Wow, a commercial open source product that COULD have pulled a rugpull, looked for all the world like they were planning a rugpull, just uh, did the right thing?
Good job, Bitwarden.
This is a most excellent place for technology news and articles.
Wow, a commercial open source product that COULD have pulled a rugpull, looked for all the world like they were planning a rugpull, just uh, did the right thing?
Good job, Bitwarden.
I know, it's a huge relief seeing this as someone who uses the free tier. I think I'll cough up for the advanced tier if they stick to their guns on this decision.
This. I will resume my recommendation of Bitwarden.
I'm sure all the folks who were quick to ignore or dismiss their clarification of the packaging issue at the time will be just as quick to make comments like these as they were to skewer them then.
I tried convincing people to give them the benefit of the doubt and see what they do, but no, everyone seemed to jump to conclusions.
Glad my trust wasn't misplaced this time. I have been and continue to be a paying customer.
everyone seemed to jump to conclusions.
Honestly, everyone's been so burned by companies pulling the wool over their eyes that there's just no trust left. People were happy with Mozilla 5-6 years ago and nowadays everyone is a skeptic.
You might be right in this case but they weren't wrong.
I get it, some orgs/projects do bad things, and we should absolutely roast them for it. But I believe in giving the benefit of the doubt for a period before melting down.
For example:
When a software project you use changes for the worse, look for alternatives, but give that product time to fix it. If they continue on the negative path, then definitely bail. If everyone bails at the first hint of trouble, we end up with a ton of half-baked projects instead of a few good ones. Give feedback and support good projects.
Yep, you're right there.
but no, everyone seemed to jump to conclusions
And I'm certain that it has served as the catalyst for the bitwarden decision.
I disagree, but unfortunately, we will probably never know. That said, I'm not against the outrage, I'm just against the conclusions. You don't need to immediately abandon a project at the slightest hint they're moving in a direction you don't like, what you should do is start watching that project a bit more closely to see if they correct or they make additional changes you don't like.
We should be taking the rational approach instead of the reactionary approach, but social media in general seems to love reacting instead. I've abandoned projects that went a direction I don't like, but I usually give them a few months after the first sign of problems. I'm currently doing that w/ Mozilla and I want to see what they do with their advertising push before jumping ship.
I will remember this, even more so because of the confused drama that preceded it. In general, I find it difficult for me to endorse any commercial entity, but Bitwarden has my admiration and I will continue to offer it as a better alternative to people I see storing their passwords in Chrome or Lastpass. I'm also happy to pay a bit to support a good product and will continue to support the development even if I switch to self-hosted at some point.
Pretty cool, good on ya Bitwarden
I'm so glad this happened. I really wanted to believe them when they said it was an error and would corrected. It appears that in relatively short order they addressed the issue, gave an explanation, an expectation, then nailed it. I hate when I recommend something, then have to backtrack because they changed.
I think I'm still switching to keepassxc, but I'll still recommend bitwarden to normal people (and my bitwarden account is paid til 2027 anyway, lol)
Keepassxc is great if you don't need to synchronize passwords across too many locations and do not require anything where state matters (mostly related to stuff like yubikeys). It DOES have the vulnerability in that a bad actor has infinite time to crack it should they get a hold of the file whereas bitwarden still lives on a server.
But they are very different products with very different capabilities. Whether someone needs bitwarden over keepass is going to be a question of use cases.
I use syncthing to sync my db and it works really well.