pwshub.com

New Bitwarden build requirement casts doubt on FOSS-ness

The Bitwarden online credentials storage service is changing its build requirements – which some commentators feel mean it's no longer FOSS.

The question has been highlighted by a new issue on the project's GitHub page, with the strong title "Desktop version 2024.10.0 is no longer free software."

This is because of a new build requirement, added in a pull request a couple of weeks ago titled "Introduce SDK client." This SDK (software development kit) is required to compile the software from source – either the Bitwarden server or any of its client applications. The problem is that although the SDK is available, it is under a license that means it's not free software. The license says:

Restricting what users can do with the software violates the first of GNU's four essential freedoms. In other words, although you can get the source code, the restrictions on what you can do with it mean that it's not truly open source anymore.

Although the license is different, the comparisons with other not-so-open-sourcey-anymore companies and products, from Hashicorp to Redis, are irresistible.

The issue hasn't attracted much discussion on GitHub itself because Kyle Spearrin, the company's chief technical officer, responded that the FOSS Bitwarden tools and the SDK were not the same thing:

He then closed and locked the discussion. However, this claim appears contractually doubtful as it may fall under the GPL's provisions regarding the aggregation of software.

There are other BitWarden-compatible tools out there, such as the Rust-based replacement server Vaultwarden. However, since that first appeared, lead developer Daniel García was hired by BitWarden. As such, its existence as an independent alternative is dubious.

  • Google apologizes for breaking password manager for millions of Windows users with iffy Chrome update
  • For password protection, dump LastPass for open source Bitwarden
  • Intruders get their hands on user data in LastPass incident
  • 1Password's Insights tool to help admins monitor users' security practices

There were signs long in advance. Back in September 2022, Abdullah Atta, lead developer of Notesnook, a similar secure and encrypted online storage tool, blogged that "It's time to leave Bitwarden." His reasoning was that Bitwarden had just obtained $100 million of venture capital financing. He predicted that the company would move away from FOSS in the direction of raising revenue, and it looks like he was right.

Bad news for our own SJVN, who just a few months later wrote that it was time to dump LastPass for open source Bitwarden – although he did say "Bitwarden is a kinda sorta open source program." It looks rather like it's a little less so now, as noted by some amusingly snarky comments on the Fediverse.

There are many other alternatives out there, from Buttercup to KeePassXC. Many will require you to synchronize your own password database between computers, either on your own, or using other cloud services. Or you could use a FOSS tool such as SyncThing. Note, however, that SyncThing just discontinued its official Android client – but independent ones remain available. ®

Source: theregister.com

Related stories
3 weeks ago - Comprehensive password management across an entire organization helps your company defend against cybersecurity threats. See how with CNET's highest-ranked overall password manager.
1 day ago - The Federal Trade Commission has introduced a new rule designed to make it harder for you to be misled by fake online reviews.Effective as of...
1 day ago - Google's latest round of updates seeks to protect Android users from those fake package delivery and job-offer scams, among other problems.
1 day ago - New Haven residents have access to several good internet options. Here are CNET's top picks for broadband in this Connecticut town.
22 hours ago - A new tool has emerged to help bypass the strict system requirements for Windows 11. The application, spotted by Neowin, is called Flyby11, and it offers a simple way to install Microsoft's latest operating system on computers that don't...
Other stories
12 minutes ago - Jacques Treiner, a theoretical physicist at Université Paris Cité, has examined the effects of walking speed on the amount of rainwater a person encounters. His insights might just change your tactics.Read Entire Article
12 minutes ago - In the company's third quarter earnings report, Tesla wrote that preparations remain underway for its offering of new vehicles. These include more affordable models, which will begin launching in the first half of next year.Read Entire...
27 minutes ago - How embarrassing for Samsung SK hynix posted on Wednesday what it called its "highest revenue since its foundation" for Q3 2024 as it pledged to continue minuting more AI chips.…
36 minutes ago - Tempe doesn't have a shortage of big-name internet providers. Here's the breakdown of which ones have the best speed and prices.
36 minutes ago - Why You Can Trust CNET Our expert deal-hunting staff showcases the best price drops and discounts from reputable sellers daily. If you make a...