Moving my passwords off Vaultwarden before I have to

For years I've made sure no single company holds too much of what I depend on, and I was about to split the few things I rent across different companies. So it's a little awkward that the password manager I'm leaning toward is Proton Pass, from the company that already has my mail and my VPN. I also like self-hosting. Almost everything I use runs on servers I own, and I tinker with them constantly, so when something breaks, I'm usually the one who broke it and always the one who fixes it. The one piece I'd stopped tinkering with is my password manager, and it turns out to depend on a company more than anything else on my servers.

My passwords live on a server I run, and they only work because Bitwarden's apps still accept it. The server runs Vaultwarden, an unofficial replacement for Bitwarden's own server. If you use it with the official apps, your logins depend on the same arrangement, and Bitwarden has never promised to keep it. Nothing has broken yet. But Bitwarden just said the apps in the stores will switch to its commercially licensed builds, and I've seen this kind of slow change before with MinIO, when I hoped instead of acting. This time I want to choose where my passwords go before I'm forced to.

For those who don't know, Vaultwarden is a Rust server that reimplements the API the Bitwarden apps call. Login goes through an identity endpoint, sync and everything else go through the API, and a websocket pushes live updates to browsers and desktop apps. Phones get theirs through Bitwarden's own push relay, and only if you register your server with Bitwarden for it. Every official Bitwarden app has a field where you type your own server URL, and after that the app can't tell the difference. The encryption happens on your device. The app stretches your master password into a key with PBKDF2 or Argon2id, encrypts your items, and uploads ciphertext. Mine ends up in a SQLite file (it's a single-user setup). If someone walked off with my server, they'd get encrypted blobs and a very slow brute-force problem.

The weak point is everything I don't control. Vaultwarden's whole job is to follow changes to Bitwarden's API upstream and reimplement them, and the apps on my phone belong to Bitwarden too.

The same servers run most of what I use every day. Nextcloud handles my files and sync, the job OneDrive or Google Drive would otherwise do. FreshRSS has my feeds, so I don't need a Feedly account (not that I ever had one), and Karakeep has my bookmarks because browser bookmarking sucks, let alone cross-platform bookmarking. Hister is a private search engine over the pages I've visited. AdGuard Home blocks ads for every device on my network, and Home Assistant runs my home automation and some other useful stuff. Uptime Kuma tells me when any of it falls over, along with a few public pages I care about. Headscale, a self-hosted version of Tailscale's coordination server, runs the private network my devices use to reach all of it from outside the house. Then there are a lot of smaller things I'll save for other posts.

I don't pay subscriptions for software I can host myself, and I stay out of walled gardens, apart from Apple's. Yes, I know what you'd say here. I complain about lock-in and carry an iPhone, a MacBook, a watch, and AirPods. I picked that one garden on purpose, which feels different from the dozen I'd have drifted into one subscription at a time. I self-host partly for privacy and partly because it's a good hobby, but what I'd miss most is the control. I decide what runs, when it updates, and when it gets retired, and nobody emails me to say my plan has changed.

I liked Bitwarden enough that I paid it $10 a year for a couple of years, as a thank-you, while using none of its hosting. That's small money, but it's how I think open source projects survive, and Bitwarden had one of the best reputations in the self-hosting community.

Then came Bitwarden's forum announcement about the store builds. It says the GPLv3 version stays on GitHub, self-hosting is unaffected, the change targets people who repackage and resell Bitwarden, and the free plan is permanent. Read alone, that's reassuring. But the build on the stores will be commercially licensed, and the announcement doesn't say what happens if Bitwarden changes its mind. The GPLv3 version will still be on GitHub, but it won't be what's on my phone. I don't know if Bitwarden will keep accepting Vaultwarden servers, and I don't want to find out the hard way. What worries me is the trajectory.

Actually, I didn't read it alone. A blog post called The quiet renovation at Bitwarden lists what else changed this year. According to its author, Premium's price doubled, and Bitwarden announced the increase inside a feature post, 15 days before renewals. The long-time CEO moved to an advisory role, and his replacement's bio leads with mergers, acquisitions, and private equity. "Always free" came off the pricing page for a while, and the author says it came back after the post got attention. I can't verify any of that myself because I wasn't paying close attention, but the post's point is that Bitwarden has been changing its business model and its public image, and the store announcement is part of that.

