17 comments

  • MostlyStable48 minutes ago
    While I&#x27;m not _happy_ about the messaging changes, those alone are not enough to do more than start paying closer attention. I highly, <i>highly</i> doubt that vault export would be the first meaningful feature change, and so I think there will be stronger signals of actual issues before then.<p>As I understand it, so far the only actual change is an announced increase in prices. Obviously, from the consumer perspective, cheaper is better, but this is a product where I think that a subscription plan makes sense (and the free tier, for now, still exists), and so I&#x27;m not going to get mad about price changes. Competitors exist and one doesn&#x27;t think the new price is worth it, then switch to one of them (using the very-much-still-available vault export).<p>I don&#x27;t think the warning is crazy or anything, but in my personal opinion it&#x27;s a little stronger&#x2F;earlier than is warranted and the current appropriate response is careful watching.
    • ktm5j13 minutes ago
      I hear you, but I feel like it&#x27;s a better safe than sorry situation. Exporting your passwords takes two seconds. I think you can export to an encrypted file, but I just did a plain-text json file and gpg&#x27;d it. Can&#x27;t hurt to play it safe.
  • cjs_ac37 minutes ago
    I store my passwords using this: <a href="https:&#x2F;&#x2F;www.passwordstore.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.passwordstore.org&#x2F;</a><p>It&#x27;s a shell script that stores passwords in a git repository, containing one file per entry. The files are encrypted using a GPG key. Because it&#x27;s just a git repository, you can synchronise it between devices using whatever infrastructure you want. I use a FOSS client for it on iOS, and there was one for Android before I got an iPhone.
    • ab71e53 minutes ago
      I&#x27;m interested in this, what do you use to host the git repo? Just a private repo on something like github or your own server? How do you backup your private key?
    • Depraved448215 minutes ago
      +1 for pass! I use this on my VPS to store secrets. I love that it syncs with GIT. Good stuff
  • tfarias12 minutes ago
    I&#x27;ve been recommending Bitwarden for a few years now and have also been paying a yearly sub since 2022, as I always thought 10$ was a really good value.<p>But with all this stuff coming out, I&#x27;m holding off on recommending it anymore; at least until everything calms down and the new value proposition is fully laid out.<p>Like other folks have said, I don&#x27;t think it&#x27;s yet time to migrate. That being said, it doesn&#x27;t hurt to do an encrypted export for backup purposes, start looking at alternatives, and reach out to people I know use Bitwarden to do the same.<p>Keeping an eye out on how this develops.
  • stormed2 minutes ago
    I only use Vaultwarden, which to my understanding is an open source reimplementation of Bitwarden&#x27;s API. I personally haven&#x27;t had any issues with it, not sure if it&#x27;ll eventually stop being compatible with Bitwarden&#x27;s official applications however.
  • Humorist229010 minutes ago
    I&#x27;m taking a &quot;wait and see&quot; approach with Bitwarden. I&#x27;ve been a paying customer for a while, happy with it, and hoping the leadership changes won&#x27;t be too user hostile. Still, a major reason I chose Bitwarden to begin with is they have a decent &quot;Export&quot; button, and all of this news reminded me that my offline backup of the vault was a few months old. Regardless of their product roadmap, they could have an incident tomorrow that keeps users away from their passwords -- offline backups are a good idea.<p>And Vaultwarden is nice. I&#x27;ve used it at work, hosted it myself, and as a user of the password manager I can say it&#x27;s basically indistinguishable. But I don&#x27;t really pay Bitwarden for a password manager -- I pay them for a secure sync of a password manager I can share with family members who can&#x27;t figure out a VPN.
  • Someone12341 hour ago
    I think the caution around Bitwarden is justified; and I think it is good that the message is getting out there. I will say &quot;while you still can&quot; is hyperbole, and will do more to distract from the larger (correct) point about Private Equity.
  • cjwoodall45 minutes ago
    I wish companies that offer such a core technology and what not were at times entered into a public trust, similar to how some public lands are managed, that would protect them from private equity takeovers; I know it defeats the purpose of the companies in the first place (making money), and it probably would backfire in myriad worse ways than the problems it might solve... But I do think there are many options for how products, services and what not can be structured that give the people who maintain them what they need to thrive; without mining the users for money.<p>Overly idealistic thinking, maybe... but still thinking.
    • throwaway8582531 minutes ago
      Public management exists for natural monopolies where no market competition is feasible. The role of the public entities is to protect competition. In this case that would be mandating import&#x2F;export interoperability.
  • poisonborz48 minutes ago
    Clients are OSS, I wonder why nobody did a Vaultwarden-style fork of them yet that would watch over upstream changes.
