Live data from Hacker News

Bitwarden raises $100M

bitwarden.com

201–210 of 522 posts

Re: Bitwarden raises $100M

#201

If you're a Bitwarden user and this doesn't worry you, you haven't been paying attention to the history of almost every company that has accepted VC funds. It doesn't matter how well intentioned the founders are - once you accept that kind of money, it's not your product anymore. You are now in the business of making money, nothing else, and those skewed incentives will start bleeding into their product and business…

Bitwarden is also open source and self hosted. If they should ever make their product not free, I can just keep running the last version and fork it to further improve it together with other people, can't I?

Re: Bitwarden raises $100M

#202

Question: all users of the free plan just don't use 2FA or Yubikey? I am amazed how that would be good policy in 2022. Nothing wrong with charging for a premium version, just curious how users handle things and why there seem to be so many users on the free plan. They all just don't know or care about 2FA?

You can use other free apps for 2FA, e.g. Authy. That might even be better for security because even if your password manager account is hacked/leaked, you would still have the 2FA setup in a separate app/platform. That being said, it’s of course more convenient to have passwords and 2FA tokens in the same app.

Re: Bitwarden raises $100M

#203
post #103

Earlier quoted context omitted.

How did I have to scroll this far down to find someone who's actually read the post? Everybody seems to think the money is purely for expanding the password manager, while in the post they call out adjacent markets they want to expand to. I'm cautiously optimistic that this could mean we won't see the end of Bitwarden, as those are areas where companies will pay big money.

It's not that people didn't read the statement, it's that people have learned not to trust statements like this. Ask all Heroku's customers who were just fired by Salesforce to focus on their enterprise offering for example.

¿Por qué no los dos?

Re: Bitwarden raises $100M

#204
post #149

Earlier quoted context omitted.

Maybe some sort of self hosting arrangement would work for you? I self-host Bitwarden behind a Wireguard VPN so it's only visible to devices I've authorised. Self-hosting comes with it's own risks of course but you would at least be in control of your data.

I do the same. I run bitwarden_rs as a docker container on a raspberry pi on my home network. Then use wireguard so I am always connected to my home network. This works great for my family. Simple set up, and I've done 0 maintenance on it.

Have you set your family up with Wireguard as well? Did you do the setup manually or do something else clever to get their devices in your network? I've been spending a lot of time thinking about this, and always end back up at MDM, which is not a terribly desirable ending, but can't necessarily put hands on a device readily for some of them.

Re: Bitwarden raises $100M

#205
post #194

Any Apple-devices users here? Why would I use this instead of Apple built-in password manager?

I think the biggest is simply having access to your data on non-apple devices and non-apple browsers. I.e. using it in Chrome or Firefox or whatever browser you want, as long as there's an extension that supports the browser it's likely available. You can store a lot more data in Bitwarden as well, including custom fields, so you aren't stuck with just a username and password and optional 2FA. With Bitwarden you can…

Apple released a Windows app that lets you access your keychain passwords. There's also a chrome extension.

Re: Bitwarden raises $100M

#206
post #128

Congrats to the Bitwarden team. Also wanted to mention it's a c# (dotnet) project for those who say dotnet isn't for startups.

Why would .net/C# have anything to do with the success or failure of a startup? Is this some weird SV bubble thing I'm seeing?

Kind of? It's been labeled enterprise in the past and comments here suggest it's frowned upon. It still ranks high in StackOverflow's survey too.

Re: Bitwarden raises $100M

#207
post #111

Earlier quoted context omitted.

> Why are large businesses “sharing passwords” between users? What happens when one user leaves? Because not all products businesses use have fine grain authentication and authorization. For example, their registar for their domain names. And differing employees need access to it at different times. > Isn’t sharing a password in a business context like “Things you shouldn’t do” 101? What do you think Bitwarden does?…

Now I’m curious and this comes from my job history is working at mostly small disorganized companies and then moving to one very large company where I work with other very large enterprises so I have no experience with mid size companies. Say I work for a large company where everything is gated via an SSO - email, Slack, internal apps, ADP for payroll, my brokerage account containing my 401K information (of course I…

> Now let’s say that BitWarden stores 10 passwords to external services and I had access to those passwords through Bitwarden. Does someone then have to go in and manually change passwords to those 10 services every time someone leaves?

To reframe this: Companies use both SSO and BitWarden, but because a typical company utilizes so many differing services with differing auth coverage (supports SSO? supports roles, permissions, etc.?) BitWarden fills the gap. BitWarden wouldn't be used for your ADP, and 401K. It may be used for your company's payment processor under one main username / password. It may be used for your root AWS account username and password. It may be used for your DNS management. Production API keys for Stripe may be stored there in plain text, but encrypted in your secret store of choice. Those are the typical use cases I see. The list of things you keep in BitWarden are small(er), but they're business critical. Whereas before they were held by the CTO of the early stage startup, now they're centralized, secured, have an audit trail, can be easily shared with others, etc. etc.

In the company I used BitWarden with, these passwords were rotated manually when an employee who had access to that password left and the new value updated in BitWarden. Maybe that's easier now?

Re: Bitwarden raises $100M

#208

I'm not referring to Bitwarden here but isn't this the standard M.O. of any SV startup? 1. Release great product for free 2. Attract as many free users as possible to signal growth to investors 3. Keep running the unprofitable free tier at a loss as long as possible using your massive VC war chest, while locking in your users with various gotchas 4. Once you reach critical scale and gained mass user adoption and you'…

Full disclosure, I'm a paying user of Bitwarden. I think for BW this kind of falls apart at #3. The main draw of this product for me and many others is that it's actually pretty no-frills. It's also broadly compatible with importing and exporting between dozens of other password managers. That said, this could be a blind spot for me. Let me know if there's any gotchas I should know about here.

It is fairly no frills. But they're gonna have to add some frills if they want to use up that $100M

Re: Bitwarden raises $100M

#209

If you're a Bitwarden user and this doesn't worry you, you haven't been paying attention to the history of almost every company that has accepted VC funds. It doesn't matter how well intentioned the founders are - once you accept that kind of money, it's not your product anymore. You are now in the business of making money, nothing else, and those skewed incentives will start bleeding into their product and business…

So just to be clear, "bootstrapped" means that you won't accept an offer of $100m, so we should trust you rather than bitwarden?

Well, yes. But to be fair, I bet there is a 5-year-old HN comment of a Bitwarden founder somewhere saying the same thing...

Re: Bitwarden raises $100M

#210

That is a LOT of money. $100M. That's enough money for ~50 people to live on $100k/year for the rest of their lives. You could pick 50 thinkers, scientists, artists and say "hey you never have to work again, just do your thing". But instead you invest it in a startup that will almost certainly burn it up in a couple of years of 7 figure salaries for execs and fail. What a waste.

You could always get your own $100M and spend it however you like. Incidentally I have worked at more than one startup that had a burn rate of about $100M/year, and most of it went to engineering and sales salaries. The execs tended to take little to no cash comp.
Post reply on HN