In the latest episode of “they will always sell you out” - they sold you out! Who would’ve thought.

Hoping for a good alternative client to appear, the writing is on the wall. Vaultwarden can’t exist without “leeching” off of Bitwarden.

    • slate@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      35
      arrow-down
      4
      ·
      2 months ago

      KeePass isn’t going anywhere. They’re also dragging their feet on passkey support, so you might go with KeepassXC.

      • eightys3v3n@lemmy.ca
        link
        fedilink
        English
        arrow-up
        10
        arrow-down
        1
        ·
        2 months ago

        They also don’t effectively allow collaboration though, which is my cheif reason for using a cloud hosted password manager.

          • eightys3v3n@lemmy.ca
            link
            fedilink
            English
            arrow-up
            7
            arrow-down
            1
            ·
            2 months ago

            Sharing passwords between groups of people so everyone always has the up to date version. Not breaking the world if two people try to modify the same entry as some file syncing solutions do.

            • Flagstaff@programming.dev
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              4
              ·
              2 months ago

              Hmm, interesting, though isn’t that a fault of the organization not having an account-linking system so that each person could have their own credentials but can still access the unified content? This workaround seems… flimsy, unless I’m not picturing a legit scenario in which no other method is as good, or something.

              • Appoxo@lemmy.dbzer0.com
                link
                fedilink
                English
                arrow-up
                3
                ·
                2 months ago

                Sometimes it just makes sense to have a single team login.
                Licensing for instance where each user costs money and not all users need a dedicated account to look at something of which only 1% is of importance to them.

              • eightys3v3n@lemmy.ca
                link
                fedilink
                English
                arrow-up
                3
                ·
                2 months ago

                It’s the fault of my family organization or every company we use that my parent’s bank, Google, phone, laptop, etc don’t allow more than one set of credentials to access the same thing?
                It’s not just that we need to be able to share credentials the once a blue moon I need to help them by logging into their account?

                • Flagstaff@programming.dev
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  2 months ago

                  Wait, I don’t understand. Why do you need to do so much account-sharing? I never had half of that… and if connecting is just once in a blue moon, then it shouldn’t need something like group creds anyway, right?

              • FreedomAdvocate@lemmy.net.auBanned from community
                link
                fedilink
                English
                arrow-up
                2
                ·
                2 months ago

                You know why most cloud based services charge money? For stuff like this, because it’s not free to implement and maintain.

                Easy and fault-proof password sharing and syncing needs software and hardware to do. You either set it up and maintain it yourself, or pay for a product that does it - like Bitwarden.

                • Flagstaff@programming.dev
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  2 months ago

                  But your argument falls apart against something like Syncthing’s discovery networks combined with send-/receive-only folder types, which use no cloud yet allow the automatic, passive propagation of file updates to different users’ devices… right? No cloud, no self-hosting, yet automatic syncing across multiple devices…

        • Lka1988@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          2 months ago

          KeePass isn’t meant to be used that way. It’s a personal password manager. Always has been.

          • eightys3v3n@lemmy.ca
            link
            fedilink
            English
            arrow-up
            4
            ·
            2 months ago

            Valid. But it’s also valid that it now doesn’t work for me or anyone who also helps manage other people’s lives or works on a team ¯_(ツ)_/¯

            • Lka1988@lemmy.dbzer0.com
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              1
              ·
              2 months ago

              Gotta use the right tool for the job. Sorry KeePass doesn’t work for you. It really is a fantastic piece of software.

        • frongt@lemmy.zip
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          2
          ·
          2 months ago

          Sure they do. Multiple people can have a file open at the same time. I use it for exactly this every day at work.

          With KeePassXC, that is. I don’t know if other flavors have different support. I use XC primarily for the browser extension.

          • eightys3v3n@lemmy.ca
            link
            fedilink
            English
            arrow-up
            3
            ·
            2 months ago

            And you can both modify the same things without causing horrible conflict issues? And you can share only parts of your vault with someone rather than having entirely different vaults you have to switch between? I’m assuming you mean putting the file somewhere like Google Drive, and you can access it offline even if you can’t edit it offline? For feature parity with Bitwarden, obviously ideally one could edit any time and it would resolve problems when it came back online if there were any but Bitwarden doesn’t allow this.

