When did Bitwarden turn to the dark side?

Following my post in 2017, Bye Bye LastPass, Hello Bitwarden I’ve been a very happy Bitwarden user. That was until a couple of nights ago when I got a message from my bank informing me that my credit card was now blocked and was caused by Bitwarden attempting to take money from my card.

It wasn’t that I was unaware of this payment, as Bitwarden had sent me an email, about two weeks ago.

Don’t get me wrong, up to this point my sub was $10 per year which was amazingly good value in my view and I was perfectly happy to renew at this new rate. What really rubbed me up the wrong way was that I knew my credit card had expired months ago, so I logged into my BitWarden account to find my new card details already there. I was a bit concerned that they had auto filled it from the new card details stored in my vault so sent an email asking where they had obtained my new card details. Here is the reply:

Per Stripes documentation, saved payment method details can continue to work even if the issuing bank replaces the physical card. Stripe works with card networks and automatically attempts to update saved card details whenever a customer receives a new card (for example, replacing an expired card or one that was reported lost or stolen). This allows your customers to continue using your service without interruption and reduces the need for you to collect new card details whenever a card is replaced. Stripe gets your updated card details through an official banking network feature called a Card Account Updater (CAU) or Automatic Card Updates. I believe if the card number is the same, and only the expiration date is needing to be updated, Stripe checks with the card networks in the background for saved payment methods. If a new card number or expiration date exists, the network securely passes the refreshed data to Stripe, which updates your vaulted details automatically so subscriptions or recurring payments do not fail.​​Automatic card updates require card issuers to participate with the network and provide this information. It’s widely supported in the United States, allowing Stripe to automatically update most American Express, Visa, Mastercard, and Discover cards issued there. International support varies from country to country.

I replied that I’d never had this before and found it extremely sneaky and underhanded. As a loyal customer I would have been perfectly fine updating the card details myself and asked the rep to record it as feedback that I was unhappy with the way it was done, not the amount or BitWarden service itself.

I decided to drop it and move on, until I got the message from my bank that my card had been blocked!

I had to spend a good hour on the phone to firstly wait in an annoying queue getting told my call is important and they were ever-so busy before getting to speak to someone real.

I asked the adviser why my bank suddenly, after 8 years of paying BitWarden the yearly fee, considered the transaction to be “unusual” and was told it was to protect me as a customer. What from I asked? Well we may have had a number of charge-backs relating to this merchant.

I wrote to Bitwarden again regarding the blocking of my card and have yet to get a proper reply, bar one, which feels AI generated and jumped on my comment about “driving loyal customers away to the likes of Proton Pass”, replied with instructions on how to cancel the subscription :/

So my question is, when did BitWarden turn to the dark side? Why all of a sudden have they doubled the subscription? Why do they think they are entitled to the subscription fee?

I’ve never agreed to a rolling subscription model. They send me an invoice and I decide if I want to pay it, simples! I dunno, I just expected better from BitWarden and feeling very betrayed right now. Any suggestions on alternative open source projects?

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.