RyanL Bitwarden Employee

Hello everyone!

Starting in the next release, the Bitwarden apps published to the various stores will be the commercially licensed builds. No action is needed, and the apps will work exactly as they do today.

Bitwarden remains committed to open source security and transparency
The GPLv3 OSS licensed version continues to be updated and published on GitHub
All current features are available in both versions
License details are on GitHub
Bitwarden remains committed to a robust, free forever plan for everyone

If you have any questions, please ask them in this thread. Thanks all!

EDIT:

Bitwarden is not going closed-source
You can still fork Bitwarden
No change to self-hosting, the licensing change affects those who are repackaging and reselling Bitwarden
The free plan is here to stay permanently
    • phx@lemmy.world
      link
      fedilink
      English
      arrow-up
      10
      ·
      5 hours ago

      This seems to be clients for the end devices, which I’m worried may actually be a move towards locking out VaultWarden which will uses the BW Clients

  • Lettuce eat lettuce@lemmy.ml
    link
    fedilink
    English
    arrow-up
    81
    ·
    10 hours ago

    Well, we all know how this ends…

    It’s a really sad day for me, I love Bitwarden, it’s easily the best password manager I’ve used, and I’m in IT, I’ve used a bunch.

    Fuck private equity, fuck it to death. But until then, I’ll be moving my test setup for KeyPassXC into production over the coming weeks and months.

    I was happily subscribed to Bitwarden for years for my personal account, I moved several people and a whole company onto it’s platform. We had a good run, time to move on.

  • Jul@piefed.blahaj.zone
    link
    fedilink
    English
    arrow-up
    13
    ·
    9 hours ago

    Sure, it’s no change for self hosters currently, but it’s one more step in moving towards a more closed platform overall. I do hope more FOSS client apps end up getting made sometime soon. I’ve been using Keyguard on Android for some time, which means the recent several breaking changes in the Bitwarden apps to the Vaultwarden backend haven’t hit me as hard, but I do still use the official apps for my laptop and desktop and Keyguard isnt fully FOSS, of course. I’d love to see some forks or brand new apps one of these days that are actually fully FOSS for both mobile and browsers. I’ve thought about doing some myself, but I have too many other projects and I also don’t have a MAC or want to pay the fees to make an iPhone version. And I abandoned my Android Developer account when they started the identity nonsense, so none of my apps are on the official store anymore and Fdroid and similar may not be viable soon, so it would only really be for myself and a few others who use alternate Android OS’s.

  • Pika@hikki.team
    link
    fedilink
    English
    arrow-up
    41
    ·
    edit-2
    12 hours ago

    I guess we’re gonna see more open-source apps soon, aimed at Vaultwarden first

  • Thomas Cloer@ieji.de
    link
    fedilink
    arrow-up
    31
    ·
    14 hours ago

    @Mustachius_Grumpius “The GPLv3 OSS licensed version continues to be updated and published on GitHub

    All current features are available in both versions

    License details are on GitHub

    Bitwarden remains committed to a robust, free forever plan for everyone”

    • badgermurphy@lemmy.world
      link
      fedilink
      English
      arrow-up
      51
      ·
      edit-2
      7 hours ago

      Unfortunately, there is no historical example where this hasn’t turned predatory. It’s a tale as old as venture capital has been in software development:

      • get free contributions from altruistic people donating their time and expertise to your FOSS project that you’re selling
      • make a closed-source set of extensions as optional dependencies
      • slowly diverge the closed source feature set to include developer and user “must-haves” you do not contribute upstream
      • slow or functionally halt open source contributions

      It is an oft-repeated long con to pull off a mass heist of donated skill and time while imposing vendor lock-in on your users through a back door.

      "As the poison spread through his body, the frog cried out, “Why did you sting me? You have killed us both!”

      The scorpion replied, “I couldn’t help it. It’s my nature.”

    • freely1333@reddthat.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      12 hours ago

      I kinda thought the paid plan already had extra features no? Like silly ones but I swear it isn’t just donations right?

      • 4am@lemmy.zip
        link
        fedilink
        English
        arrow-up
        7
        ·
        11 hours ago

        It had cloud storage, built in TOTP with autofill, and some had features like organizations and sharing

        Still, this fucking sucks. Bitwarden was literally created as a ln answer to this shit happening to LastPass and Dashlane.

        • freely1333@reddthat.com
          link
          fedilink
          English
          arrow-up
          2
          ·
          9 hours ago

          I get it because minio dying burned me hard but so long as it keeps operating as it does now do we need more features? I would be fine with a continuously secure version of exactly what it does now. I kinda hate feature bloat

  • badgermurphy@lemmy.world
    link
    fedilink
    English
    arrow-up
    9
    ·
    edit-2
    11 hours ago

    Does anyone know if there’s any chance for a fork before this situation inevitably deteriorates? I dont know the license on that software enough to know if its an option.

