RyanL Bitwarden Employee

Hello everyone!

Starting in the next release, the Bitwarden apps published to the various stores will be the commercially licensed builds. No action is needed, and the apps will work exactly as they do today.

Bitwarden remains committed to open source security and transparency
The GPLv3 OSS licensed version continues to be updated and published on GitHub
All current features are available in both versions
License details are on GitHub
Bitwarden remains committed to a robust, free forever plan for everyone

If you have any questions, please ask them in this thread. Thanks all!

EDIT:

Bitwarden is not going closed-source
You can still fork Bitwarden
No change to self-hosting, the licensing change affects those who are repackaging and reselling Bitwarden
The free plan is here to stay permanently
    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 hours ago

      That you didn’t need to sync it yourself?

      and that you have to never deal with sync conflicts. It’s a huge deal for those who are using tech but not understanding it, and a convenience for the rest

  • 1984@lemmy.today
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    1
    ·
    11 hours ago

    There is no way I’m self hosting something this important… So now I’m not sure what to do actually.

    • sonstwas@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      9
      ·
      6 hours ago

      That’s why I’m just using KeePass. It’s just an encrypted file that you can store on whatever storage you want and sync with existing solutions like Syncthing etc.

      Yes it’s a bit finicky when you edit the file on multiple devices before they’ve synced but it works very well for me…

    • ominous ocelot@leminal.space
      link
      fedilink
      English
      arrow-up
      3
      ·
      8 hours ago

      If self hosting is not an option. Ideas that come to mind:

      Evaluate what it is worth to you and maybe pay for it, if they offer enough worth to you and it is affordable.

      Then there are people who host it and provide it to others. Together with other apps, as a suite. Maybe that’s an option. But I suppose, donating or paying is expected here, too.

      Or switch to another solution. Preferably one with an import feature.

  • DanWolfstone@leminal.space
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    7 hours ago

    All these people keep saying that Vaultwarden won’t work because it relies on bitwarden’s API but if there is an incompatibility then wouldn’t vaultwarden just be left in a functional limbo? Like it’ll still work because self hosted but no more new features in parity with official client? Or have I misunderstood the connection between the two

    • WhyJiffie@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      3 hours ago

      this year there were 2 separate updates to bitwarden clients that fucked up vaultwarden servers, because the bitwarden developers “accidentally” reused a variable name in the data that was unused for a few years. but vaultwarden forgot to remove it, and now it is used in a different way, and the clients bugged away so hard that you had to uninstall them, because even if you was fortunate to be able to get to your passwords list you could not get it to sync otherwise

  • Lettuce eat lettuce@lemmy.ml
    link
    fedilink
    English
    arrow-up
    133
    arrow-down
    1
    ·
    22 hours ago

    Well, we all know how this ends…

    It’s a really sad day for me, I love Bitwarden, it’s easily the best password manager I’ve used, and I’m in IT, I’ve used a bunch.

    Fuck private equity, fuck it to death. But until then, I’ll be moving my test setup for KeyPassXC into production over the coming weeks and months.

    I was happily subscribed to Bitwarden for years for my personal account, I moved several people and a whole company onto it’s platform. We had a good run, time to move on.

    • 1984@lemmy.today
      link
      fedilink
      English
      arrow-up
      2
      ·
      11 hours ago

      100% but move where? I’m not going to self host something this critical. KeypassX is so much worse. I can’t even use it on mobile probably.

      • Lettuce eat lettuce@lemmy.ml
        link
        fedilink
        English
        arrow-up
        32
        arrow-down
        1
        ·
        19 hours ago

        If I’m going to have to host my own infrastructure, I don’t want it tied to Bitwarden, given the new direction of the company.

        I fully support Vaultwarden though, and I wish them well.

        I’ll be going with KeyPassXC and Syncthing.

      • lemmyvore@feddit.nl
        link
        fedilink
        English
        arrow-up
        20
        arrow-down
        2
        ·
        18 hours ago

        Vaultwarden (and all the client apps) depend on Bitwarden for the API spec. If Bitwarden introduces closed features in the API that Vaultwarden can’t/won’t implement, but the client apps do, it will split the spec. They can also introduce API license keys, which would render Vaultwarden mostly irrelevant.

        The only way for Vaultwarden to remain relevant going forward is to own it and split ways from Bitwarden. This would in turn mean that the FOSS client apps have to decide which to support. But I think the ecosystem is going to fragment eventually anyway, so the sooner every app decides which way they want to go, the better.

            • nibbler@discuss.tchncs.de
              link
              fedilink
              English
              arrow-up
              3
              ·
              8 hours ago

              History shows this will happen. Or do you have any counter example?