    • jerf12 minutes ago
      Until Bitwarden screws up it&#x27;s going to be difficult for any fork to get much attention. If they do, that will the moment to launch a fork.<p>It&#x27;s Bitwarden&#x27;s game to lose. Forking is easy enough that there&#x27;s no great need to pre-emptively fork.
    • subhobroto42 minutes ago
      Vaultwarden is a very lean implementation of Bitwarden but if you want to look into an alternative to the Bitwarden ecosystem, I recommend - AliasVault <a href="https:&#x2F;&#x2F;github.com&#x2F;aliasvault&#x2F;aliasvault" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;aliasvault&#x2F;aliasvault</a> - check it out!
  • PaulHoule50 minutes ago
    Sometimes I think when a startup announces that they are being acquired their competitors have a meeting that morning and announce that they&#x27;re going to start dialing for dollars. Since acquisitions almost always hurt customers I wonder if we can start creating &quot;poison pills&quot; that deter them.
  • bilal4hmed23 minutes ago
    This is getting so tiring. What are the other options out there now?
  • ChrisArchitect10 minutes ago
    Related:<p><i>The quiet renovation at Bitwarden</i><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=48163389">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=48163389</a>
  • eleventen1 hour ago
    I think this is a little hyperbolic. The product may drop features, increase prices, and squeeze its free tier users. Everything enshittifies. But the idea that password export might disappear or be degraded? Nah. You&#x27;ll be able to jump ship any time you want.
    • vallassy59 minutes ago
      &gt;You&#x27;ll be able to jump ship any time you want.<p>Famous last words...
      • AdmiralAsshat22 minutes ago
        I mean, LastPass was a train wreck after their breach, but they didn&#x27;t go as far as trying to stop me from exporting my vault when I switched to BW.<p>The idea of BW doing a rug pull and suddenly removing the ability to export your vault I think would trigger a class-action lawsuit.
    • e4023 minutes ago
      I don&#x27;t know why this is framed as &quot;jumping ship&quot; ... of course you can stop using it any time (and use your periodic export to go elsewhere).<p>The real issue is potential data loss. Remember LastPass? Bought by someone and downhill it went, with multiple security incidents.
    • tremarley1 hour ago
      Never underestimate the lengths companies will go to, to enshittify their product to squeeze customers for money.
      • eleventen57 minutes ago
        Name one major password manager that blocks or paywalls export.
        • kpozin53 minutes ago
          - Authy<p>- Google Authenticator
          • MostlyStable44 minutes ago
            Google Authenticator has an export-as-QR-code function that several other authenticator apps can parse. Is it the best&#x2F;most convenient implementation? Obviously not, but you can absolutely export the codes.
          • eleventen41 minutes ago
            Not password managers of course, but thanks for reminding me that I should figure out how to ditch Authy.<p><a href="https:&#x2F;&#x2F;github.com&#x2F;BrenoFariasdaSilva&#x2F;Authy-iOS-MiTM" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;BrenoFariasdaSilva&#x2F;Authy-iOS-MiTM</a> is going to be my project for the afternoon.
            • Ringz20 minutes ago
              Ente Auth<p>is a good alter. Works perfect for me.
          • Someone123449 minutes ago
            Notably not password managers.
  • steviedotboston10 minutes ago
    This is a whole lot of FUD.
  • subhobroto40 minutes ago
    I&#x27;m a huge fan of AliasVault <a href="https:&#x2F;&#x2F;github.com&#x2F;aliasvault&#x2F;aliasvault" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;aliasvault&#x2F;aliasvault</a> - the author is responsive, receptive. The whole ecosystem is opensource.<p>Bitwarden&#x2F;Vaultwarden had a good run but if someone&#x27;s going to self-host Vaultwarden, I would encourage people to look into AliasVault instead. It&#x27;s a complete opensource ecosystem.
  • pattilupone45 minutes ago
    WOW. Quietly editing the 4-year-old blog post is super slimy, holy crap. Also seems like since this story was published, they edited the 4-year-old blog post again. The story points out<p>&gt;But the explanatory paragraph at the bottom of the same post still says the old ones: Inclusion and Transparency. Crandell’s name is still on it. The post now contradicts itself, and nobody wrote a new one.<p>Looking at the post right now, they&#x27;ve corrected it to Innovation and Trust.
  • jrm430 minutes ago
    Third-party password management as an isolated paid service (i.e. you don&#x27;t get password management unless you pay specifically for the password management) is just a terribly bad idea all around.<p>Waiting for people to get this.
    • e4025 minutes ago
      A bad idea for you. My non-technical family members can barely use 1Password and it is the easiest of the lot. The idea you promote is just not realistic.
      • baal80spam21 minutes ago
        Not really. That something is convenient doesn&#x27;t mean that it&#x27;s a good idea. It&#x27;s always a matter of convenience vs security.
  • avgDev1 hour ago
    A tale as old as time, enshitification.