Live data from Hacker News

Bitwarden raises $100M

bitwarden.com

181–190 of 522 posts

Re: Bitwarden raises $100M

#181
post #133

If you're a Bitwarden user and this doesn't worry you, you haven't been paying attention to the history of almost every company that has accepted VC funds. It doesn't matter how well intentioned the founders are - once you accept that kind of money, it's not your product anymore. You are now in the business of making money, nothing else, and those skewed incentives will start bleeding into their product and business…

Isn't bitwarden[0] already open source and aren't you just asking people to trust you till you take VC money? [0] - https://github.com/bitwarden/server

Not only that but even the clients are open source ( https://github.com/bitwarden/clients ).

There's even an unofficial Rust reimplementation of the server which is even better.

Parent post is spreading FUD on this one.

Re: Bitwarden raises $100M

#182

does bitwarden scale up to 20-30-50 thousand users?

I would love to hear the battle stories from a helpdesk from a 20K+ rollout of bitwarden.

The UX might be a bit uphill for non-techies. (Example: Tab, Vault, Send, Generator, Settings are what is displayed for the main browser interface. Can you guess what they do? Selecting a Keyboard icon is "view account".)

Re: Bitwarden raises $100M

#183

Earlier quoted context omitted.

1Password, a competitor, raised ~$650m earlier in the year off the back of exceptional growth. The investment case is likely: Bitwarden are doing well, 1Password are doing very well, maybe Bitwarden can do very well too with some additional capital. Password management is rapidly growing in mindshare, there's a big market and great room for growth, the amounts involved are commensurate with the opportunity -- every s…

1Password is 4x the price and is not open source. Doesn't 1Password's stronger backing provide more risk for Bitwarden investors too (chasing the same customers but with less to spend on acquisition)? Spitballing, $100M, assuming investors want 20% per annum return and Bitwarden do 50% profit ... they need 24M paying customers. Where are they at now?

Venture investments don't typically work that way: the goal isn't incremental returns YoY but rather major returns in the long term. Raise a fund, make a bunch of investments, report growth in valuation YoY (based on increasing valuations of portfolio) and then deliver returns once portfolio companies start to exit.

If BitWarden can use that $100m to 10x their valuation and then exit (whether that's an acquisition, going public etc.) the investors will have secured a win: if BitWarden's valuation stays where it is and returns ~$10m/year to the investor(s) over the next decade, that's not a great outcome considering the opportunity cost of capital.

Debt equity is the type of financing you're describing: lower risk, lower returns, not particularly exciting and not particularly attractive to investors if they believe the company has substantial upside potential.

Re: Bitwarden raises $100M

#184

I'm not referring to Bitwarden here but isn't this the standard M.O. of any SV startup? 1. Release great product for free 2. Attract as many free users as possible to signal growth to investors 3. Keep running the unprofitable free tier at a loss as long as possible using your massive VC war chest, while locking in your users with various gotchas 4. Once you reach critical scale and gained mass user adoption and you'…

The people at Bitwarden and their supporters are familiar with countless examples of this playbook. Those tricks are not as easy to pull anymore. I have seen Bitwarden be very ethical in their business so far. I recommend it to my friends and family and to my company to pay for the service. It is a similar model to Nextcloud who successfully funds their business from governments and companies and provides it free to individuals. This model can and does work well.

Re: Bitwarden raises $100M

#185

If you're a Bitwarden user and this doesn't worry you, you haven't been paying attention to the history of almost every company that has accepted VC funds. It doesn't matter how well intentioned the founders are - once you accept that kind of money, it's not your product anymore. You are now in the business of making money, nothing else, and those skewed incentives will start bleeding into their product and business…

Paying Bitwarden user here. This doesn't worry me that much. In the event that incentives get skewed (which isn't certain), I guess I could just stop updating the app before that happens, or fork the last good version? I'm interested in your alternative. I hadn't heard of it, went on your site and it looked decent, I think if I had seen this before going with Bitwarden I'd have seriously considered it, BUT now that I…

> This doesn't worry me that much. In the event that incentives get skewed (which isn't certain), I guess I could just stop updating the app before that happens, or fork the last good version?

This is easily said, but remember you're talking about a security-sensitive application. Do you really trust yourself to keep your fork secure? I know it doesn't look like it on the surface, but password managers have become wickedly complex, especially if you require things such as shared vaults, audit logs, a zero-knowledge architecture etc. The reality is maintaining your own fork won't be feasible for the vast majority of users, even those with a technical background.

> Why should I trust you (and a product I've only just learned about)?

The simple answer is that you shouldn't. You should ALWAYS be sceptical, and look for possible indicators of a company heading down the path to the dark side. Like taking a 9-figure sum of VC money for example ;)

Re: Bitwarden raises $100M

#186
post #127
post #109

Earlier quoted context omitted.

I just hope we won't get repeat of LastPass - some company buys it then just keeps on life support while raising prices. Also "OSS" version is not really open source, it's just core and all the features you really want from password manager are behind the paid license anyway

Like what? All the features that password manager needs to have (and features that 99% of people need) OSS version have it. SSO, organization management etc. is not something that "password manager" needs to have.

[deleted]

Re: Bitwarden raises $100M

#187
Oh dear, this isnt good news at all. Now they're going to be under pressure to produce excessive returns to fatten the company up for an IPO or sale. Having seen what happened to Lastpass when it was passed around from pillar to post this saddens me deeply. Lets see what anti consumer measures they start introducing to force us to pay more. Limitations on the free tier look likely and price rises as well.

Re: Bitwarden raises $100M

#188
post #152

I switched to Bitwarden when LastPass started using silly tactics to make customers pay. I didn't switch because of the price - the service pricing of Bitwarden was a pleasant surprise. I switched because I lost all trust in LastPass. Managing credentials and sensitive information is all about trust. The second I lose trust in that kind of service, I don't just stop using it, I will most likely never even consider co…

What specifically did they do to trick you into paying?

Re: Bitwarden raises $100M

#189
post #127

Earlier quoted context omitted.

Like what? All the features that password manager needs to have (and features that 99% of people need) OSS version have it. SSO, organization management etc. is not something that "password manager" needs to have.

Like TOTP, which is part of payed variant and I consider that an essential feature of a password manager in 2022. Don't get me wrong, I am not complaining about that business decision, just answering since you asked.

To be fair, TOTP should be a separate device to fulfil the criteria of actually being 2FA.

Re: Bitwarden raises $100M

#190
Question: all users of the free plan just don't use 2FA or Yubikey? I am amazed how that would be good policy in 2022.

Nothing wrong with charging for a premium version, just curious how users handle things and why there seem to be so many users on the free plan. They all just don't know or care about 2FA?

Post reply on HN