              Mariadb, libreoffice and most recently OpenCourant

              • Natanox@discuss.tchncs.de
                link
                fedilink
                English
                arrow-up
                2
                ·
                8 hours ago

                Not arguing against it of course, just dislike when people make forking (and establishing a whole new standard) sound like not that big of a deal.

                • nibbler@discuss.tchncs.de
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  8 hours ago

                  well, the first step of forking is clicking a button or execting a “git clone” command. thats trivial. publishing to android is a bit of work, but very one-time.

                  keeping up with development is a different story - but many foss projects thrive with support from whoever needs to have something fixed.

            • ryannathans@aussie.zone
              link
              fedilink
              English
              arrow-up
              7
              arrow-down
              7
              ·
              13 hours ago

              When presented a hypothetical between the commenter suggesting it be

              A) forked now

              And me suggesting

              B) forking when there is a problem

              You elect C) the commenter does the work?

              Brilliant contribution

      • altphoto@lemmy.today
        link
        fedilink
        English
        arrow-up
        8
        ·
        21 hours ago

        I’m. Using Vaultgarden but its not clear if the Android app will still be available.

          • dustyData@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            50 minutes ago

            It currently doesn’t work with Vaultwarden. The Linux client doesn’t accept custom certificates. And the Android client is paid. It is a dead-end for self-hosting.

            The license is also stupidly a single sentence. Which means that use could be nuked at any minute, and any money you use to pay the developer means nothing. If they wanted to kill the project today and nuke the repo, you have no legal rights, the project dies and fuck you and your passwords. That doesn’t exactly inspires confidence.

            • Artwork@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              4
              ·
              14 hours ago

              It is free and open-source on Desktop at this moment.

              Keyguard is a commercial app and unlocking a premium funds its further development and supports me (Artem Chepurnyi) directly. As of right now, only the Android builds distributed via Google Play store have main features locked behind a paywall, other distribution channels have a build with everything unlocked.

              Source: https://keyguard.dev/docs/premium/

              But it makes sense to pay for it, since Bitwarden is a constantly changing system and these projects based on it must always be up-to-date with their API changes, too. This is time and worry consuming, and should be compensated.

          • Artwork@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            14 hours ago

            Thank you very much for the awesome project mentioned! I had no idea about it!
            The marvel works great with Vaultwarden, too, it seems!

            Though, Bitwarden system/clients are not so featureful as KeePassXC, for example, it’s a great alternative for a more adequate synchronization.

    • phx@lemmy.world
      link
      fedilink
      English
      arrow-up
      15
      ·
      17 hours ago

      This seems to be clients for the end devices, which I’m worried may actually be a move towards locking out VaultWarden which will uses the BW Clients

  • Jul@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    21
    ·
    21 hours ago

    Sure, it’s no change for self hosters currently, but it’s one more step in moving towards a more closed platform overall. I do hope more FOSS client apps end up getting made sometime soon. I’ve been using Keyguard on Android for some time, which means the recent several breaking changes in the Bitwarden apps to the Vaultwarden backend haven’t hit me as hard, but I do still use the official apps for my laptop and desktop and Keyguard isnt fully FOSS, of course. I’d love to see some forks or brand new apps one of these days that are actually fully FOSS for both mobile and browsers. I’ve thought about doing some myself, but I have too many other projects and I also don’t have a MAC or want to pay the fees to make an iPhone version. And I abandoned my Android Developer account when they started the identity nonsense, so none of my apps are on the official store anymore and Fdroid and similar may not be viable soon, so it would only really be for myself and a few others who use alternate Android OS’s.

  • Pika@hikki.team
    link
    fedilink
    English
    arrow-up
    44
    ·
    1 day ago

    I guess we’re gonna see more open-source apps soon, aimed at Vaultwarden first

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    2
    ·
    edit-2
    34 minutes ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    Git Popular version control system, primarily for code
    SSH Secure Shell for remote terminal access
    TLS Transport Layer Security, supersedes SSL
    VPN Virtual Private Network

    [Thread #125 for this comm, first seen 11th Oct 2026, 04:30] [FAQ] [Full list] [Contact] [Source code]

  • Thomas Cloer@ieji.de
    link
    fedilink
    arrow-up
    36
    arrow-down
    3
    ·
    1 day ago

    @Mustachius_Grumpius “The GPLv3 OSS licensed version continues to be updated and published on GitHub

    All current features are available in both versions

    License details are on GitHub

    Bitwarden remains committed to a robust, free forever plan for everyone”

    • flop_leash_973@lemmy.world
      link
      fedilink
      English
      arrow-up
      13
      ·
      12 hours ago

      If there is no intention to put the screws to the user base, then why do it on the first place?

