RyanL Bitwarden Employee

Hello everyone!

Starting in the next release, the Bitwarden apps published to the various stores will be the commercially licensed builds. No action is needed, and the apps will work exactly as they do today.

Bitwarden remains committed to open source security and transparency
The GPLv3 OSS licensed version continues to be updated and published on GitHub
All current features are available in both versions
License details are on GitHub
Bitwarden remains committed to a robust, free forever plan for everyone

If you have any questions, please ask them in this thread. Thanks all!

EDIT:

Bitwarden is not going closed-source
You can still fork Bitwarden
No change to self-hosting, the licensing change affects those who are repackaging and reselling Bitwarden
The free plan is here to stay permanently
  • lemmyvore@feddit.nl
    link
    fedilink
    English
    arrow-up
    1
    ·
    6 hours ago

    The current FOSS backend used to be the center of the ecosystem. Going forward that may change. If it stops being that center and it becomes merely a token offering so Bitwarden can claim “we’re still doing FOSS” then it will become pointless.

    Simply forking the backend is meaningless without the work to also drag along the entire ecosystem, or establish a new one. Forking a project takes time, effort, vision, persistence, determination.

      • lemmyvore@feddit.nl
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 hours ago

        Both backend and frontend revolve around the API, and Bitwarden owns that not Vaultwarden.

        If Bitwarden decides to modify the API so that only their closed-source backend has the full spec, and only gives that spec to their own apps, everything else (Vaultwarden and 3rd-party apps) will fall behind or become unusable.

        To counter that, Vaultwarden and the 3rd-party apps need to declare their own API and prepare to fly solo completely independently from Bitwarden.

        Such a move would force Bitwarden to show their true colors. If they really mean to stay true to the open version they will keep cooperating and keeping their API in sync with the Vaultwarden API.

          • lemmyvore@feddit.nl
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 hour ago

            If there are two version of Bitwarden backend (closed and FOSS), and the closed one changes its API, and the closed Bitwarden apps also switch to the closed API, then what value does the FOSS API have anymore?

            • nibbler@discuss.tchncs.de
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 hour ago

              What is “the API”?

              The API is implemented by the bitwarden back end.

              The API is also implemented by the vaultwarden back end.

              The open source bitwarden client does talk the current version of this API. The open source client can be forked, so there is without much effort a version speaking this protocol in this version and is FOSS. Just the name will be different. I guess “vaultwarden client” would be fitting, but what ever.

              • lemmyvore@feddit.nl
                link
                fedilink
                English
                arrow-up
                1
                ·
                54 minutes ago

                What is “the API”?

                Good question. When you have multiple implementations of an API, the API (the authoritative version) is what gives the reference spec that all other apps must follow.

                If the authoritative version will be fully implemented only by the closed backend and in the closed apps, it will cripple the FOSS backend and apps.

                This is a common tactic used by companies that want to sideline the FOSS options and slowly make them irrelevant.

                Yes, today all apps talk to both Bitwarden and Vaultwarden the same way. Be on the lookout in case that changes.

                • nibbler@discuss.tchncs.de
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  39 minutes ago

                  I’d totally see the risk if the clients were not available as open source. But they are. So I’m not.

                  They might diverge, but vaultwarden users will just fork. Nobody who is using official clients with vaulwarden will be “oh dang, now I have to buy bitwarden, so long vaulwarden, was fun…”