to different users’ devices… right? No cloud, no self-hosting, yet automatic syncing across multiple devices…

eightys3v3n@lemmy.ca on 16 May 13:05 collapse

It’s the fault of my family organization or every company we use that my parent’s bank, Google, phone, laptop, etc don’t allow more than one set of credentials to access the same thing?
It’s not just that we need to be able to share credentials the once a blue moon I need to help them by logging into their account?

Viceversa@lemmy.world on 16 May 00:29 collapse

Parallel creating, reading, updating, deleting password entries by multiple users.

Flagstaff@programming.dev on 16 May 01:01 collapse

Whoa, thanks. I had no idea this was a thing…

frongt@lemmy.zip on 15 May 23:13 collapse

Sure they do. Multiple people can have a file open at the same time. I use it for exactly this every day at work.

With KeePassXC, that is. I don’t know if other flavors have different support. I use XC primarily for the browser extension.

eightys3v3n@lemmy.ca on 16 May 00:16 collapse

And you can both modify the same things without causing horrible conflict issues? And you can share only parts of your vault with someone rather than having entirely different vaults you have to switch between? I’m assuming you mean putting the file somewhere like Google Drive, and you can access it offline even if you can’t edit it offline? For feature parity with Bitwarden, obviously ideally one could edit any time and it would resolve problems when it came back online if there were any but Bitwarden doesn’t allow this.

frongt@lemmy.zip on 16 May 00:29 collapse

Yes, no conflicts. I don’t know if you can only share part of vault; I just created a separate one for a separate team.

I wouldn’t put it in Google Drive or anything like that. The separate sync logic will definitely cause conflicts.

I’m not worried about having access if I’m offline, because if I’m offline I’m not going to be able to log into anything anyway.

eightys3v3n@lemmy.ca on 16 May 00:32 collapse

I guess a laptop, server, IoT device, or WiFi connection when your main device doesn’t have internet is out of scope for you?
Like fixing my laptop and not wanting to type the new password into my phone instead of copy/paste, sync when online?
And how are you sharing a file, to multiple people anywhere in the world realtime ish, without a cloud service you or someone else hosts? Doesn’t that necessitate some syncronization logic?

frongt@lemmy.zip on 16 May 00:41 collapse

It’s hosted on a local network share, so we don’t need Internet access.

If can’t copy paste, I just type it out.

We use a VPN to the office.

Flagstaff@programming.dev on 15 May 22:38 collapse

They’re also dragging their feet on passkey support

Astheyshould, forever.

4am@lemmy.zip on 15 May 23:13 collapse

Two articles behind a paywall, one that won’t load, and another article that says the big problem with passkeys is…people are unfamiliar with them.

If anyone tells you that Passkeys are bad, they’re a liar. Way more safe than passwords, full stop.

Just don’t let Microsoft or Apple tie them to your device. You don’t have to do that.

Flagstaff@programming.dev on 16 May 01:05 next collapse

Are you calling me a liar? That’s pretty weird; it’s not like I’m telling you to stick to passwords while I move to passkeys. With that said, though, get Bypass Paywalls Clean (Mozilla-only, as far as I know) and you’ll never see another paywall again. I forgot about having that.

Just don’t let Microsoft or Apple tie them to your device. You don’t have to do that.

The problem is that this is where it’s eventually going to lead to.

fushuan@piefed.blahaj.zone on 16 May 02:49 next collapse

Not really, Vaultwarden/bitwa4den offer passkey support. When I log into a service a popup shows on my extension, I click it and I’m in. It’s not gonna lead to device locking if you don’t want to…

Lemmert@reddthat.com on 16 May 08:58 collapse

At the very least you’re misguided or don’t know what you’re talking about. Passkeys are not vendor locked in and of themselves.

You can make the same argument against password managers because most iPhone users that use them, use Apple’s one.

qqq@lemmy.world on 16 May 16:45 collapse

They will almost certainly lead to vendor lock in. Why do you think they won’t? Apple’s password manager is definitely an example of vendor lock in. Many others have a simple to use export feature to CSV or something that others can understand

Edit: it could be that you don’t know what the WebAuthn/FIDO2 specification says or we understand it differently? Do you know how the attestation mechanism works? That ties the key to a device of software authenticator (the software authenticator is likely going to tie it to the device somehow, possibly even via a TEE).

qqq@lemmy.world on 16 May 16:42 collapse

There is no full stop there… A password that is sufficiently long will never be cracked no matter the hashing algorithm in use. Passwords are easily transferrable and can be communicated to a third party in the event of an emergency. They also provide tunable security, where you can trade off security for convenience if you want.

