Bitwarden Dual License Model
Bitwarden announced a dual-license model, shifting app store builds to a commercial license while maintaining an OSS version on GitHub. This move has ignited a fiery debate on HN, with many fearing 'enshittification' and the slow erosion of their beloved open-source password manager. Others argue it's a necessary, albeit unpopular, step for OSS projects to sustain themselves against corporate giants.
The Lowdown
Bitwarden, the popular open-source password manager, recently announced a significant shift in its licensing strategy, moving to a dual-license model for its official applications. The company communicated this change via a community forum post, aiming to clarify the implications.
- Starting with the next release, Bitwarden apps published to various app stores (e.g., Apple App Store, Google Play Store) will utilize commercially licensed builds.
- The GPLv3 open-source licensed version will continue to be updated and published on GitHub, ensuring source availability.
- All current features remain available in both the commercial and OSS versions, with no immediate changes to functionality.
- Bitwarden explicitly stated it is not going closed-source, self-hosting remains unaffected, and the free plan is permanent.
- However, a key detail emerged: 'Some future components will be published under the commercial license and will exist only in that build,' with new features evaluated on a case-by-case basis.
While Bitwarden asserts its continued commitment to open source and a robust free plan, the community is rife with speculation about the long-term implications for the project's open nature and feature parity, especially concerning future developments.
The Gossip
Enshittification Echoes
Many users expressed strong concern, viewing Bitwarden's license shift as the first step towards 'enshittification' and a departure from its open-source roots, drawing parallels to projects like Elasticsearch or Redis. The prevailing fear is a slow 'boil-the-frog' strategy where future, desirable features will be withheld from the purely open-source version, impacting users who value full transparency and control. Several comments also referenced an external blog post, 'The Quiet Renovation at Bitwarden,' as prescient.
The Open-Source Funding Predicament
A significant counter-narrative emerged, suggesting that such a license change might be a necessary evil. Proponents argue it's a pragmatic move for open-source projects to protect themselves from commercial exploitation (e.g., cloud providers offering managed versions without contributing back) and to ensure financial sustainability. They acknowledge the difficult realities of maintaining popular open-source software and question if those criticizing are simply unwilling to pay for tools.
Alternative Apprehensions & Options
Prompted by the license changes and concerns over Bitwarden's future direction, the discussion quickly pivoted to identifying and evaluating alternative password managers or compatible open-source clients. Users recommended and discussed projects like Vaultwarden (a Rust-based Bitwarden API implementation), Keyguard (an alternative Android client), KeePassXC (often paired with SyncThing for syncing), and even newer projects like PassPony, highlighting a potential user migration if trust continues to erode.
Quality Quandaries
Beyond the licensing debate, a recurring sub-theme involved criticisms of Bitwarden's current software quality, particularly the perceived slowness and 'bloat' of its browser extensions. Some users reported significant performance issues, especially on powerful hardware, suggesting that the use of heavy JavaScript frameworks contributes to a less-than-ideal user experience. This technical critique implicitly suggested that alternatives might offer a better experience regardless of licensing considerations.