      We all know how this game ends when venture capital gets involved.

        • dustyData@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          43 minutes ago

          Split versions is usually the first step. Many projects have done so before. Next year there will be some technical reason they can’t keep feature parity with the commercial repository, and it will drift from the OSS repository. Oops, we broke compatibility, sowwy guys. A couple of years later the OSS repository will be closed because it is a security risk. By that point the company and management would’ve drifted so far from the initial values of the project that people won’t notice. Those who cared will have jumped ship to alternatives sooner, those who noticed later will be already too deep into depending on the software that they will keep paying the subscription.

          I have no evidence, but I also don’t have any doubts this is the plan.

    • badgermurphy@lemmy.world
      link
      fedilink
      English
      arrow-up
      77
      arrow-down
      1
      ·
      edit-2
      19 hours ago

      Unfortunately, there is no historical example where this hasn’t turned predatory. It’s a tale as old as venture capital has been in software development:

      • get free contributions from altruistic people donating their time and expertise to your FOSS project that you’re selling
      • make a closed-source set of extensions as optional dependencies
      • slowly diverge the closed source feature set to include developer and user “must-haves” you do not contribute upstream
      • slow or functionally halt open source contributions

      It is an oft-repeated long con to pull off a mass heist of donated skill and time while imposing vendor lock-in on your users through a back door.

      "As the poison spread through his body, the frog cried out, “Why did you sting me? You have killed us both!”

      The scorpion replied, “I couldn’t help it. It’s my nature.”

    • freely1333@reddthat.com
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 day ago

      I kinda thought the paid plan already had extra features no? Like silly ones but I swear it isn’t just donations right?

      • 4am@lemmy.zip
        link
        fedilink
        English
        arrow-up
        10
        ·
        23 hours ago

        It had cloud storage, built in TOTP with autofill, and some had features like organizations and sharing

        Still, this fucking sucks. Bitwarden was literally created as a ln answer to this shit happening to LastPass and Dashlane.

        • freely1333@reddthat.com
          link
          fedilink
          English
          arrow-up
          4
          ·
          21 hours ago

          I get it because minio dying burned me hard but so long as it keeps operating as it does now do we need more features? I would be fine with a continuously secure version of exactly what it does now. I kinda hate feature bloat

  • badgermurphy@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    ·
    23 hours ago

    Does anyone know if there’s any chance for a fork before this situation inevitably deteriorates? I dont know the license on that software enough to know if its an option.

      • ElectricVocalist@jlai.lu
        link
        fedilink
        English
        arrow-up
        10
        arrow-down
        2
        ·
        23 hours ago

        No, that would GPL. The benefit for them is that some features will be paid and won’t be unlockable just by using Vaultwarden

        • thr0w4w4y2@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          6
          arrow-down
          5
          ·
          22 hours ago

          it literally says in the post that the license change affects companies who are repackaging and reselling bitwarden, but ok.

          • nibbler@discuss.tchncs.de
            link
            fedilink
            English
            arrow-up
            16
            arrow-down
            1
            ·
            21 hours ago

            But this is the post by bitwarden, defending their decision. AKA marketing.

            Can you explain how bitwarden can be “repackaged and resold”, that would be stopped by that change?

            Everybody can still fork/rename/publish the FOSS version which is continued to be available. Everybody can connect to vaultwarden…?

            • lemmyvore@feddit.nl
              link
              fedilink
              English
              arrow-up
              5
              ·
              18 hours ago

              Everybody can still fork/rename/publish the FOSS version

              Yeah, but there’s no guarantee the FOSS version will be the same as the closed one.

              • nibbler@discuss.tchncs.de
                link
                fedilink
                English
                arrow-up
                1
                ·
                7 hours ago

                There is certainty that the Foss version won’t be worse than current bitwarden client. Then those will diverge. So?

                • lemmyvore@feddit.nl
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  7 hours ago

                  The current FOSS backend used to be the center of the ecosystem. Going forward that may change. If it stops being that center and it becomes merely a token offering so Bitwarden can claim “we’re still doing FOSS” then it will become pointless.

                  Simply forking the backend is meaningless without the work to also drag along the entire ecosystem, or establish a new one. Forking a project takes time, effort, vision, persistence, determination.

            • Buckshot@programming.dev
              link
              fedilink
              English
              arrow-up
              8
              ·
              20 hours ago

              Yeah this only makes sense if the builds start diverging from the open source code, extra features that are closed source.