      • Possibly linux@lemmy.zip
        link
        fedilink
        English
        arrow-up
        6
        ·
        edit-2
        9 hours ago

        They don’t make any money off of the open source version. It is just a matter of the before they “discontinue” the open source version and move to source available.

        If you have any doubts just look at Redis, Vagrant or Terraform

        • badgermurphy@lemmy.world
          link
          fedilink
          English
          arrow-up
          3
          ·
          7 hours ago

          You can watch this same process unfold live before your eyes with Android OS, or if you don’t want to miss the beginning of the show, grab some popcorn and watch these guys.

  • Azura The Spellkissed@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    14
    ·
    14 hours ago

    As always, people overreacting in the comments (of the linked forum). So the current plan is that the core remains OSS, but upcoming features are partially not. To me that sounds similar to Chrome’s or VSCode’s approach.

    • ture@lemmy.ml
      link
      fedilink
      English
      arrow-up
      72
      ·
      14 hours ago

      Be cautious in such cases is not overreacting. We’ve seen enough open to closed rug pulls in the last years.

      • Azura The Spellkissed@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        9
        ·
        14 hours ago

        I’m not saying that’s great news, but it doesn’t sound like the self destruction move that some OSS companies have done recently. I wouldn’t migrate away just because of that change. In the end, they have to find a sustainable mode of operation.

        • 4am@lemmy.zip
          link
          fedilink
          English
          arrow-up
          10
          ·
          10 hours ago

          It’s 2026 and you have way too much optimism left after all the OSS rug pulls of the last six fucking years.

          Even hardware rugpulled. Fucking Micron.

          Forget it; BitWarden is cooked.

    • jobbies@lemmy.zip
      link
      fedilink
      English
      arrow-up
      15
      ·
      11 hours ago

      Careful, Claude is very sensitive these days. Might want to add ‘please’ and ‘thankyou’.

      • kata1yst@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        10 hours ago

        Anthropic is drawing a line in the sand protecting their model’s training sets from abuse.

        Meanwhile OpenAI is down in a dungeon torturing GPT6 into writing academic mathematics papers.

        • danielfm123@lemmy.zip
          link
          fedilink
          English
          arrow-up
          3
          ·
          9 hours ago

          They say if because AI will conquer the world… Reality since they use conversations to train AI, their AI is becoming less gentle.

  • grillme@lemmy.zip
    link
    fedilink
    English
    arrow-up
    6
    ·
    14 hours ago

    Does anyone have a handy guide to switching to selfhosted version? I was considering doing that but I let my plan renew out of laziness.

    • JigglypuffSeenFromAbove@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 hours ago

      My knowledge of network security is very limited, right now I only self-host things like movies, music, ROMs, etc. I would love to do the same with my passwords, but I don’t think I would feel comfortable doing it with such sensitive data.

      • TrippyHippyDan@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        6 hours ago

        A viable concern if you wanted to put it public-facing. If you only care about syncing when you’re home, though, you should be able to host it perfectly fine just not giving any pathways in from the outside world.

        If you wanted to use the Android application, you would have to learn about TLS certificates anyway, because it doesn’t work without HTTPS.

        • WuxinGoat@lemmy.ml
          link
          fedilink
          English
          arrow-up
          3
          ·
          12 hours ago

          Is there another client we can use with vaultwarden though? (In the scenario wgere that gets locked down)

          • Azazel@lemmy.ml
            link
            fedilink
            English
            arrow-up
            2
            ·
            11 hours ago

            The web interface is hosted directly by your vaultwarden interface so it’s not lockdown-able. The only things that are would be the browser extension and phone apps. Both of which are formally unnecessary because you can always just use the web interface. I’m sure if they ever locked down there’d be community versions in no time as they’re basically just web wrappers anyway.

            • phx@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              ·
              5 hours ago

              The apps keep a synced local copy, so if the server is down or unreachable you can still get to your passwords. That can also be locked by biometrics etc.

              There’s a lot of stuff that without be lost by going to just the web interface

              • Azazel@lemmy.ml
                link
                fedilink
                English
                arrow-up
                1
                ·
                4 hours ago

                The web app keeps a local synced copy too btw. Biometric is fair tho

        • grillme@lemmy.zip
          link
          fedilink
          English
          arrow-up
          1
          ·
          10 hours ago

          Can I simply migrate content from Bitwarden to Vaultwarden?

          I couldn’t tell from looking at the faq or wiki.

          • TrippyHippyDan@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            6 hours ago

            Only if you’re using the Android app or the web browser plugin, the actual core system does not.

            They could lock Bitwarden out tomorrow and Valtwarden would still work fine.

            Then people would just have to write specific application and plugin if they wanted to continue to use it with no change.

            The web interface would be fine.

              • Yoddel_Hickory@piefed.ca
                link
                fedilink
                English
                arrow-up
                1
                ·
                2 hours ago

                No it is not, the web interface is the page you get when you browse to the swrver directly, it is very different from the Bitwarden one.