Some (not all, I know) passkeys are tied to a device. Stolen device means stolen passkey, and it’s potentially very difficult to recover from that. Passkeys are also locked to a certain standard, passwords have no such restrictions.

Tbh I don’t understand the move for passkeys replacing passwords. They should become the second factor when a user wants additional security. They’re perfect for that niche.

MangoPenguin@lemmy.blahaj.zone on 15 May 21:27 next collapse

KeePassXC + KeePassDX is probably the best option, with the downside of no way to sync easily (syncthing is probably the best option there)

I might switch back at some point, been getting frustrated with the bitwarden extension performance always being so poor.

electric_nan@lemmy.ml on 15 May 21:44 next collapse

Sync however you want. Syncthing, Nextcloud, Dropbox, Gdrive etc.

Flagstaff@programming.dev on 15 May 22:35 collapse

Syncthing is the way to leave Google Drive, etc.

electric_nan@lemmy.ml on 16 May 02:25 collapse

I use Nextcloud myself, but if people don’t want to host a server or fuck with syncthing, they can sync it however they want as long as they use a strong enough master password/phrase (which they should be anyway.).

tremble5218@programming.dev on 15 May 23:28 next collapse

Rclone with any cloud provider is another great option that’s seldom mentioned. I posted my setup as a comment on another post. You may find it here - programming.dev/comment/23849767

german@pawb.social on 16 May 00:06 next collapse

Merge conflicts are a concern for KeePass, especially for those that don’t want to resolve them. Sync is difficult. AFAIK this is a very common issue with Syncthing setups.

Also, the portability from Bitwarden to KP leaves a bit to be desired, though that’s probably 90% on BW.

elmicha@feddit.org on 16 May 02:57 next collapse

I’m using Keepass2Android (and KeepassXC). It can copy the database from/to an sftp server, so it can easily merge the entries. I don’t have the sftp server exposed to the Internet, because when I’m not home, nobody will change the database at home.

eli@lemmy.world on 16 May 04:48 next collapse

I’ve been using KeePass with Syncthing for 5+ years now and I think I’ve only had a sync issue once in all this time.

Granted I do make sure I only use the database on one device at a time (so not making edits on desktop and my phone at the same time) and I’m using XC and DX clients not the OG KeePass program.

I’m curious what is causing sync issues to make it “common”, I use my db every day.

german@pawb.social on 16 May 07:18 collapse

Yeah, it’s not an uncommon use case to accidentally or even intentionally edit the database on two online devices - I do it all the time when I want a new login to be used on my laptop right after I signed up for some new website on my PC, and the laptop just happens to have an “unpushed” change from last evening, or I edit the new login’s metadata, or whatever.

With this, I’d have to keep a mental model of the versioning of each database and avoid even touching my phone like the plague if KeePass is open on my computer.

It’s not that big of a deal, it’ll probably be a problem once every few months, but it’s annoying to keep track of and worth talking about.

eli@lemmy.world on 16 May 08:23 collapse

Hmm, I’ll have to play around with it a bit more then to see if I can trigger it.

My only gripe is the browser autofill. Sometimes it triggers correctly and sometimes it doesn’t. I’ve noticed if I let KeePass add in a new login itself after I’ve manually entered it then it’s much more receptive to suggesting that login correctly going forward. So I’m tempted to create a brand new database and login everything manually so KeePass will create the database entries itself to fix my gripe.

SeductiveTortoise@piefed.social on 16 May 13:20 collapse

I’m using KeeWeb on Mac and Windows and Keepass2Android on my Android device and I don’t have any issues at all. I’m storing in OneDrive though, this is the one thing I’m using it for still.

elaina@lemmy.zip on 16 May 02:55 next collapse

Yeah the performance is what made me install the desktop app, but then it’s 1gb in size

auntieclokwise@lemmy.world on 16 May 03:23 next collapse

I use KeePass with KeeAnywhere. KeePass can natively sync over network share, FTP, or WebDav. With plugins, it can sync over SSH, FTPS, Amazon S3 compatible buckets (including open source compatible versions you host yourself), Azure, Box, Dropbox, Google Drive, OneDrive, and more.