            • frongt@lemmy.zip
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              2
              ·
              2 months ago

              Yes, no conflicts. I don’t know if you can only share part of vault; I just created a separate one for a separate team.

              I wouldn’t put it in Google Drive or anything like that. The separate sync logic will definitely cause conflicts.

              I’m not worried about having access if I’m offline, because if I’m offline I’m not going to be able to log into anything anyway.

              • eightys3v3n@lemmy.ca
                link
                fedilink
                English
                arrow-up
                3
                ·
                2 months ago

                I guess a laptop, server, IoT device, or WiFi connection when your main device doesn’t have internet is out of scope for you?
                Like fixing my laptop and not wanting to type the new password into my phone instead of copy/paste, sync when online?
                And how are you sharing a file, to multiple people anywhere in the world realtime ish, without a cloud service you or someone else hosts? Doesn’t that necessitate some syncronization logic?

                • frongt@lemmy.zip
                  link
                  fedilink
                  English
                  arrow-up
                  2
                  arrow-down
                  2
                  ·
                  2 months ago

                  It’s hosted on a local network share, so we don’t need Internet access.

                  If can’t copy paste, I just type it out.

                  We use a VPN to the office.

        • 4am@lemmy.zip
          link
          fedilink
          English
          arrow-up
          25
          arrow-down
          6
          ·
          2 months ago

          Two articles behind a paywall, one that won’t load, and another article that says the big problem with passkeys is…people are unfamiliar with them.

          If anyone tells you that Passkeys are bad, they’re a liar. Way more safe than passwords, full stop.

          Just don’t let Microsoft or Apple tie them to your device. You don’t have to do that.

          • Flagstaff@programming.dev
            link
            fedilink
            English
            arrow-up
            8
            arrow-down
            2
            ·
            2 months ago

            Are you calling me a liar? That’s pretty weird; it’s not like I’m telling you to stick to passwords while I move to passkeys. With that said, though, get Bypass Paywalls Clean (Mozilla-only, as far as I know) and you’ll never see another paywall again. I forgot about having that.

            Just don’t let Microsoft or Apple tie them to your device. You don’t have to do that.

            The problem is that this is where it’s eventually going to lead to.

            • fushuan@piefed.blahaj.zone
              link
              fedilink
              English
              arrow-up
              4
              arrow-down
              1
              ·
              2 months ago

              Not really, Vaultwarden/bitwa4den offer passkey support. When I log into a service a popup shows on my extension, I click it and I’m in. It’s not gonna lead to device locking if you don’t want to…

              • WhyJiffie@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                2
                ·
                2 months ago

                except when the wide populace starts accepting it being device locked, and your opinion does not matter anymore to those making the decisions

                • fushuan@piefed.blahaj.zone
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  2 months ago

                  No one of the people I know that use passkeys use it from the phone, either they use a password manager, they have passwords on a physical note, on an excel file in the desktop, a physical yubikey, or bitwarden like me. That’s everyone I physically know including every family member, friends and work people.

                  I know it’s anecdotal, but you present your “wide populace” fact without giving sources too, and since I know no one that uses phone based passkeys, even if my experience is anecdotal, I say sus. Check your bias.

            • Lemmert@reddthat.com
              link
              fedilink
              English
              arrow-up
              5
              arrow-down
              2
              ·
              2 months ago

              At the very least you’re misguided or don’t know what you’re talking about. Passkeys are not vendor locked in and of themselves.

              You can make the same argument against password managers because most iPhone users that use them, use Apple’s one.