If Bitwarden wanted to end the current arrangement, I see three ways it could happen, and none needs an announcement. The apps could start depending on an endpoint Vaultwarden doesn't implement, and Vaultwarden's maintainers would be catching up from outside, with no deadline anyone has to respect. The apps could gate custom server URLs behind a license check. Or the store builds could drift from what's on GitHub, so that "the code is open" stays true while the thing on my phone is something else. Bitwarden sells enterprises its own server, and it has only ever tolerated Vaultwarden.

The third has a history. In October 2024 someone opened an issue titled Desktop version 2024.10.0 is no longer free software, because the app had started pulling in an SDK under Bitwarden's own license. Bitwarden called the build problem "merely a bug" and reorganized the SDK so the clients could be built from GPL code alone. Today the clients repository builds the browser extension, desktop app, web vault, and CLI twice: once as an "open source license" flavor, and once as a "commercial license" flavor that swaps the GPL SDK for a package under the Bitwarden SDK License. Both live on GitHub, and according to the announcement, the stores will get the second one.

People point to forks as the safety net, and with GPLv3 code that works on paper. On my iPhone, though, a fork needs a developer account, App Store review, and someone willing to maintain an AutoFill extension for years. Volunteers do that for a while. A password manager is also the one tool where a surprise breaks every login on every device at once.

That's why I won't wait. I waited with MinIO, the S3 object storage server a lot of self-hosters treated as the default (it used to show up in a lot of default docker-compose.yml templates). I ran it too, and every time the project took something away, I told myself the next change wouldn't reach me. MinIO moved from Apache 2.0 to AGPLv3 in 2021. In 2025 the community edition lost most of its admin interface to the paid product. In October 2025 the company stopped publishing prebuilt binaries and container images. In December the README announced maintenance mode and pointed people at the commercial AIStor product, and by February 2026 the top of the README read "THIS REPOSITORY IS NO LONGER MAINTAINED." The free edition that made MinIO popular is now a source-only repository nobody maintains. A license lets anyone fork, but the people who'll maintain a fork for years rarely show up on day one. I hoped it would go differently, and my hoping had no effect. I spent a while migrating from MinIO to Garage.

For the password manager, the easy answer comes from the company that has my email. Email is the one thing I've never self-hosted, and I'm not insane enough to chase deliverability problems, which is a polite way of saying I won't spend my weekends convincing Google's and Microsoft's filters that my email isn't spam. I used Fastmail for a couple of years and liked it, then moved to Proton because of its stronger privacy position. I'd make that call again, but I miss Fastmail's interface and especially its calendar. Encrypted mail and calendars are harder to make pleasant, and I've accepted that as the price. Renting this piece is easy for me because I use my own domain. The address stays mine and the provider is replaceable.

I was planning to leave Proton next year. I pay for Proton Unlimited, which covers mail, VPN, passwords, and storage. I use the mail and the VPN, and I never touched Proton Pass or Drive, because I didn't want all my eggs in one basket. Paying for a bundle I only half used made no sense, so the plan was Fastmail for mail (once it offers EU-based servers), Mullvad for VPN, and no bundle.

Mullvad was my favorite VPN. Then I read that one of its co-founders donated to a political party. I'm not white and I'm not European, and that party isn't aligned with anything about me. I don't want my monthly payment to end up there, and I know other people draw that line in different places. This is where mine is. I'm used to boycotting companies that don't share my values, or, as Americans love to say, voting with my wallet.

That knocked out half the plan, and my VPN stays with Proton. Bitwarden's news means my passwords may need a new home too, and the bundle I've been half ignoring already includes one. Adding passwords to the mail and VPN I already have there is the opposite of what I've spent years building, and I haven't decided to do it. I'm leaning toward Proton Pass, though. Its apps are open source and it can export my data, so leaving stays possible. Bitwarden has open source clients and exports too, and here I am. Proton can change its mind like any company, and I don't have a better argument than "so far, so good."

I'd still pick a self-hosted password manager if I found one where no part of the chain depends on a company putting up with me, with an iPhone app and AutoFill extension I'd trust to still be maintained in a few years. I'll go back to my favorite GitHub repository, awesome-selfhosted, and evaluate the password managers listed there. I don't know if I'll find one, but I know I won't wait for Bitwarden to sunset all its open source and self-hosted options.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论