I actually find this somewhat understandable; and I'll be continuing my subscription; as long as all source continues to be available and personal self-hosting remains a viable option.

Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.

Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.

It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.

I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.

I was at redis when they changed the license (the first time). I begged the new leadership to not change the core license but to do a few things instead.

1) bundle the "source available" modules as part of redis source distribution 2) enable people who only want bsd code to be able to build a "redis_core" 3) commit to the community that the core will remain BSD licensed and that they are committed to making it the best key/value store. 4) increase the amount of source available code that until then had been kept closed (including what we called big redis/RedisOnFlash/MultiTier) 5) Require anyone using the redis trademarks in a commercial setting to ship the entire Redis (which includes the source available portions, so Amazon et al would no longer be able to use the Redis trademarks without a license deal.

Another alternative was to simply go to AGPL (which they went to anyways awhile later).

I failed to convince the leadership about this. I honestly think they squandered huge value in community engagement, but perhaps that's what they wanted. I left a bit after these changes were made as it became clear that the new US led leadership of the company wasn't particularity interested in what was the soul of redis. (previously was heavily Israeli led and a critical mass there was invested in redis as an open source product).

Funny story, the then new/current CEO used to be the head of WebEx at Cisco. We had a Q&A when he was hired and I asked, what did he learn from his time at WebEx about how to maintain market position (as they lost everything to zoom et al). His response at the time wasn't that convincing, but I was willing to give him the benefit of the doubt. I feel its fair to ask if the same thing occurred again.

Thank you for trying to do something to prevent it, many people wouldn't bother.

> His response at the time wasn't that convincing, but I was willing to give him the benefit of the doubt. I feel its fair to ask if the same thing occurred again.

Business will have to try different things at different points due to external & internal pressures. Some decisions are reversible (at cost), some aren't. Decisions (chaotic / complex / complicated ones, at least) are not made merely based on available data and analysis, but also based on intuition, experiments, and predictions. Then, to look at the outcome rather than the process is missing the point. When the circumstance / situation isn't clear-cut, the feedback (the outcome of a decision) is in itself more valuable to the organization (than never having taken the decision, at all), especially when the costs (to reverse / change it) are bearable.

I’m conflicted. On one hand I’m grateful for the years of trustworthy (and pay-what-you-want) password management. On the other this feels like an attempt to EEE the free version.

That's my concern as well. I have no problem with the current license change if they continue to publish all the code as they claim. My concern is that this is usually step 1 in a boil-the-frog strategy to eventually split and break off enterprise features. I'll give them some trust until they give me a reason not to (I think they've earned it), but the concern remains.

They don't?

"Some future components will be published under the commercial license and will exist only in that build."

(From that thread)

I would be with you if they didn't change the owner to private equity in the last year.

Wasn’t it just a minority stake?

The thing I always think about is that they wouldn't have to change the license and tighten the screws if people paid for it. Getting mad that the free hosted password manager has changed the deal a little bit I find to be quite arrogant.

Pay the $20/yr or whatever to have them host it and the whole world keeps turning.

Hosted password manager is equivalent to publishing all your passwords outright.

Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all.

you have no idea how bitwarden works, do you...

by that logic, every time you send a password over a TLS connection, you're publishing it outright too

People are going to try much harder to break into the main Bitwarden servers than they are my little Vaultwarden instance. Plus, I have the ability to lock it behind a VPN so it isn't even publicly exposed.

But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.

I'm not sure where your sentiment comes from here.

> But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.

A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me. I much prefer 1Password's approach where they have a usually-hidden second secret (the "Secret Key") that both (A) isn't shown unless you're setting up another device, and (B) acts as extra data needed to form the decryption key for your vault.

The main threat model I'm thinking of protecting against is a 1password vault data breach of some kind (or possibly cooperation with government agencies) + password exposure in some way (be it from CCTV-extracted password entries, over-the-shoulder watching, etc), as even with both of those factors, they would somehow need to get your secret key to decrypt vaults.

Like, all of those lastpass vaults obtained during the Lastpass hack would be de-facto useless even with a correct password if their design included some sort of hidden secret secret.

Are you aware of Yubikeys?

I'm not sure that calculus is going to be true for much longer – with the costs of AI falling, it's going to be much easier to throw tokens at the problem even tiny targets that wouldn't have been worth it before. Can you guarantee your VPN is patched and secure at all times?

Can you guarantee the hosted servers are patched and secure at all times?

I took it to mean non-self hosted is like publishing your passwords online, which I agree with.

AI will do it

I mean, no it's absolutely nothing like "publishing all your passwords outright" but fine. Pay the $20/yr and don't have them host it, host it yourself. Just pay them the $20.

Your comment is generally ignorant on infosec.

Do you have a quantum computer from the future and a file of passwords that haven't been changed in 50 years? Complete nonsense.

Sorry but the elasticsearch thing was a big stupid take of elastic. It was big corpo against big corpo not the poor elastic company.

Changing licenses is a sick move and companies doing that should be fucked over, because the license made them big. Changing it later on means that they got greedy nothing more nothing less.

Without oss bitwarden would be a paid cloud like all the others that probably would’ve had a hard time getting trusted.

> Changing it later on means that they got greedy nothing more nothing less.

Or just trying hard to keep the company afloat?

Just because they published Open Source code at some point, you feel that you're entitled to free updates for the rest of your life?

elastics cloud offering was awful

That's not what's happening here. They're making their app closed source with closed source features. Time to find a new provider.

Per their public discussion on the topic, the non-OSS licenses will still be public and accessible for review.

We’ve seen it countless times over the last decade. OpenSolaris was the first big one. The open source side isn’t going to change, it’ll just get abandoned. They’re committed to open source… for now. Nothing is going to change… for now. They’ll maintain compatibility with compatible servers… for now.

Everything will get chipped away piece by piece. It’s been happening continuously for well over a decade at this point and everyone should understand the strategy by now.

Of course. There's never any free lunch. There's always a cost to software development. Just sometimes the cost gets shifted in a way that's beneficial to the general public. But it never lasts.

At least with bitwarden, if the value they're trying to extract becomes more than the product is worth, in terms of real cost, lockin or transparency, at least the code is open now and for the foreseeable future. And when it comes time to fork it, AI will make it easier for the future maintainer(s) to keep the fork alive at minimal expense.

[flagged]