Resonosity@lemmy.dbzer0.com on 16 May 04:04 collapse

My first password manager was KeePassXC.

Hooked it up with Syncthing, and I’ve never had issues aside from the occasion database duplicate.

Flagstaff@programming.dev on 16 May 07:56 collapse

Right, and it has a neat merge-database feature anyway, so no excuses for those holding back!

Speculater@lemmy.world on 15 May 23:49 next collapse

I just got Bit warden this year! Gah. Where are we jumping?

testaccount789@sh.itjust.works on 16 May 00:09 next collapse

Full circle to sticky notes on monitor.

roofuskit@lemmy.world on 16 May 01:23 collapse

Vaultwarden

FreedomAdvocate@lemmy.net.au on 16 May 02:32 collapse

Maybe pay for one then?

aeiou_ckr@lemmy.world on 16 May 04:04 collapse

I pay for bitwarden for the yubi key support and I’m also tired of switching.

goatinspace@feddit.org on 15 May 20:48 next collapse

<img alt="" src="https://feddit.org/pictrs/image/a558cd21-8f5a-44f4-a49a-81ded8a21df3.gif">

SnotFlickerman@lemmy.blahaj.zone on 15 May 20:57 next collapse

This is why corporate promises can never be trusted, because a new CEO can change those promises on a whim.

It’s part of why despite being interested in Beeper, I never signed up for it because I had questions about if those privacy promises they made would be kept if they sold to a bigger company… which they eventually did.

On the plus side Bitwarden already made an official open source self-hosted version, which can be forked and/or return to the community developed Vaultwarden roots.

Meanwhile KeepassXC keeps on chugging along.

northernlights@lemmy.today on 15 May 22:44 collapse

FYI beeper is really just matrix with bridges. Once I realized that I set up my own and now I have the same functionalities as beeper, self hosted, with a choice of clients.

SnotFlickerman@lemmy.blahaj.zone on 15 May 22:49 collapse

Oh I was well aware at the time, but I had a lot of friends who still struggled with trying to use Matrix/Element so at the time I was seeking a simpler solution for them.

youcantreadthis@quokk.au on 16 May 01:56 collapse

How fucking stupid do you need to be to struggle with element do they struggle to use cups are they trying to do weird advanced features on an architecture I’ve never heard of with a compiler built themselves wtf

SnotFlickerman@lemmy.blahaj.zone on 16 May 02:02 collapse

Wow, usually people lose their shit and complain that Element is too complex and that me and the devs are being assholes asking them to use it… You know kind of like all the people here on the Fediverse who think we need to make it bigger and bring in everyone from everywhere and that the devs and users who defend them are awful for not focusing on user interface first and making it less confusing to choose a server…

Anyway, thanks for being on team reasonable, because I’m with you on this 100%, but I can’t change how little people want to learn anything sadly so I make compromises with people who cant or wont learn how to do things. It sucks, people really don’t seem to understand that security and convenience are a balance, and every time people argue for shit to be easier they’re actually arguing for everything to be less secure. You sacrifice security for convenience, every time, and the opposite happens because you can sacrifice convenience for increased security measures. Security has to be complex by nature to be effective, and the core of Matrix is being a secure, encrypted protocol, which they have already actually put a ton of work into making easier for fucking normies. Yet, it’s never enough for people. Always screams of “It’s too complex! I hate thinking!”

youcantreadthis@quokk.au on 16 May 02:05 collapse

The buttons are in a different place oh god so much blood yes I resized the window what’s your point

SnotFlickerman@lemmy.blahaj.zone on 16 May 02:09 collapse

lmao God I can feel the frustration rising in me just thinking about it. I know these are digital rather than physical objects… but do these people fail to have object permanence?

youcantreadthis@quokk.au on 16 May 05:13 next collapse

Not everyone is a tech nerd some of us just want our stuff to work stop asking us to be nerds too this is why everyone hates you fix it fix it fix it

youcantreadthis@quokk.au on 16 May 08:11 collapse

I feel like there’s a very real rejection of consciousness and self reflection I feel that as a strange person who doesn’t always accommodate defaults too its really depressing in a very real sense they’re rejecting personhood based on protest and and silicon valley propaganda of normalcy and frictionlessness

silentjohn@lemmy.ml on 15 May 20:58 next collapse

Every company is basically evil at this point.

iamthetot@piefed.ca on 15 May 21:26 next collapse

There is no ethical consumption under capitalism.

wheezy@lemmy.ml on 15 May 23:14 collapse

I think the rope they’re selling us might, one day soon, have a net positive impact.

grue@lemmy.world on 15 May 23:48 collapse

Since Dodge v. Ford Motor Co (1919), if not earlier.

