In the latest episode of “they will always sell you out” - they sold you out! Who would’ve thought.

Hoping for a good alternative client to appear, the writing is on the wall. Vaultwarden can’t exist without “leeching” off of Bitwarden.

  • deadcade@lemmy.deadca.de
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 months ago

    Hoping for another Moonlight/Sunshine moment! Already running Vaultwarden, rbw, and Keyguard. Just need a simple FOSS browser extension for autofill and editing entries.

    For context, Moonlight was created first as a FOSS Nvidea gamestream client. Then Sunshine was created as a FOSS server implementation. Later, Nvidia dropped “official” support, now the two projects are a FOSS stack built atop a formerly proprietary protocol.

    • baduhai@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      It can, but vaultwarden, as it currently is, is an implementation of the server only. So if bitwarden decides to go closed source all the way, they’d haver to start either creating their own clients or fork the current bitwarden clients.

  • Shortstack@reddthat.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 months ago

    That’s troubling, I don’t like what this portends.

    The new CEOs background especially suggests they’re spiffing up the company for a later sellout, why else would they pick a merger specialist for the role?

    • mlg@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      I hate to break the news but the issue with Bitwarden is that the client sucks total ass, and there are no drop in 3rd party replacements for the browser plugin.

      Been running Vaultwarden for a while now and even though the sync implementation is nice and clean, it’s just not worth the end user experience.

      This is really dumb when compared to literally every other password manager, open source and enterprise which does a much better job of actually being a password manager and not a glorified encrypted text file.

      I’m eventually going to switch back to KeePassXC and just suggest setting a master password with Firefox’s builtin password manager for everyone else who just wants a painless user experience and not have to deal with syncing vaults.

    • Lka1988@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      BW news dropped, so you’re going to move to something that still requires the BW app?

      Circular logic, friend. Ditch everything related to BW. Move to a truly open password manager like KeePass (including its various forks).

    • auntieclokwise@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      No, KeePass. Fully open source, no cloud involved in any way, unless you want something to sync your data (the server only ever sees your encrypted database - all encryption and decryption is done locally). You can also host your own sync server using any of a variety of different protocols.

      • MonkeMischief@lemmy.today
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 months ago

        @palmtrees2309@lemmy.world

        Yep. Seconding this!

        KeePass + Syncthing is the best.

        Back up the database(s) regularly. (Syncthing can also retain x number of versions and things like that, but also do your own 3-2-1 backups.)

        You can use something as simple as a Pi, or an old laptop, or even an old phone if you get creative, as an always-on syncthing server to keep them synchronized. KeePassXC even has a fancy integration with Firefox, so all you gotta do is unlock your database and click autofill on websites.

        • auntieclokwise@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          3 months ago

          I use KeePass + KeeAnywhere. KeeAnywhere will sync with a wide variety of cloud storage providers. Or your own S3 data bucket server (can be self hosted or on Amazon), if you prefer. Does pretty much the same thing though with versioning. Auto filling in Firefox is done with KeePassHttp-connector on the Firefox side and the KeePassHTTP plugin in KeePass. Similar to what you describe.

        • eli@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          3 months ago

          Yup, been doing this combo for 5-6 years now.

          I use KeePassXC on desktop and KeePassDX on Android. No issues whatsoever.

          I do have a NAS so that’s my “always on” device for Syncthing. Everything syncs up within like 10-15 seconds when a device connects.

          I also use a key file as a pseudo 2FA that I keep on a flash drive, so you’d need my master password and my key file to unlock the database.

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    3 months ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    IoT Internet of Things for device controllers
    SSH Secure Shell for remote terminal access
    VPN Virtual Private Network

    3 acronyms in this thread; the most compressed thread commented on today has 20 acronyms.

    [Thread #295 for this comm, first seen 16th May 2026, 03:30] [FAQ] [Full list] [Contact] [Source code]

    • Bluegrass_Addict@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      yeah fuck that… fuck subscriptions ALL OF THEM. fucn these companies, ALL OF THEM.

      stop giving any of these pricks any slack. none of them deserve it, nor money.

      today it’s 1.65… tomorrow it’s 4.99… next week it’s 12.99… stop being a mindless sheep giving them any sort of leeway. you’re enabling the scammers to literally scam you more, and more and more.

      I’m relocating all my shit right now because we’ll… fuck em. I am loyal to NO COMPANY. none of them deserve anything but bankruptcy at a minimum.

      • hellmo_luciferrari@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 months ago

        I am totally in line with not agreeing with everything being a subscription. And I absolutely dont agree with subscription creep.

