Bitwarden’s FOSS halo slips as new SDK requirement locks down freedoms

Bitwarden's FOSS halo slips as new SDK requirement locks down freedoms

October 24, 2024 at 07:39AM

Bitwarden’s new build requirements have raised concerns about its status as free and open-source software (FOSS). A recent GitHub discussion highlighted that the SDK needed for compilation is not free, prompting comparisons to other companies that have shifted away from open-source principles. Alternatives exist but may require more user management.

### Meeting Takeaways:

1. **Change in Bitwarden’s Build Requirements**:
– Bitwarden has updated its build requirements, leading to concerns that it may no longer be a Free and Open Source Software (FOSS).
– A significant issue has been raised on GitHub titled “Desktop version 2024.10.0 is no longer free software,” prompting discussions among users.

2. **New SDK Requirements**:
– The introduction of a new Software Development Kit (SDK) for compiling Bitwarden software is at the center of the controversy.
– Although the SDK is available, its licensing is not open-source, which contradicts the principles of FOSS regarding user freedoms.

3. **Response from Leadership**:
– Kyle Spearrin, CTO of Bitwarden, stated that the FOSS tools and the SDK are distinct and subsequently closed the GitHub discussion.
– This conclusion is met with skepticism regarding its alignment with the GPL’s aggregation provisions.

4. **Alternative Tools and Market Changes**:
– There are Bitwarden-compatible tools, like Vaultwarden, but their independence is questioned due to the hiring of its developer by Bitwarden.
– The shift away from FOSS was predicted by Abdullah Atta in September 2022 after Bitwarden received significant venture capital funding.

5. **Community Reactions**:
– Users have expressed disappointment on platforms like the Fediverse, highlighting the perceived decline in Bitwarden’s open-source nature.
– Other password management alternatives exist, such as Buttercup, KeePassXC, and SyncThing (noting the recent discontinuation of its official Android client).

6. **Implications for Users**:
– Users may need to explore other FOSS alternatives or be prepared to manage their password databases independently.

### Action Items:
– Monitor updates from Bitwarden regarding their licensing and build requirements.
– Consider evaluating alternative password management solutions.
– Stay informed on community discussions surrounding this issue on GitHub and other platforms.

Full Article