See also: reclaimdemocracy.org/corporate-accountability-his…

TORFdot0@lemmy.world on 15 May 21:06 next collapse

Damn I guess I’m going back to keepass again since I am not really interested in hosting a vault

Grandwolf319@sh.itjust.works on 15 May 21:23 next collapse

Oh no, and I just setup Vaultwarden

deathbird@mander.xyz on 15 May 22:10 next collapse

I could care less that he removed inclusion, if that was all it was. But it got replaced by “innovation”, which coming from a guy who proudly lists his private capital ventures sounds like a dog whistle for figuring out how to fuck over customers.

Bad portents all around.

Stupendous@lemmy.world on 15 May 22:27 next collapse

Keepassxc and whatever I’m using off f droid for Android. Then is sync with proton drive. Works well for me. I do the same for my one time password backups. You don’t even need to pay for a subscription to proton. These are small files. Free version is good enough

Flagstaff@programming.dev on 15 May 22:35 next collapse

Yes, I use KeePassDX as well.

sync with proton drive

That’s not good enough. Stay entirely offline. Keep your own stuff in sync via Syncthing and Syncthing-Fork daisy chains, especially if they’re small files.

Cargon@lemmy.ml on 16 May 04:50 collapse

Has the sketchiness around the Syncthing fork hand-off get sorted?

Flagstaff@programming.dev on 16 May 07:52 collapse

I don’t know if their behavior over the transition was ever explained but at least it was legit, last I read.

ripcord@lemmy.world on 15 May 22:38 collapse

Right but fdroid is just about dead

akwd169@sh.itjust.works on 15 May 22:48 next collapse

Motherfuck!

sloppy_diffuser@sh.itjust.works on 15 May 22:59 next collapse

They responded on reddit and walked some of it back as an “oversight”: www.reddit.com/r/Bitwarden/comments/…/olznwcv/. Allegedly, I’m too lazy to verify.

blarth@thelemmy.club on 15 May 23:30 collapse

A change that would require intent to make is not a mistake or oversight.

This sucks. I committed to Bitwarden years ago and now am going to have to switch before they lock me in the garden.

german@pawb.social on 15 May 23:55 collapse

They also haven’t addressed the removal of inclusion and transparency from their goals.

EDIT: They did. They said it’s “less of a priority”. The article I shared has been updated. I smell corporate bullshit though. “Oversight” this, “priority shift” that, they’d have to work hard to gain any trust back.

blarth@thelemmy.club on 16 May 04:30 collapse
godsammitdam@lemmy.zip on 15 May 23:47 next collapse

Has Vaultwarden said anything yet? I imagine that, if necessary, given that bitwarden’s client is still open, at the point they choose to try and close it, we, the users, can fork it and establish it for vaultwarden, correct? Or, maybe even the vaultwarden team will think about forking it themselves and making a light client as well to pair with the current server.

But Vaultwarden can exist without “leeching” they just haven’t needed to yet. That’s more symbiotic than parasitic. The parasite class just took over Bitwarden after all.

german@pawb.social on 16 May 00:03 collapse

Not to my knowledge. As far as forks go, that’s true. However, Vaultwarden would need to become an independent team, and even if they don’t take over maintaining the client, someone else would need to become independent. While it can work, it can also lead to very nasty, longstanding bugs or security issues due to scale, budget, and effort. I see this a lot with Apple apps for example - smaller developers understandably don’t want to deal with Apple’s crap and costs, and everyone suffers in the end.

If you look at the current state of the cybersecurity world, it’s not kind to open-source developers. AI-generated BS is dredging up vulnerabilities on all sides. So security is also a big concern. Someone like Bitwarden has a lot of budget to swing.

Vaultwarden itself is incredibly good, but not perfect:

~~nvd.nist.gov/vuln/detail/CVE-2026-26012.~~

Edit: Bad example, point is security is a concern with a smaller team.

godsammitdam@lemmy.zip on 16 May 00:12 collapse

You’re right. And that’s why more of us need to contribute and spread the word of projects to support them.

