# Bitwarden switches store builds to a commercial license

Published: 2026-10-12

Bitwarden says the next release of its store-distributed apps will use a commercial license, while GPLv3 builds continue to be updated on GitHub. Current features remain available in both versions; a staff reply reserves some future components for the commercial build, with features evaluated case by case. This October 11 Daily Diff also explains a literal tilde in a quoted PATH entry and Terence Eden's paid README usability sessions. Niko's verdict is NEEDS REVIEW: inspect the exact build and license, then watch future feature parity.

Canonical: https://thedailydiff.dev/video/bitwarden-store-license/

## What this video covers

- The upcoming distribution change applies to store builds. Bitwarden also says direct downloads will use the commercial license; do not assume the website download is the GPL build.
- Bitwarden says current features remain in both versions, GPL builds continue on GitHub and the free plan remains. These are company statements; no independent binary/source equivalence audit is claimed.
- The clients repository already categorizes GPLv3 and Bitwarden License v1.0 code. This event changes distributed-build licensing rather than introducing the repository's first mixed license structure.
- A staff reply says some future components will exist only in the commercial build. No particular feature or delivery date is named, so future parity remains an inspection task.
- Source visibility and modification or redistribution permission are different checks. Review the exact package and applicable notices before assuming every component has the same license.
- A quoted tilde can remain literal in a PATH assignment, creating a relative entry resolved from the current directory. The blog's quoted $HOME correction expands the intended home directory; unquoted Bash assignment semantics differ.
- Terence Eden describes paying €25 for an hour of ActivityBot first-run testing, around €150 total, with screen sharing, spoken feedback and README revisions between sessions. The informal account supplies no controlled success-rate improvement.
- A fresh user can expose wrong links, confusing hidden-file instructions and missing product explanations that the author silently supplies from memory. Keep required installation facts clear and jokes outside prerequisites.

## Chapters

- 0:00 Which Bitwarden build are you getting?
- 0:42 Where does the GPL build go?
- 1:16 What could diverge in future releases?
- 2:10 When does tilde stop meaning home?
- 3:00 How do you inspect the actual PATH?
- 3:26 What did €150 of README testing find?
- 4:29 Which word changes the reassurance?
- 4:53 What would I review before switching?

## Transcript

### Which Bitwarden build are you getting?

0:00 You expect an open source password manager from the app store. Bitwarden says its next store builds will carry a commercial license. In this video, which build changes? Which rights survive? And what could split later? One staff reply changes how reassuring that announcement sounds. Keep it in mind. It's Sunday, October eleventh, and this is The Daily Diff.

0:19 Bitwarden is a password manager that stores logins in an encrypted vault and fills them into websites. Its client code is public on GitHub. This story concerns the license attached to distributed apps. On Friday, a Bitwarden employee announced the switch for the next release. By Sunday, developers were arguing over the downloaded app. Meanwhile, a shell shortcut points somewhere surprising, and somebody actually paid humans to read the instructions.

0:41 Start with the distribution split.

### Where does the GPL build go?

0:43 Store builds get the commercial license. The general public license version keeps getting updates on GitHub. All current features are available in both versions. The first useful reaction came from a volunteer moderator asking what would differ between the parallel versions. Identical features can still hide a changing roadmap. The diff can arrive before the code. The repository already has two license categories.

1:05 Its license file defaults to version three of the general public license, with separately licensed code elsewhere. The commercial agreement itself is dated twenty twenty. The birth of dual licensing predates this announcement. Then the employee answers.

### What could diverge in future releases?

1:17 Some future components will exist only in the commercial build. Newly developed features get evaluated case by case. There is the moving boundary. Matching feature lists today leave room for different feature lists later, with no named feature or delivery date promised. The announcement also says the free plan stays, and an edited clarification says the code remains publicly auditable. Good. Trust matters for a password manager.

1:40 Finding a second license behind the same download button adds homework to that relationship. Visibility and permission are separate questions. Reading source helps an audit. Your permission to modify and redistribute a particular component comes from its applicable license. Check the actual package before trusting a familiar logo. So the first answer is the store build. The surviving path is the GPL version on GitHub. The future split is explicitly possible.

2:04 You can keep using the current app while tracking that boundary, a hobby marginally cheaper than mechanical keyboards.

