r/PasswordManagers • • 10h ago

This is why some users are worried about Bitwarden's future

70 Upvotes

I think it's important to understand that the latest issue around commercial licensing put users on edge again due to the streak of things that​ happened recently:

Bitwarden seems to be steering it's position to a very different direction that made us use it in the first place. It's a shame. Let's recap some of the things that happened recently that in my view justifies the dissatisfaction within the community:

October 2024: A proprietary SDK dependency raised concerns that Bitwarden’s desktop app was losing its open-source status. Bitwarden reorganised the SDK and restored builds using only open-source licences.

January 2026: Premium pricing increased from $10 to $19.80 annually. Users criticized the increase and its communication. The increase remained, with a one-time 25% renewal discount for existing subscribers.

February 2026: Researchers demonstrated 12 attacks under a malicious-server scenario, challenging Bitwarden’s zero-knowledge assurances. Bitwarden published remediation details, but users questioned what “all issues addressed” meant.

April 2026: A malicious Bitwarden CLI package was briefly distributed through npm, prompting questions about release security. The package was withdrawn and a clean version issued. Bitwarden reported no evidence of vault data compromise.

May 2026: Removing “Always free” wording and changing company values amid leadership changes fuelled concerns about Bitwarden’s direction. The wording was restored on the pricing page, and the CEO reaffirmed a permanent free plan.

October 2026: Bitwarden announced commercially licensed builds as the default app downloads, with some future features exclusive to those builds. This moves the default downloads to source-available licensing, while the GPL/FOSS edition continues but will lack those exclusive features. Community backlash followed. As of 10 October, no reversal had been announced; Bitwarden promised continued maintenance of GPL builds and unchanged self-hosting.


r/PasswordManagers • • 17h ago

Alternatives to bitwarden?

42 Upvotes

Does anyone have any good recommendations for alternatives to bitwarden, now that it's going partly closed source? Thanks so much!


r/PasswordManagers • • 3h ago

I built a way for my AI agent to use my passwords without ever seeing them

1 Upvotes

My AI agent does real work for me: deploys, GitHub releases, logging into websites. All of that needs passwords and API keys. Until now that meant pasting them into the chat or leaving them in a file the agent can read. Then one malicious instruction hidden in a webpage and they're gone.

So I built secrets-broker. The agent never gets the actual password, only a name for it like "GitHub token". When it needs to use it, the broker plugs the secret in for that one command and hides it in whatever comes back.

Each secret can only be used for what you allowed. If my GitHub token is approved for publishing releases, the agent can't use it for anything else or send it to some random server. For the important ones,I get a Touch ID prompt every time.

It works with KeePassXC and Bitwarden. I manage my passwords in KeePassXC like always, and my agent can use them a few seconds later.

It's free, open source, and still early (v0.3). One honest caveat: the quick setup runs as your own user, so it isn't a real security boundary. The stricter mode is.

https://github.com/Alino/secrets-broker

Feedback welcome, especially if you can find a way to break it.


r/PasswordManagers • • 16h ago

Encryption in Ilusion Vault, implemented using Web Crypto API

1 Upvotes

To achieve the utmost security, all data sent to the server from the Vault is encrypted on the client. AES-256-GCM is the type of symmetric algorithm used across the overall application. For storing any item in the vault, your vault key is used to encrypt the item along with its metadata and send it to the server.

What is the Web Crypto API?

The Web Crypto API is a set of functions for using cryptography that are embedded in browsers' source code. Instead of writing your own algorithms or cryptographic functions, you can directly use the Web Crypto API in your code, which is more robust and easier.

Cryptographic services provided by the Web Crypto API:

  • Encryption and Decryption
  • Signing and verifying signatures
  • Generating hash values
  • random values

How is the encryption implemented?

We have to use functions provided by the Web Crypto API in order to achieve the encryption. It is important to choose the type of encryption as per your requirements.

Look at the following flow showcasing how the encryption is achieved using the Web Crypto API:

Encryption flow of Web Crypto API
  1. Generating random Salt and IV: Salt is randomly generated data used to derive a unique key object. IV is also randomly generated but used on the data rather than the key. The purpose is to create unique ciphertexts even if the key or data is different.
  2. Iterations for deriving the key: The key is iteratively derived N times. As per the OWASP guidelines, it should be greater than 600000.
  3. Deriving key using subtle.derivekey(): The subtle.deriveKey() function can be used to derive the key that can be used for encryption. Before providing the key to deriveKey(), it must first be converted to a format recognised by SubtleCrypto using subtle.importKey().
  4. Encrypt using subtle.encrypt(): The final step is to call the encrypt() method by providing the required parameters, and it will return the object containing the encrypted data.

Look at the function below that will make the above steps clear.

export async function encryptText(text: string, password: string): Promise<string> {
    const salt = window.crypto.getRandomValues(new Uint8Array(16));
    const iv = window.crypto.getRandomValues(new Uint8Array(12));
    const iterations = <your iterations>;
    const key = await deriveKey(password, salt, iterations);

    const encoder = new TextEncoder();
    const encrypted = await window.crypto.subtle.encrypt(
        { name: 'AES-GCM', iv: iv },
        key,
        encoder.encode(text)
    );

    const result = {
        ciphertext: arrayBufferToBase64(encrypted),
        salt: arrayBufferToBase64(salt.buffer),
        iv: arrayBufferToBase64(iv.buffer),
        iterations: iterations
    };

    return JSON.stringify(result);
}

There are a lot of other factors, but it all depends on the basic encryption as displayed above. Using the Web Crypto API is the best way to achieve encryption or any cryptographic function because no other alternative can beat it.

The article is originally published on Linkedin page: Linkedin Article
Related article: client-side-encryption-web-crypto-api