Honestly, FOSS is our last bastion against this consumerist hellscape. I’m working on learning to build my own discord-like front end on matrix specifically for gaming. But I’m just one guy. We’ve all gotta pick where we place our effort and support those around us similarly.

Vaultwarden taking over bitwarden, should they shut doen as open source, I think would be entirely worthy. But it might need more people to either help vaultwarden or maintain it on their own, you’re right.

To me, seeing and learning about all of these projects gives me hope. All of these people and communities working to build things out of passion and dedication, because they care and want to provide value to others. No profit motive necessary. We just need to be there to support them as we’ve tied capital to our survival currently.

german@pawb.social on 16 May 00:26 next collapse

True dat. The more people know every corporation, even the most “wholesome chungus Reddit karma 100” ones ONLY care about squeezing profits out of you, the better off we’re going to be in the future.

Check out and contribute to gomuks. It’s the go-to power user Matrix client as I’ve learned. I recently developed a theme for it to make it look more like Cinny, which itself is a bit of a Discord UI Clone. I don’t actually use gomuks, but it really needed a nice theme.

FreedomAdvocate@lemmy.net.au on 16 May 02:26 collapse

Anyone that doesn’t understand that companies exist to make profit needs to be studied at this point. You have to wonder how they even function in the world.

People don’t go work 9-5 for the fun of it and for free, do they? No, a company and/or customers pay them. Without that payment step there’s no job and there’s no product/service.

If you don’t think the company deserves your money, find another free service and use that until they start charging. Rinse and repeat - or just be an adult and pay for services and work that you like and use.

german@pawb.social on 16 May 07:13 collapse

Are you genuinely unable to comprehend the concept of a company not doing evil things to make profit? You do realise I paid for it up until this point right? Thanks captain obvious for telling me I can stop paying for things.

I was fine with a price hike, I realise that paid users are subsidizing free ones and everything is getting more expensive. What I’m not fine with is the deception, shitty marketing, removal of “DEI-like” language, and a sudden clear lack of morality in the company. They lost my trust, anyone with a brain shouldn’t trust them either with their most precious online secrets.

And you call yourself a freedom advocate, then advocate for textbook enshittification which always leads to the removal of freedom lol, what a shill

quips@slrpnk.net on 16 May 02:08 collapse

What is your matrix front end called?

godsammitdam@lemmy.zip on 16 May 03:48 collapse

It doesn’t exist yet 😅 as I said, still learning and trying to avoid using AI as a lot of vibe coded discord clones popped up. I did compile a list (which probably needs updating)

github.com/…/discord-alternatives-wishlist

Fmstrat@lemmy.world on 16 May 00:30 next collapse

Vaultwarden can’t exist without “leeching” off of Bitwarden.

Why not? No reason mobile apps and browser extensions can’t be forked.

german@pawb.social on 16 May 00:32 collapse

pawb.social/comment/22239133

Fmstrat@lemmy.world on 16 May 11:50 next collapse

Well, yes, Vaultwarden would need more support, but that happens pretty frequently when a major provider enshitifies. Look at Godot, Lemmy, etc.

As for the CVE linked, BitWarden itself has many more: app.opencve.io/cve/?vendor=bitwarden

CVEs aren’t an indication of poor quality. Speed to resolution is. It’s not often devs themselves are finding CVEs, it’s the community.

At the core, regardless of what a C suiter does to the marketing, the state of the FOSS repos is what matters. Since they already walked back the “always free” comment this whole debate may be moot, so time will tell. Hopefully the rest of the company and the public sway them to continue to support it properly themselves.

german@pawb.social on 16 May 14:23 collapse

I suppose so. Maybe the corporate propaganda got to me about the security of smaller projects.

zipjo@lemmy.world on 16 May 14:37 collapse

The linked vulnerability has been fixed a day prior of being reported by the dev themself and it’s not an issue since then, it even sais so in the cve description.

deadcade@lemmy.deadca.de on 16 May 00:54 next collapse

Hoping for another Moonlight/Sunshine moment! Already running Vaultwarden, rbw, and Keyguard. Just need a simple FOSS browser extension for autofill and editing entries.

