Remix.run Logo
▲ dannyw 3 hours ago

I actually find this somewhat understandable; and I'll be continuing my subscription; as long as all source continues to be available and personal self-hosting remains a viable option.

Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.

Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.

It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.

I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.

▲compsciphd an hour ago | parent | next [-]

I was at redis when they changed the license (the first time). I begged the new leadership to not change the core license but to do a few things instead.

1) bundle the "source available" modules as part of redis source distribution 2) enable people who only want bsd code to be able to build a "redis_core" 3) commit to the community that the core will remain BSD licensed and that they are committed to making it the best key/value store. 4) increase the amount of source available code that until then had been kept closed (including what we called big redis/RedisOnFlash/MultiTier) 5) Require anyone using the redis trademarks in a commercial setting to ship the entire Redis (which includes the source available portions, so Amazon et al would no longer be able to use the Redis trademarks without a license deal.

Another alternative was to simply go to AGPL (which they went to anyways awhile later).

I failed to convince the leadership about this. I honestly think they squandered huge value in community engagement, but perhaps that's what they wanted. I left a bit after these changes were made as it became clear that the new US led leadership of the company wasn't particularity interested in what was the soul of redis. (previously was heavily Israeli led and a critical mass there was invested in redis as an open source product).

Funny story, the then new/current CEO used to be the head of WebEx at Cisco. We had a Q&A when he was hired and I asked, what did he learn from his time at WebEx about how to maintain market position (as they lost everything to zoom et al). His response at the time wasn't that convincing, but I was willing to give him the benefit of the doubt. I feel its fair to ask if the same thing occurred again.

▲farlight an hour ago | parent [-]

Thank you for trying to do something to prevent it, many people wouldn't bother.

▲solarkraft 3 hours ago | parent | prev | next [-]

I’m conflicted. On one hand I’m grateful for the years of trustworthy (and pay-what-you-want) password management. On the other this feels like an attempt to EEE the free version.

▲freedomben 3 hours ago | parent [-]

That's my concern as well. I have no problem with the current license change if they continue to publish all the code as they claim. My concern is that this is usually step 1 in a boil-the-frog strategy to eventually split and break off enterprise features. I'll give them some trust until they give me a reason not to (I think they've earned it), but the concern remains.

▲4ndrewl 3 hours ago | parent [-]

They don't?

"Some future components will be published under the commercial license and will exist only in that build."

(From that thread)

▲trentor 2 hours ago | parent | prev | next [-]

I would be with you if they didn't change the owner to private equity in the last year.

▲zeroonetwothree 2 hours ago | parent [-]

Wasn’t it just a minority stake?

▲selectodude 2 hours ago | parent | prev | next [-]

The thing I always think about is that they wouldn't have to change the license and tighten the screws if people paid for it. Getting mad that the free hosted password manager has changed the deal a little bit I find to be quite arrogant.

Pay the $20/yr or whatever to have them host it and the whole world keeps turning.

▲lstodd 2 hours ago | parent [-]

Hosted password manager is equivalent to publishing all your passwords outright.

Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all.

▲ricericerice 2 hours ago | parent | next [-]

you have no idea how bitwarden works, do you...

by that logic, every time you send a password over a TLS connection, you're publishing it outright too

▲techjamie 2 hours ago | parent | prev | next [-]

People are going to try much harder to break into the main Bitwarden servers than they are my little Vaultwarden instance. Plus, I have the ability to lock it behind a VPN so it isn't even publicly exposed.

But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.

I'm not sure where your sentiment comes from here.

▲judge2020 2 hours ago | parent | next [-]

> But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.

A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me. I much prefer 1Password's approach where they have a usually-hidden second secret (the "Secret Key") that both (A) isn't shown unless you're setting up another device, and (B) acts as extra data needed to form the decryption key for your vault.

The main threat model I'm thinking of protecting against is a 1password vault data breach of some kind (or possibly cooperation with government agencies) + password exposure in some way (be it from CCTV-extracted password entries, over-the-shoulder watching, etc), as even with both of those factors, they would somehow need to get your secret key to decrypt vaults.

Like, all of those lastpass vaults obtained during the Lastpass hack would be de-facto useless even with a correct password if their design included some sort of hidden secret secret.

▲atherton94027 2 hours ago | parent | prev | next [-]

I'm not sure that calculus is going to be true for much longer – with the costs of AI falling, it's going to be much easier to throw tokens at the problem even tiny targets that wouldn't have been worth it before. Can you guarantee your VPN is patched and secure at all times?

▲yjftsjthsd-h an hour ago | parent [-]

Can you guarantee the hosted servers are patched and secure at all times?

▲technolo-g 2 hours ago | parent | prev | next [-]

I took it to mean non-self hosted is like publishing your passwords online, which I agree with.

▲iohvvbhdyh 2 hours ago | parent | prev [-]

AI will do it

▲selectodude 2 hours ago | parent | prev | next [-]

I mean, no it's absolutely nothing like "publishing all your passwords outright" but fine. Pay the $20/yr and don't have them host it, host it yourself. Just pay them the $20.

▲orf 2 hours ago | parent | prev | next [-]

Your comment is generally ignorant on infosec.

▲willmadden 2 hours ago | parent | prev [-]

Do you have a quantum computer from the future and a file of passwords that haven't been changed in 50 years? Complete nonsense.

▲behringer 2 hours ago | parent | prev | next [-]

That's not what's happening here. They're making their app closed source with closed source features. Time to find a new provider.

▲merb 3 hours ago | parent | prev | next [-]

Sorry but the elasticsearch thing was a big stupid take of elastic. It was big corpo against big corpo not the poor elastic company.

Changing licenses is a sick move and companies doing that should be fucked over, because the license made them big. Changing it later on means that they got greedy nothing more nothing less.

Without oss bitwarden would be a paid cloud like all the others that probably would’ve had a hard time getting trusted.

▲mcfedr 2 hours ago | parent [-]

elastics cloud offering was awful

▲amber71de 2 hours ago | parent | prev [-]

[flagged]