Bitwarden Dual License Model
Cider9986
368 points
263 comments
October 10, 2026
Related Discussions
Found 5 related stories in 93.5ms across 9,063 title embeddings via pgvector HNSW
- AurionMail: E2EE suite (CryptPad/Stalwart) with single-password UX polo46 · 31 pts · August 26, 2026 · 41% similar
- Show HN: macOS data protection keychain for Electron apps biwills · 23 pts · August 18, 2026 · 41% similar
- Two-tier encryption in the UK ReturnoftheHack · 406 pts · September 24, 2026 · 40% similar
- I built a hardware-bound local password vault hidden in a photo BlindLock · 16 pts · August 31, 2026 · 38% similar
- Ask HN: Advice on Migrating from 1Password? 0xbadcafebee · 102 pts · September 03, 2026 · 38% similar
Discussion Highlights (20 comments)
figmert
This was always inevitable when they took funding.
petterroea
Yet another elasticsearch. Or terraform. Or redis. I guess? Oss trying to protect itself from scalpers?
dannyw
I actually find this somewhat understandable; and I'll be continuing my subscription; as long as all source continues to be available and personal self-hosting remains a viable option. Yes, I'd much prefer full open source, but "all source available; some restrictions on commercial use" is still miles better; the OSS funding and incentives problem is still unsolved. Just look at Elasticsearch -> AWS ElasticSearch; or Redis -> ElastiCache; etc. It's like leeching: a big corporation, with far more distribution and brand takes your codebase; and their structural advantages (in terms of distribution) makes it an extremely difficult uphill battle for you to compete. I struggle to think of solutions: yes, they are doing everything by the license; so the main viable solution seems to be... changing the license.
solarkraft
I’m willing to commit money to a project committed to release free builds without these shenanigans.
hn3ufz62f7
Ran Vaultwarden for a team of ~15 for years and that's the part I'd watch here, the clients are the leverage, not the server. If the mobile apps stop being buildable from source the self host story gets a lot thinner.
inexcf
Well seems like Bitwarden is dying. A clear move towards enshittification. I was fine with the premium subscription existing while i was self-hosting Vaultwarden, but now every step seems to make that worse. Now new features will be under the commercial license an everything else will be slowly neglected. Time to jump ship.
Cider9986
This is enshittification but I'm not gonna drop Bitwarden unless they do something really bad. I'm already on the F-Droid version from their GitHub for my GrapheneOS phone because that one has no Google services/telemetry. One of the family members I set up with Bitwarden has said it changed their life and they can't imagine not using it. I would guess that would apply to any crossplatform password manager but Bitwarden is quite good and the one that stuck. I probably wouldn't move to one of these [1] because I don't like the UI of Proton Pass, the convenience of KeyPass, and 1Passsword is obvious. I'm interested in AliasVault as it seems to be a more privacy-focused password manager, which is cool, but I'd have to look more into it. [1] https://www.privacyguides.org/en/passwords [2] https://discuss.privacyguides.net/t/aliasvault-open-source-e...
0l
IMO Bitwarden really isn't that well engineered software, and I now use Keyguard on Android/Vaultwarden server instead. Reminds me of Subsonic, with many competing clients/servers. Hopefully someone will write a third party browser extension as the current one is quite slow/buggy.
arjie
Okay, it’s good they have the open source because if you rewrite the Chrome extension you can get it to load in under 100 ms after you click the button. If you use the standard Chrome extension you’re not having that happen on an M1 Max. Their stuff is far too heavy. Full JS framework to display a small box.
mindracer
This seems like the beginning of the end, what password manager is recommended now?
karel-3d
I don't understand the point or the motivation. They don't list any. It's very badly explained what actually changes
anilgulecha
Rust based vaultwarden awaits.
rsyring
Very insightful blog post listed by another user as a sub-comment. Worth posting as a top-level comment: https://blog.ppb1701.com/the-quiet-renovation-at-bitwarden Previously discussed: https://news.ycombinator.com/item?id=48163389
rvz
The problem with this license change is that it is unenforceable, now that developers believe they can vibe-code their own. Only a matter of time until we see "OpenWarden", just like we saw the migration from Redis to Valkey. But let's be honest. "enshittification" here really means "I don't want to pay for my tools and I want it completely for free forever." Just look at the reactions towards the single UI change made in Firefox on HN [0] and already the complaints are there. Even if you charge your users $1 to remove tracking it is somehow "enshittification" because $1 is too much to pay for software maintenance. The real cost of maintenance is the amount raised in VC capital (Bitwarden raised $100M) or $600M a year (Google paying Firefox). Donations won't cover the capital needed to fund Firefox or Bitwarden's development at all. "Open source" is only sustainable when someone else is paying for that maintenance. Small donations will only take you so far until one core developer says that they are underpaid. [0] https://news.ycombinator.com/item?id=49892721
caaqil
Unless they pull the LastPass crap, this is not a big deal for regular users.
scotty79
I'll be moving to PearPass ... there's really no reason for any company to hold my passwords for me.
charcircuit
I don't see hours this business strategy works post LLMs. Someone's just going to immediately prompt into existence any commercial feature you make into the open source side.
contravariant
I'm a bit confused what they're actually doing. Their code is now covered by two different licenses with each file licensed under one of the two and they claim the resulting application is using the commercial Bitwarden license and not the GPL license? How on earth does that work? Is that something the GPL license even allows? This sounds like they're just taking a GPL licensed application and using it for themselves to make money.
zeroonetwothree
I’ve been a premium subscriber for 10+ years and I have to admit I don’t really care about this license stuff. As long as it keeps working well I’m happy.
robertlane0
Licensing changes aside, this is why I've never been enthused for hosted password management, it's too easy for the terms of the agreement to change. (And in the case of LastPass, endless breaches). Honestly, plain KeePassXC and an arrangement to sync the password database has served me well because I can use any compatible client I can trust with it.