              • qqq@lemmy.world
                link
                fedilink
                English
                arrow-up
                7
                arrow-down
                1
                ·
                edit-2
                2 months ago

                They will almost certainly lead to vendor lock in. Why do you think they won’t? Apple’s password manager is definitely an example of vendor lock in. Many others have a simple to use export feature to CSV or something that others can understand

                Edit: it could be that you don’t know what the WebAuthn/FIDO2 specification says or we understand it differently? Do you know how the attestation mechanism works? That ties the key to a device or software authenticator (the software authenticator is likely going to tie it to the device somehow, possibly even via a TEE).

          • qqq@lemmy.world
            link
            fedilink
            English
            arrow-up
            4
            arrow-down
            1
            ·
            2 months ago

            There is no full stop there… A password that is sufficiently long will never be cracked no matter the hashing algorithm in use. Passwords are easily transferrable and can be communicated to a third party in the event of an emergency. They also provide tunable security, where you can trade off security for convenience if you want.

            Some (not all, I know) passkeys are tied to a device. Stolen device means stolen passkey, and it’s potentially very difficult to recover from that. Passkeys are also locked to a certain standard, passwords have no such restrictions.

            Tbh I don’t understand the move for passkeys replacing passwords. They should become the second factor when a user wants additional security. They’re perfect for that niche.

            • captcha_incorrect@lemmy.world
              link
              fedilink
              English
              arrow-up
              4
              ·
              2 months ago

              Passkeys provide a secure way to authenticate while also being convenient. With the tradeoffs you mentioned.

              I don’t like the push for only allowing some vendors to issue keys and to not allowing exporting and backups. And password should still be an option.

            • fatalicus@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 months ago

              Password can also very easily be stolen during phishing, while passkeys are phishing resistant.

              And while a hardware passkeys can be stole and used, those who steal them will still need the pin to use them, and the two major hardware passkeys options now (Yubico and Token2) both have some pin brute force protection in their firmware to slow someone down long enough for an account to be secured another way.

              As for passkeys on phones, they require the pin or biometric used to unlock the phones to be used.

              • qqq@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                2 months ago

                “Difficult to recover from” was referencing setting all of your accounts back up. I should have also included “lost” and “broken” to make that more obvious. Many hardware (most? all?) passkeys do not allow for backup and restore.

                But I do see an issue with stolen hardware passkeys being used for access too if they’re a primary factor. With the mitigations you mentioned hopefully holding up.

    • bordam@feddit.it
      link
      fedilink
      English
      arrow-up
      2
      ·
      2 months ago

      Password Store is the answer, if you don’t need passkey support. You can be sure it can’t be sold. It’s the golden middle: not self hosted, but not owned by anyone.

  • Shortstack@reddthat.com
    link
    fedilink
    English
    arrow-up
    101
    ·
    2 months ago

    That’s troubling, I don’t like what this portends.

    The new CEOs background especially suggests they’re spiffing up the company for a later sellout, why else would they pick a merger specialist for the role?

  • Otter@lemmy.ca
    link
    fedilink
    English
    arrow-up
    77
    ·
    2 months ago

    I think the original title was more helpful because it shows that this is a recent development. Maybe you can add “new CEO”?

    Bitwarden scrubs ‘Always free’ and ‘Inclusion’ values from its website as longtime execs step down

    In February, longtime CEO Michael Crandell moved to an advisory role, according to LinkedIn, with no announcement from the company. His replacement, Michael Sullivan, former CEO of both Acquia and Insightsoftware, touts his experience with “all facets of mergers and acquisitions” on his own LinkedIn page, including experience working with leading private equity firms.

    CFO Stephen Morrison also left Bitwarden in April, replaced by former InVision CEO Michael Shenkman. Both Crandell and Morrison joined the company in 2019. Kyle Spearrin, who started Bitwarden as a fun hobby project in 2015, remains the company’s CTO.

  • John@lemmy.ml
    link
    fedilink
    English
    arrow-up
    54
    arrow-down
    3
    ·
    2 months ago

    Every company is basically evil at this point.