For context, Moonlight was created first as a FOSS Nvidea gamestream client. Then Sunshine was created as a FOSS server implementation. Later, Nvidia dropped “official” support, now the two projects are a FOSS stack built atop a formerly proprietary protocol.

Ulrich@feddit.org on 16 May 01:03 next collapse

I guess that explains the transition to AI coding as well

cow@lemmy.world on 16 May 01:04 next collapse

rbw is an unofficial CLI client which works with vault warden.

youcantreadthis@quokk.au on 16 May 01:54 next collapse

Everyone who used and shilled them deserves thus lol

FreedomAdvocate@lemmy.net.au on 16 May 02:28 collapse

Many of us already pay for it because it’s an amazing service that we appreciate and are happy to pay for.

Not everyone is a cheapskate who thinks they deserve other people’s hard work to not be rewarded.

irotsoma@piefed.blahaj.zone on 16 May 02:14 next collapse

Glad I started using Vaultwarden a while back. Just need to find better apps for android and Firefox I guess because I’m guessing they’re going to try to break compatibility.

hanrahan@slrpnk.net on 16 May 08:43 collapse

vauktwarden needs bitwarden though

irotsoma@piefed.blahaj.zone on 16 May 15:29 collapse

I mean at this point in its evolution, what parts does vaultwarden rely on from bitwarden? The clients, but there are alternatives like keyguard for Android devices. What other layers does it rely on, I actually have been trying to figure this out myself.

FreedomAdvocate@lemmy.net.au on 16 May 02:17 next collapse

No one is being “sold out” lol. Anyone using the free tier has had a great run with an amazing service without posting a cent. Can’t complain about that.

I already pay for Bitwarden as it’s a great service that brings a lot of value. I’m happy to pay for it, and have zero anger at a company wanting to make money from their product.

Others might disagree, but companies can’t exist without making money. It’s insane that there are somehow still people that don’t understand how business works.

My work just started giving out 6 sponsored family licenses per employee which is awesome, so I’ll actually get to stop paying for it for a while.

gusgalarnyk@lemmy.world on 16 May 03:27 collapse

Buddy, I don’t know if you’ve been living under a rock but everything a venture capitalist touches is enshittifying. You think any of these companies you’re reading headlines about are suffering to keep their doors open? When google locks down android or X starts including ads in Grok they’re doing it to keep the lights on? You think if Bitwarden started cutting free services and charging more the average employee is going to get a proportional raise to the new profits?

No. We’re not upset because we dont understand that a company needs to make money. We’re upset because we have basic pattern recognition skills and we understand the nature of late stage capitalism on wealth inequality (at least intuitively). This (likely) isn’t some smart business person coming in to balance the books, this is (likely) some rich asshole whose job is to kill the golden goose and sell it for parts before anyone catches on that you need it alive to produce eggs.

altphoto@lemmy.today on 16 May 02:36 next collapse

Ah shit. Here we go again!

osanna@lemmy.vg on 16 May 03:25 collapse

Can anyone say “Enshittification”!

altphoto@lemmy.today on 16 May 03:30 collapse

Enshitification coming right up!

DFX4509B@lemmy.wtf on 16 May 02:53 next collapse

Move to KeePassXC or its recent LLM-free fork while you still can, because at some point Bitwarden is going to try to go closed-source again.

MonkeMischief@lemmy.today on 16 May 04:41 collapse

Oh crap, how’s KeePass got an LLM involved‽ Time to look into this now…

I did find codeberg.org/ChiPass/ChiPass , but it looks like a very new project.

DFX4509B@lemmy.wtf on 16 May 04:44 collapse

This blog post goes over it.

hexagonwin@lemmy.today on 16 May 12:04 collapse

…actually seems quite reasonable.

adarza@lemmy.ca on 16 May 12:19 collapse

very much so.

palmtrees2309@lemmy.world on 16 May 02:58 next collapse

Vaultwarden here I come

auntieclokwise@lemmy.world on 16 May 03:08 next collapse

No, KeePass. Fully open source, no cloud involved in any way, unless you want something to sync your data (the server only ever sees your encrypted database - all encryption and decryption is done locally). You can also host your own sync server using any of a variety of different protocols.

palmtrees2309@lemmy.world on 16 May 03:09 next collapse

Ok thanks for the heads up

MonkeMischief@lemmy.today on 16 May 04:37 next collapse

@palmtrees2309@lemmy.world

Yep. Seconding this!

