• 1 Post
  • 78 Comments
Joined 1 year ago
cake
Cake day: July 9th, 2023

help-circle
  • You might not have read the other comments, but I do QA for a living. Devs fucking up commits is why I continue to have a job. Also, companies/maintainers aren’t required to capitulate to every bug report. It’s possible that whoever made the original comments didn’t understand why it was such a big deal and/or didn’t know of an alternative way to structure their software; public pressure made them look a little harder.

    Like I said in my first comment: you do you. Bring out the pitchforks. The fact that there’s reasonable candidate explanations other than malicious intent says to me that the internet is overreacting—again.

    Though, when has the internet ever done that, amirite? /s



  • Their inability to do the right PR things is just a signal that they can’t be bothered with the facade…

    …or they’re just bad at PR. It’s not a skill everyone has.

    Re: ethics, they are no longer on F-Droid because they tried to get this in under the radar…

    …or they made an honest mistake and don’t care to put it back on F-droid for reasons to which we are not privy. I bring up these counter-examples not as a way to point out where I’m right and you’re wrong, but to point out that there are other candidate explanations, and it’s not justified to infer that malfeasance is the only likely possibility.

    I also understand why you would cynically think that Bitwarden might succumb to Capitalism—I too live in a late-stage-capitalism country—but that’s not a forgone conclusion, and I say again that we don’t need to be imagining villains when there’s plenty of objectively real ones at which to point a finger already.




  • Who knows for how long though because, if you read carefully, they didn’t promise that it will not be used in the future.

    This is conspiratorial thinking, and it’s a fallacy called the Argument from Silence (i.e. asserting intent based on what they didn’t say). If I say I’m going to give you a handshake, but you say, “But you didn’t promise you won’t punch me in the face,” most people would recognize that as a ridiculous line of reasoning.

    Bitwarden has now landed itself in the category of software that I would rather move away from and cannot wholeheartedly recommend anymore. That’s pretty sad.

    You do you. This doesn’t seem all that problematic to me, as I don’t need Secrets Manager, and I’ll still recommend it to anyone looking for a password manager.

    Seems to me that it makes more sense to vilify them when they become villains, not before based on paranoid reasoning that they might.








  • It went unnoticed at the time that the plugin was not providing any source code and was only providing binaries for download. Going forward, we will be requiring that all plugins that we link to have an OSI Approved Open Source License and that some level of due diligence has been done to verify that the plugin is safe for users.

    Unfortunate that this happened, but at least they are forcing more transparency to try to minimize the ability to hide behind opaque code.