  • godsammitdam@lemmy.zip
    link
    fedilink
    English
    arrow-up
    40
    ·
    2 months ago

    Has Vaultwarden said anything yet? I imagine that, if necessary, given that bitwarden’s client is still open, at the point they choose to try and close it, we, the users, can fork it and establish it for vaultwarden, correct? Or, maybe even the vaultwarden team will think about forking it themselves and making a light client as well to pair with the current server.

    But Vaultwarden can exist without “leeching” they just haven’t needed to yet. That’s more symbiotic than parasitic. The parasite class just took over Bitwarden after all.

    • German The Jackal@pawb.socialOP
      link
      fedilink
      English
      arrow-up
      8
      ·
      edit-2
      2 months ago

      Not to my knowledge. As far as forks go, that’s true. However, Vaultwarden would need to become an independent team, and even if they don’t take over maintaining the client, someone else would need to become independent. While it can work, it can also lead to very nasty, longstanding bugs or security issues due to scale, budget, and effort. I see this a lot with Apple apps for example - smaller developers understandably don’t want to deal with Apple’s crap and costs, and everyone suffers in the end.

      If you look at the current state of the cybersecurity world, it’s not kind to open-source developers. AI-generated BS is dredging up vulnerabilities on all sides. So security is also a big concern. Someone like Bitwarden has a lot of budget to swing.

      Vaultwarden itself is incredibly good, but not perfect:

      ~~https://nvd.nist.gov/vuln/detail/CVE-2026-26012.~~

      Edit: Bad example, point is security is a concern with a smaller team.

      • godsammitdam@lemmy.zip
        link
        fedilink
        English
        arrow-up
        13
        arrow-down
        1
        ·
        2 months ago

        You’re right. And that’s why more of us need to contribute and spread the word of projects to support them.

        Honestly, FOSS is our last bastion against this consumerist hellscape. I’m working on learning to build my own discord-like front end on matrix specifically for gaming. But I’m just one guy. We’ve all gotta pick where we place our effort and support those around us similarly.

        Vaultwarden taking over bitwarden, should they shut doen as open source, I think would be entirely worthy. But it might need more people to either help vaultwarden or maintain it on their own, you’re right.

        To me, seeing and learning about all of these projects gives me hope. All of these people and communities working to build things out of passion and dedication, because they care and want to provide value to others. No profit motive necessary. We just need to be there to support them as we’ve tied capital to our survival currently.

        • German The Jackal@pawb.socialOP
          link
          fedilink
          English
          arrow-up
          3
          ·
          2 months ago

          True dat. The more people know every corporation, even the most “wholesome chungus Reddit karma 100” ones ONLY care about squeezing profits out of you, the better off we’re going to be in the future.

          Check out and contribute to gomuks. It’s the go-to power user Matrix client as I’ve learned. I recently developed a theme for it to make it look more like Cinny, which itself is a bit of a Discord UI Clone. I don’t actually use gomuks, but it really needed a nice theme.

          • FreedomAdvocate@lemmy.net.auBanned from community
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            2
            ·
            2 months ago

            Anyone that doesn’t understand that companies exist to make profit needs to be studied at this point. You have to wonder how they even function in the world.

            People don’t go work 9-5 for the fun of it and for free, do they? No, a company and/or customers pay them. Without that payment step there’s no job and there’s no product/service.

            If you don’t think the company deserves your money, find another free service and use that until they start charging. Rinse and repeat - or just be an adult and pay for services and work that you like and use.

            • German The Jackal@pawb.socialOP
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              1
              ·
              2 months ago

              Are you genuinely unable to comprehend the concept of a company not doing evil things to make profit? You do realise I paid for it up until this point right? Thanks captain obvious for telling me I can stop paying for things.

              I was fine with a price hike, I realise that paid users are subsidizing free ones and everything is getting more expensive. What I’m not fine with is the deception, shitty marketing, removal of “DEI-like” language, and a sudden clear lack of morality in the company. They lost my trust, anyone with a brain shouldn’t trust them either with their most precious online secrets.