        So I minimize what I pay for. And let me say, in no means am I defending the change in Bitwarden here. I would never.

        It isn’t a realistic expectation to expect any hosted service to be free. Especially in capitalism. Someone will come along and fuck with pricing.

        Not everyone has the time, knowledge, or finances to fund self hosting everything.

        But to automatically assume everyone is a sheep for using a service that benefits them is a bit of a jump.

        Yes, I myself value privacy, security, and the merits of self hosting as much as I can with my resources. And I have had conversations with people on these topics, and there are the folk that lack the understanding of the importance of the hill many of the folk like me stand on. So I have seen the wide spectrum of people who pay for services.

        Wild take dude.

        yAlL aRe ShEeP blah blah blah…

      • irmadlad@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 months ago

        today it’s 1.65… tomorrow it’s 4.99… next week it’s 12.99… stop being a mindless sheep giving them any sort of leeway. you’re enabling the scammers to literally scam you more, and more and more.

        ‘Mindless sheep’. That’s hilarious. But I get it. Nobody likes to pay for shit.

          • irmadlad@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            3 months ago

            It’s not ‘out of touch’. It’s paying for (if it comes to that) a service that houses all of my business accounts, investment accounts, personal accounts, etc, and all with a pretty damn good track record. As with any technology, you must constantly evaluate it to see if what you are spending is justified for the service you are receiving. If at such time I feel the service isn’t worth the price, then sure. As of now, it’s not really an issue to me.

              • irmadlad@lemmy.world
                link
                fedilink
                English
                arrow-up
                0
                ·
                3 months ago

                It’s not acknowledging that part which seems out of touch.

                I assure you, I am fully cognizant of what for-profit corporations do. It’s one of the reasons I turned off the TV over two decades ago. There just wasn’t any ROI for me.

      • iamthetot@piefed.ca
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 months ago

        I’ve cut down my subscriptions by a lot over the past few years, and I’ve gotten very close to what I consider a minimum. Whenever possible, I like to buy outright.

        However, surely you can understand how not every product can function as a one time purchase. For something like a password manager, they are providing an ongoing service. They are storing and serving your data.

        You can self host, sure, and I’m doing a lot of that lately. But not everyone has the capacity or desire to.

        All that said, this leadership shakeup is concerning and I think I’ll be migrating to Proton, since I already have a Duo plan.

        • Flagstaff@programming.dev
          link
          fedilink
          English
          arrow-up
          0
          ·
          3 months ago

          You don’t need to self-host at all! Daisy-chain your needed files via Syncthing and Syncthing-Fork. That’s literally what I do with KeePassXC and KeePassDX, keeping everything offline.

    • TheTrueColonel@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      Funny thing is I clicked the link and “Always free.” was gone. Refreshed the page and it was back. Definitely something going on.

    • phx@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      Yeah it’s not about not paying for me, it’s about being able to host my own with my protections and controls

      • irmadlad@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 months ago

        That is totally awesome and cool bro. You’ll never hear me throw shade on someone for charting their own course in life or choosing a different path. In fact, to drop a little relevant Hendrix up in here:

        “I’m the one who has to die when it’s time for me to die. So, let me live my life the way I want.”

        As long as my life doesn’t interfere with your life, we’ll be just jippity jippity. Rock on! Git sum! It’s a big world. We can all coexist.

  • wickedrando@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 months ago

    i was just thinking this week with the passphrase addition how good bitwarden is and when will the other shoe drop. There it is.

    • Lka1988@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      Keepass (all variants and forks) has a passphrase generator, been built-in for years.

      The writing is on the wall for BW, and has been for quite some time now.

  • Fmstrat@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 months ago

    Vaultwarden can’t exist without “leeching” off of Bitwarden.

    Why not? No reason mobile apps and browser extensions can’t be forked.

      • Fmstrat@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 months ago

        Well, yes, Vaultwarden would need more support, but that happens pretty frequently when a major provider enshitifies. Look at Godot, Lemmy, etc.

        As for the CVE linked, BitWarden itself has many more: https://app.opencve.io/cve/?vendor=bitwarden

        CVEs aren’t an indication of poor quality. Speed to resolution is. It’s not often devs themselves are finding CVEs, it’s the community.

        At the core, regardless of what a C suiter does to the marketing, the state of the FOSS repos is what matters. Since they already walked back the “always free” comment this whole debate may be moot, so time will tell. Hopefully the rest of the company and the public sway them to continue to support it properly themselves.

