← Back to context

Comment by dannyw

8 hours ago

I actually find this somewhat understandable; and I'll be continuing my subscription; as long as all source continues to be available and personal self-hosting remains a viable option.

Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved.

Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc.

It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete.

I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.

I was at redis when they changed the license (the first time). I begged the new leadership to not change the core license but to do a few things instead.

1) bundle the "source available" modules as part of redis source distribution 2) enable people who only want bsd code to be able to build a "redis_core" 3) commit to the community that the core will remain BSD licensed and that they are committed to making it the best key/value store. 4) increase the amount of source available code that until then had been kept closed (including what we called big redis/RedisOnFlash/MultiTier) 5) Require anyone using the redis trademarks in a commercial setting to ship the entire Redis (which includes the source available portions, so Amazon et al would no longer be able to use the Redis trademarks without a license deal.

Another alternative was to simply go to AGPL (which they went to anyways awhile later).

I failed to convince the leadership about this. I honestly think they squandered huge value in community engagement, but perhaps that's what they wanted. I left a bit after these changes were made as it became clear that the new US led leadership of the company wasn't particularity interested in what was the soul of redis. (previously was heavily Israeli led and a critical mass there was invested in redis as an open source product).

Funny story, the then new/current CEO used to be the head of WebEx at Cisco. We had a Q&A when he was hired and I asked, what did he learn from his time at WebEx about how to maintain market position (as they lost everything to zoom et al). His response at the time wasn't that convincing, but I was willing to give him the benefit of the doubt. I feel its fair to ask if the same thing occurred again.

  • > His response at the time wasn't that convincing, but I was willing to give him the benefit of the doubt. I feel its fair to ask if the same thing occurred again.

    Business will have to try different things at different points due to external & internal pressures. Some decisions are reversible (at cost), some aren't. Decisions (chaotic / complex / complicated ones, at least) are not made merely based on available data and analysis, but also based on intuition, experiments, and predictions. Then, to look at the outcome rather than the process is missing the point. When the circumstance / situation isn't clear-cut, the feedback (the outcome of a decision) is in itself more valuable to the organization (than never having taken the decision, at all), especially when the costs (to reverse / change it) are bearable.

I’m conflicted. On one hand I’m grateful for the years of trustworthy (and pay-what-you-want) password management. On the other this feels like an attempt to EEE the free version.

  • That's my concern as well. I have no problem with the current license change if they continue to publish all the code as they claim. My concern is that this is usually step 1 in a boil-the-frog strategy to eventually split and break off enterprise features. I'll give them some trust until they give me a reason not to (I think they've earned it), but the concern remains.

    • They don't?

      "Some future components will be published under the commercial license and will exist only in that build."

      (From that thread)

The thing I always think about is that they wouldn't have to change the license and tighten the screws if people paid for it. Getting mad that the free hosted password manager has changed the deal a little bit I find to be quite arrogant.

Pay the $20/yr or whatever to have them host it and the whole world keeps turning.

  • Hosted password manager is equivalent to publishing all your passwords outright.

    Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all.

    • you have no idea how bitwarden works, do you...

      by that logic, every time you send a password over a TLS connection, you're publishing it outright too

    • People are going to try much harder to break into the main Bitwarden servers than they are my little Vaultwarden instance. Plus, I have the ability to lock it behind a VPN so it isn't even publicly exposed.

      But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.

      I'm not sure where your sentiment comes from here.

      6 replies →

    • I mean, no it's absolutely nothing like "publishing all your passwords outright" but fine. Pay the $20/yr and don't have them host it, host it yourself. Just pay them the $20.

    • Do you have a quantum computer from the future and a file of passwords that haven't been changed in 50 years? Complete nonsense.

Sorry but the elasticsearch thing was a big stupid take of elastic. It was big corpo against big corpo not the poor elastic company.

Changing licenses is a sick move and companies doing that should be fucked over, because the license made them big. Changing it later on means that they got greedy nothing more nothing less.

Without oss bitwarden would be a paid cloud like all the others that probably would’ve had a hard time getting trusted.

  • > Changing it later on means that they got greedy nothing more nothing less.

    Or just trying hard to keep the company afloat?

    Just because they published Open Source code at some point, you feel that you're entitled to free updates for the rest of your life?

That's not what's happening here. They're making their app closed source with closed source features. Time to find a new provider.

  • Per their public discussion on the topic, the non-OSS licenses will still be public and accessible for review.

    • We’ve seen it countless times over the last decade. OpenSolaris was the first big one. The open source side isn’t going to change, it’ll just get abandoned. They’re committed to open source… for now. Nothing is going to change… for now. They’ll maintain compatibility with compatible servers… for now.

      Everything will get chipped away piece by piece. It’s been happening continuously for well over a decade at this point and everyone should understand the strategy by now.

      1 reply →