Watch the video, transcript and sources
- Bitwarden changes store-build license
- Quoted tilde makes PATH relative
+ Paid README tests find real frictionYou expect an open source password manager from the app store. Bitwarden says its next store builds will carry a commercial license. One staff reply changes how reassuring that announcement sounds. Keep it in mind. Bitwarden is a password manager that stores logins in an encrypted vault and fills them into websites. Its client code is public on GitHub. This story concerns the license attached to distributed apps.
On Friday, a Bitwarden employee announced the switch for the next release. By Sunday, developers were arguing over the downloaded app. Meanwhile, a shell shortcut points somewhere surprising, and somebody actually paid humans to read the instructions. Start with the distribution split. Store builds get the commercial license. The general public license version keeps getting updates on GitHub. All current features are available in both versions. The first useful reaction came from a volunteer moderator asking what would differ between the parallel versions. Identical features can still hide a changing roadmap. The diff can arrive before the code.
The repository already has two license categories. Its license file defaults to version three of the general public license, with separately licensed code elsewhere. The commercial agreement itself is dated twenty twenty. The birth of dual licensing predates this announcement. Then the employee answers. Some future components will exist only in the commercial build. Newly developed features get evaluated case by case. There is the moving boundary. Matching feature lists today leave room for different feature lists later, with no named feature or delivery date promised. The announcement also says the free plan stays, and an edited clarification says the code remains publicly auditable. Good. Trust matters for a password manager. Finding a second license behind the same download button adds homework to that relationship.
Visibility and permission are separate questions. Reading source helps an audit. Your permission to modify and redistribute a particular component comes from its applicable license. Check the actual package before trusting a familiar logo. So the first answer is the store build. The surviving path is the GPL version on GitHub. The future split is explicitly possible. You can keep using the current app while tracking that boundary, a hobby marginally cheaper than mechanical keyboards. That brings us to a boundary your shell can misunderstand. Disconnect3d's October second post resurfaced on Hacker News today after a sandbox flagged a writable path entry. The tiny character at the center of it is the tilde, our confident abbreviation for home.
Put that tilde inside a quoted path assignment and it stays literal. The example appends a bin directory. Bash's manual requires an unquoted tilde for that expansion. The quotes preserve that character. Lookup starts from your current directory, inside a directory actually named tilde. The author's demo finds a program there and prints hello. Home is unused by this literal entry. Your working directory gets a casting vote. That matters when you enter a directory somebody else controls. A relative search entry can change where a command is found. This post demonstrates the lookup behavior; it supplies no evidence of victims or a new shell vulnerability. The footgun arrived with the furniture.
The fix in the post uses the home environment variable inside the quotes. That variable expands, giving the intended home based directory. It also shows a command to search your path for literal tildes. Review each matching entry before changing your shell configuration, on shared machines. The unquoted assignment can expand the tilde in Bash, too. The trap is the quoted form shown here. A familiar symbol changes meaning with context, copying a configuration line lets you inherit assumptions. And assumptions are exactly what Terence Eden bought for inspection. In a post published today, he describes paying people twenty five euros for an hour testing ActivityBot's first run. The entire exercise cost around one hundred fifty euros, less than many meetings cost.
He asked testers to share their screen and speak aloud. He took notes, changed the readme after each session, and tested it again with the next person. It separates what the author remembers from what the document explains. The findings include a wrong demo link, confusing hidden file instructions and sections in an unhelpful order. Some people read the readme in a terminal. Eden also realized he hadn't explained what the software would do. The installation guide had successfully installed a question mark. My favorite finding is that his jokes confused people. Keep a prerequisite out of the clever sentence, including mine. A joke belongs after the fact. An installation step should survive being read by somebody who wants dinner.
These were informal usability sessions, with revisions between users. The post gives no controlled success rate or before and after percentage. Watch a fresh user try your instructions and listen when they hesitate. Back to that reassuring Bitwarden announcement. The sentence about all current features has a time limit built into the word current. The staff reply reserves future components for the commercial build. That's the detail to keep watching. Today's matching apps and tomorrow's licensing boundary can coexist.
Verdict: NEEDS REVIEW — Check the build and future parity
Sources
https://community.bitwarden.com/t/published-version-update-in-app-stores/102750
https://community.bitwarden.com/t/published-version-update-in-app-stores/102750/4
https://community.bitwarden.com/t/published-version-update-in-app-stores/102750/8
https://news.ycombinator.com/item?id=50033407
https://github.com/bitwarden/clients/blob/main/LICENSE.txt
https://github.com/bitwarden/clients/blob/main/LICENSE_BITWARDEN.txt
https://bitwarden.com/
https://bitwarden.com/help/bitwarden-security-white-paper/
https://disconnect3d.pl/2026/10/02/dont-put-tilde-in-your-path/
https://news.ycombinator.com/item?id=50042425
https://www.gnu.org/software/bash/manual/html_node/Tilde-Expansion.html
https://shkspr.mobi/blog/2026/10/i-paid-people-to-try-and-follow-my-readme/
https://news.ycombinator.com/item?id=50042219
And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.
YouTube · Newsletter · thedailydiff.dev · forward this to the intern who deployed on Friday.