              And you call yourself a freedom advocate, then advocate for textbook enshittification which always leads to the removal of freedom lol, what a shill

    • blarth@thelemmy.club
      link
      fedilink
      English
      arrow-up
      49
      ·
      2 months ago

      A change that would require intent to make is not a mistake or oversight.

      This sucks. I committed to Bitwarden years ago and now am going to have to switch before they lock me in the garden.

      • German The Jackal@pawb.socialOP
        link
        fedilink
        English
        arrow-up
        36
        arrow-down
        2
        ·
        edit-2
        2 months ago

        They also haven’t addressed the removal of inclusion and transparency from their goals.

        EDIT: They did. They said it’s “less of a priority”. The article I shared has been updated. I smell corporate bullshit though. “Oversight” this, “priority shift” that, they’d have to work hard to gain any trust back.

      • Lka1988@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        6
        arrow-down
        2
        ·
        edit-2
        2 months ago

        When someone says “use KeePass”, we generally mean ”use an app based on KeePass".

        Personally, I use the OG KeePass (work laptop), KeePass XC (all personal machines), Keepass2Android (personal Pixel), and Keepassium (work iPhone).

        Whichever one you use is entirely subjective. Also, XC wouldn’t exist without the OG KeePass, so maybe don’t be a tribal weird-ass over it.

        • youmaynotknow@lemmy.zip
          link
          fedilink
          English
          arrow-up
          3
          ·
          2 months ago

          I’ve been wanting to move to KeePass from my current vaultwarden. What’s the most seamless way to synchronize the DB across GrapheneOS and Arch?

          I trust Syncthing for syncing files, but it kind of feels insufficient for an actual encrypted database.

          What works for you for syncing?

          • Lka1988@lemmy.dbzer0.com
            link
            fedilink
            English
            arrow-up
            2
            arrow-down
            1
            ·
            2 months ago

            The encrypted database is a file. Syncthing handles it perfectly fine. KeePass’ protocol has versioning and merge support built right in, so all of the KeePass variants work great with each other without issues over Syncthing.

            Just make sure you’re not editing the database on multiple machines at the same time - that’ll cause merge conflicts.

            • youmaynotknow@lemmy.zip
              link
              fedilink
              English
              arrow-up
              1
              ·
              2 months ago

              Thanks, that was exactly what was happening, at least in some cases. I was modifying icons on my laptop while messing with the templates on my phone.

      • SayCyberOnceMore@feddit.uk
        link
        fedilink
        English
        arrow-up
        2
        ·
        2 months ago

        Personally, I use a plugin for passphrases and - last time I looked - the other forks didn’t handle them.

        Does keepassxc support plugins now?

        On my phone, I use KeePassDX from F-Droid and KeePassDroid (Not sure if that’s being maintained at the moment?)

        The main point is; we need to support open source developers, so pick an open-source solution and contribute, donate, etc.

  • wickedrando@lemmy.ml
    link
    fedilink
    English
    arrow-up
    24
    ·
    2 months ago

    i was just thinking this week with the passphrase addition how good bitwarden is and when will the other shoe drop. There it is.

    • Lka1988@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      2 months ago

      Keepass (all variants and forks) has a passphrase generator, been built-in for years.

      The writing is on the wall for BW, and has been for quite some time now.

  • DFX4509B@lemmy.wtf
    link
    fedilink
    English
    arrow-up
    25
    arrow-down
    1
    ·
    2 months ago

    Move to KeePassXC or its recent LLM-free fork while you still can, because at some point Bitwarden is going to try to go closed-source again.

        • Lka1988@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          9
          arrow-down
          1
          ·
          2 months ago

          Yeah, I’m no fan of slopcoding either, but this policy addresses those who contribute AI-generated code; it is most certainly not “our devs are shipping AI slopcode”.

          Seems a lot here missed this part:

          All code submissions go through a rigorous review process regardless of the development workflow or submitter.

          Linus Torvalds does the same thing with the Linux kernel. He gets AI-generated slopcode submissions all the time. They’re reviewed by real people, and like most submissions Linus gets, sloppy work is rejected, AI and human alike.