Live data from Hacker News

Bitwarden raises $100M

bitwarden.com

61–70 of 522 posts

Re: Bitwarden raises $100M

#61
post #56

Earlier quoted context omitted.

How is vaultwarden more independent than bitwarden? Aren't they both FOSS and can be forked?

bitwarden server is mostly written by bitwarden's CTO. [1] If tomorrow bitwarden decides to do "a mongodb" (= violating the AGPL, and make it closed-source), you would have to spin up a new community to maintain the AGPL fork. [1] https://github.com/bitwarden/server/graphs/contributors

That's only possible if Bitwarden requires a CLA, do they require a CLA for commits/PRs?

Re: Bitwarden raises $100M

#62

Bitwarden already does one thing well. It's everything I'm looking for - open source, costs money but not much ($10/yr), 2FA, clean interface. I'm happy for the new investment, but I hope they don't start adding new things just for the sake of growing. Also - to the people who analyze funding rounds - $100M sounds like a huge amount to me. Why would a password manager need so much money?

With smartphones leading the push towards digital everything, passwords (auth / authz) have become the most important asset, even for consumers. Edit: An interesting conversation between Basecamp's DHH and 1Password's Teare on their series-a as an opportunity to de-risk the venture: https://archive.is/Kdnpz

Which has also become a single point of failure, and a target for social engineering since "lost device" or "stolen device" etc becomes to new defacto backdoor

Re: Bitwarden raises $100M

#63
post #37
post #12

The trend of open source spyware is really worrisome to me. More often than not these corporate open source projects include spyware features (Bitwarden included) that phone home without user consent. They claim selfhosting is a goal, yet their published client will report on your activity to Microsoft without your consent.

Citation (code snippet(s)?) please.

Not sure why dwbit's comment got killed, they furthered the conversation and sourced information well by, inter alia, linking to "What third-party services, libraries or identifiers are used in my Bitwarden account?" on Bitwarden's FAQ (https://bitwarden.com/help/security-faqs/#q-what-third-party...).

Re: Bitwarden raises $100M

#64

Earlier quoted context omitted.

> Why would a password manager need so much money? The announcement suggests they are looking to also launch their own authentication service and tools for managing application secrets.

How did I have to scroll this far down to find someone who's actually read the post? Everybody seems to think the money is purely for expanding the password manager, while in the post they call out adjacent markets they want to expand to. I'm cautiously optimistic that this could mean we won't see the end of Bitwarden, as those are areas where companies will pay big money.

>How did I have to scroll this far down to find someone who's actually read the post?

Welcome to Hacker News

Re: Bitwarden raises $100M

#65

Earlier quoted context omitted.

And the three companies behind the major platforms - Google, Apple, and Microsoft - have all agreed on a standard and will integrate a solution into their operating systems.

Yes, and what is that one like the 6th or more "auth standard" they all "agreed to" before promptly doing their own variations which then get spun into a new standard they all "agree" to before.......

Even if that is the case, storing passwords across devices is a solved problem and not enough people are willing to pay for it to be a profitable business.

“It’s a feature not a product”

Re: Bitwarden raises $100M

#66
post #56

Earlier quoted context omitted.

bitwarden server is mostly written by bitwarden's CTO. [1] If tomorrow bitwarden decides to do "a mongodb" (= violating the AGPL, and make it closed-source), you would have to spin up a new community to maintain the AGPL fork. [1] https://github.com/bitwarden/server/graphs/contributors

That's only possible if Bitwarden requires a CLA, do they require a CLA for commits/PRs?

Yep, https://contributing.bitwarden.com/contributing/#contributor...

Re: Bitwarden raises $100M

#67
post #32

Earlier quoted context omitted.

I use Vaultwarden (formerly bitwarden_rs) just for myself. I still use the Bitwarden extension in Firefox, which is a similar attack surface to what you describe, though probably a shade less vulnerable in practice. I’d like to replace it with something leaner and functionally superior (it’s pretty heavy, and has the major problem of mostly not working in Private Browsing windows, and some other timing/focus issues t…

Wouldn’t Firefox’ or chrome’s built-in password manager (with a master password set) be a better way of bringing a few frequently-used low-impact passwords closer to the internet, than a plug-in written by some developer?

An interesting perspective. From that of an attacker, the random plug-in might be a much lower hanging fruit, but also a much smaller one. Obscurity is not completely without merit.

Re: Bitwarden raises $100M

#68

Earlier quoted context omitted.

Yes, and what is that one like the 6th or more "auth standard" they all "agreed to" before promptly doing their own variations which then get spun into a new standard they all "agree" to before.......

Even if that is the case, storing passwords across devices is a solved problem and not enough people are willing to pay for it to be a profitable business. “It’s a feature not a product”

Given the number of businesses out there doing it I would venture to guess you are wrong.

Also Bitwarden and other password managers are not just about storing the passwords. For example on a personal level I use bitwarden family to manage my Parents passwords and to assist them with issue on various service, this gives me away to setup accounts and securely share passwords with them for the services, and vice versa

For business we use the Enterprise products to share passwords for everything...

None of which is a "solved problem" at the OS or Browser level

Re: Bitwarden raises $100M

#70
post #37
post #12

The trend of open source spyware is really worrisome to me. More often than not these corporate open source projects include spyware features (Bitwarden included) that phone home without user consent. They claim selfhosting is a goal, yet their published client will report on your activity to Microsoft without your consent.

Citation (code snippet(s)?) please.

[deleted]
Post reply on HN