KeePass + Syncthing is the best.

Back up the database(s) regularly. (Syncthing can also retain x number of versions and things like that, but also do your own 3-2-1 backups.)

You can use something as simple as a Pi, or an old laptop, or even an old phone if you get creative, as an always-on syncthing server to keep them synchronized. KeePassXC even has a fancy integration with Firefox, so all you gotta do is unlock your database and click autofill on websites.

Edit: lmao seriously, not like I care but what’s there to downvote about this? 😂

auntieclokwise@lemmy.world on 16 May 04:42 next collapse

I use KeePass + KeeAnywhere. KeeAnywhere will sync with a wide variety of cloud storage providers. Or your own S3 data bucket server (can be self hosted or on Amazon), if you prefer. Does pretty much the same thing though with versioning. Auto filling in Firefox is done with KeePassHttp-connector on the Firefox side and the KeePassHTTP plugin in KeePass. Similar to what you describe.

eli@lemmy.world on 16 May 04:42 collapse

Yup, been doing this combo for 5-6 years now.

I use KeePassXC on desktop and KeePassDX on Android. No issues whatsoever.

I do have a NAS so that’s my “always on” device for Syncthing. Everything syncs up within like 10-15 seconds when a device connects.

I also use a key file as a pseudo 2FA that I keep on a flash drive, so you’d need my master password and my key file to unlock the database.

ttyybb@lemmy.world on 16 May 07:00 collapse

Going to need to work on migrating

mlg@lemmy.world on 16 May 09:16 collapse

I hate to break the news but the issue with Bitwarden is that the client sucks total ass, and there are no drop in 3rd party replacements for the browser plugin.

Been running Vaultwarden for a while now and even though the sync implementation is nice and clean, it’s just not worth the end user experience.

<img alt="" src="https://lemmy.world/pictrs/image/80b42cda-409a-42c1-843c-283d864c6a85.png">

<img alt="" src="https://lemmy.world/pictrs/image/bb6c28c4-7d3f-42f3-91db-30e83d12971e.png">

This is really dumb when compared to literally every other password manager, open source and enterprise which does a much better job of actually being a password manager and not a glorified encrypted text file.

I’m eventually going to switch back to KeePassXC and just suggest setting a master password with Firefox’s builtin password manager for everyone else who just wants a painless user experience and not have to deal with syncing vaults.

lechekaflan@lemmy.world on 16 May 03:12 next collapse

Once again, enshittification by the fucking suits.

Early on I decided to use only KeePass for full personal control instead of an online service. Didn’t regret making that decision.

qwestjest78@lemmy.ca on 16 May 03:18 next collapse

Fuck

Decronym@lemmy.decronym.xyz on 16 May 03:30 next collapse

Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

Fewer Letters More Letters
Git Popular version control system, primarily for code
IoT Internet of Things for device controllers
NAS Network-Attached Storage
SSH Secure Shell for remote terminal access
VPN Virtual Private Network

5 acronyms in this thread; the most compressed thread commented on today has 22 acronyms.

[Thread #295 for this comm, first seen 16th May 2026, 03:30] [FAQ] [Full list] [Contact] [Source code]

DisasterTransport@startrek.website on 16 May 04:49 next collapse

For once ADHD preventing me from completing a migration is a boon, I guess I’ll move back to keepass

Cyber@feddit.uk on 16 May 07:59 next collapse

My solution:

keepass.info/donate.html

(& yes, I’m linking to their donate page first)

hexagonwin@lemmy.today on 16 May 12:01 next collapse

why this over keepassxc?

aesthelete@lemmy.world on 16 May 16:19 collapse

Keep ass what though? /s

WorldsDumbestMan@lemmy.today on 16 May 09:02 next collapse

They all want all of the poor people dead. They are wagging war on us.

floquant@lemmy.dbzer0.com on 16 May 12:13 next collapse

All hail the new Chief Enshittification Officer!

wickedrando@lemmy.ml on 16 May 13:50 next collapse

i was just thinking this week with the passphrase addition how good bitwarden is and when will the other shoe drop. There it is.

Adderbox76@lemmy.ca on 16 May 15:43 next collapse

Goddammit. Why can’t we have nice things?

aesthelete@lemmy.world on 16 May 16:19 collapse

I’m going to have to just write my own one of these fucking things aren’t I?