      • zipjo@lemmy.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 months ago

        The linked vulnerability has been fixed a day prior of being reported by the dev themself and it’s not an issue since then, it even sais so in the cve description.

  • godsammitdam@lemmy.zip
    link
    fedilink
    English
    arrow-up
    0
    ·
    3 months ago

    Has Vaultwarden said anything yet? I imagine that, if necessary, given that bitwarden’s client is still open, at the point they choose to try and close it, we, the users, can fork it and establish it for vaultwarden, correct? Or, maybe even the vaultwarden team will think about forking it themselves and making a light client as well to pair with the current server.

    But Vaultwarden can exist without “leeching” they just haven’t needed to yet. That’s more symbiotic than parasitic. The parasite class just took over Bitwarden after all.

    • German The Jackal@pawb.socialOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 months ago

      Not to my knowledge. As far as forks go, that’s true. However, Vaultwarden would need to become an independent team, and even if they don’t take over maintaining the client, someone else would need to become independent. While it can work, it can also lead to very nasty, longstanding bugs or security issues due to scale, budget, and effort. I see this a lot with Apple apps for example - smaller developers understandably don’t want to deal with Apple’s crap and costs, and everyone suffers in the end.

      If you look at the current state of the cybersecurity world, it’s not kind to open-source developers. AI-generated BS is dredging up vulnerabilities on all sides. So security is also a big concern. Someone like Bitwarden has a lot of budget to swing.

      Vaultwarden itself is incredibly good, but not perfect:

      https://nvd.nist.gov/vuln/detail/CVE-2026-26012.

      • godsammitdam@lemmy.zip
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 months ago

        You’re right. And that’s why more of us need to contribute and spread the word of projects to support them.

        Honestly, FOSS is our last bastion against this consumerist hellscape. I’m working on learning to build my own discord-like front end on matrix specifically for gaming. But I’m just one guy. We’ve all gotta pick where we place our effort and support those around us similarly.

        Vaultwarden taking over bitwarden, should they shut doen as open source, I think would be entirely worthy. But it might need more people to either help vaultwarden or maintain it on their own, you’re right.

        To me, seeing and learning about all of these projects gives me hope. All of these people and communities working to build things out of passion and dedication, because they care and want to provide value to others. No profit motive necessary. We just need to be there to support them as we’ve tied capital to our survival currently.

        • German The Jackal@pawb.socialOP
          link
          fedilink
          English
          arrow-up
          0
          ·
          3 months ago

          True dat. The more people know every corporation, even the most “wholesome chungus Reddit karma 100” ones ONLY care about squeezing profits out of you, the better off we’re going to be in the future.

          Check out and contribute to gomuks. It’s the go-to power user Matrix client as I’ve learned. I recently developed a theme for it to make it look more like Cinny, which itself is a bit of a Discord UI Clone. I don’t actually use gomuks, but it really needed a nice theme.

          • FreedomAdvocate@lemmy.net.au
            link
            fedilink
            English
            arrow-up
            0
            ·
            3 months ago

            Anyone that doesn’t understand that companies exist to make profit needs to be studied at this point. You have to wonder how they even function in the world.

            People don’t go work 9-5 for the fun of it and for free, do they? No, a company and/or customers pay them. Without that payment step there’s no job and there’s no product/service.

            If you don’t think the company deserves your money, find another free service and use that until they start charging. Rinse and repeat - or just be an adult and pay for services and work that you like and use.

            • German The Jackal@pawb.socialOP
              link
              fedilink
              English
              arrow-up
              0
              ·
              3 months ago

              Are you genuinely unable to comprehend the concept of a company not doing evil things to make profit? You do realise I paid for it up until this point right? Thanks captain obvious for telling me I can stop paying for things.

              I was fine with a price hike, I realise that paid users are subsidizing free ones and everything is getting more expensive. What I’m not fine with is the deception, shitty marketing, removal of “DEI-like” language, and a sudden clear lack of morality in the company. They lost my trust, anyone with a brain shouldn’t trust them either with their most precious online secrets.

              And you call yourself a freedom advocate, then advocate for textbook enshittification which always leads to the removal of freedom lol, what a shill

              • FreedomAdvocate@lemmy.net.au
                link
                fedilink
                English
                arrow-up
                0
                ·
                3 months ago

                You think that people are going to lose “freedom” with Bitwarden making changes? Are you serious?

                They’re not doing anything “evil” lol. Inclusivity should not be a main focus of a password storage company lol. That makes no sense.

                You shouldn’t have had “trust” in a company to begin with. That’s on you.