### When does tilde stop meaning home?

2:10 That brings us to a boundary your shell can misunderstand. Disconnect3d's October second post resurfaced on Hacker News today after a sandbox flagged a writable path entry. The tiny character at the center of it is the tilde, our confident abbreviation for home. Put that tilde inside a quoted path assignment and it stays literal. The example appends a bin directory. Bash's manual requires an unquoted tilde for that expansion. The quotes preserve that character.

2:34 Lookup starts from your current directory, inside a directory actually named tilde. The author's demo finds a program there and prints hello. The home directory never participates. Your working directory gets a casting vote. That matters when you enter a directory somebody else controls. A relative search entry can change where a command is found. This post demonstrates the lookup behavior; it supplies no evidence of victims

2:56 or a new shell vulnerability. The footgun arrived with the furniture. The fix in the post uses the home environment variable inside the quotes.

### How do you inspect the actual PATH?

3:03 That variable expands, giving the intended home based directory. It also shows a command to search your path for literal tildes. Review each matching entry before changing your shell configuration, on shared machines. The unquoted assignment can expand the tilde in Bash, too. The trap is the quoted form shown here. A familiar symbol changes meaning with context, copying a configuration line lets you inherit assumptions.

3:25 And assumptions are exactly what Terence Eden bought for inspection.

### What did €150 of README testing find?

3:29 In a post published today, he describes paying people twenty five euros for an hour testing ActivityBot's first run. The entire exercise cost around one hundred fifty euros, less than many meetings cost. He asked testers to share their screen and speak aloud. He took notes, changed the readme after each session, and tested it again with the next person. It separates what the author remembers from what the document explains.

3:51 The findings include a wrong demo link, confusing hidden file instructions and sections in an unhelpful order. Some people read the readme in a terminal. Eden also realized he hadn't explained what the software would do. The installation guide had successfully installed a question mark. My favorite finding is that his jokes confused people. Keep a prerequisite out of the clever sentence, including mine. A joke belongs after the fact.

4:14 An installation step should survive being read by somebody who wants dinner. These were informal usability sessions, with revisions between users. The post gives no controlled success rate or before and after percentage. Watch a fresh user try your instructions and listen when they hesitate.

### Which word changes the reassurance?

4:29 Back to that reassuring Bitwarden announcement. The sentence about all current features has a time limit built into the word current. The staff reply reserves future components for the commercial build. That's the detail to keep watching. Today's matching apps and tomorrow's licensing boundary can coexist. Keep the boundary visible. If you'd rather read this than hear me say it, the diff lands in your inbox every morning, free at the daily diff dot dev, link below.

4:52 So today's verdict is NEEDS REVIEW.

### What would I review before switching?

4:55 I'd keep using it while checking which build and license my workflow depends on, and watching future feature parity. Subscribe, hit the bell, and tell me in the comments if you'd have stamped it differently. And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.

## Sources

- [Published version update in app stores](https://community.bitwarden.com/t/published-version-update-in-app-stores/102750) — Bitwarden Community / RyanL
- [Future components and case-by-case licensing — reply 4](https://community.bitwarden.com/t/published-version-update-in-app-stores/102750/4) — Bitwarden Community / RyanL
- [Direct-download and source-visibility clarification — reply 8](https://community.bitwarden.com/t/published-version-update-in-app-stores/102750/8) — Bitwarden Community / RyanL
- [Client repository license map](https://github.com/bitwarden/clients/blob/main/LICENSE.txt) — Bitwarden on GitHub
- [Bitwarden commercial source-module license](https://github.com/bitwarden/clients/blob/main/LICENSE_BITWARDEN.txt) — Bitwarden on GitHub
- [Bitwarden Password Manager](https://bitwarden.com/) — Bitwarden
- [Security whitepaper — encrypted vault definition](https://bitwarden.com/help/bitwarden-security-white-paper/) — Bitwarden
- [Bitwarden licensing discussion](https://news.ycombinator.com/item?id=50033407) — Hacker News
- [The tilde in your PATH may not be your HOME](https://disconnect3d.pl/2026/10/02/dont-put-tilde-in-your-path/) — Disconnect3d
- [Tilde Expansion](https://www.gnu.org/software/bash/manual/html_node/Tilde-Expansion.html) — GNU Bash manual
- [Quoted tilde discussion](https://news.ycombinator.com/item?id=50042425) — Hacker News
- [I paid people to try and follow my README](https://shkspr.mobi/blog/2026/10/i-paid-people-to-try-and-follow-my-readme/) — Terence Eden
- [Paid README testing discussion](https://news.ycombinator.com/item?id=50042219) — Hacker News
