Earlier quoted context omitted.
The people at Bitwarden and their supporters are familiar with countless examples of this playbook. Those tricks are not as easy to pull anymore. I have seen Bitwarden be very ethical in their business so far. I recommend it to my friends and family and to my company to pay for the service. It is a similar model to Nextcloud who successfully funds their business from governments and companies and provides it free to…
The server and client-side apps/extensions for Bitwarden are open source unlike Lastpass too. At worst, we'll have to fork a current release if BW does stupid things in the future.
Bitwarden raises $100M
221–230 of 522 posts
Re: Bitwarden raises $100M
#222I'm not referring to Bitwarden here but isn't this the standard M.O. of any SV startup? 1. Release great product for free 2. Attract as many free users as possible to signal growth to investors 3. Keep running the unprofitable free tier at a loss as long as possible using your massive VC war chest, while locking in your users with various gotchas 4. Once you reach critical scale and gained mass user adoption and you'…
Full disclosure, I'm a paying user of Bitwarden. I think for BW this kind of falls apart at #3. The main draw of this product for me and many others is that it's actually pretty no-frills. It's also broadly compatible with importing and exporting between dozens of other password managers. That said, this could be a blind spot for me. Let me know if there's any gotchas I should know about here.
Once they're set up with it, the idea of "importing and exporting between dozens of password managers" is meaningless. And gotchas aren't always limitations but can be "positive" like well meaning features, integrations, your company using it (so you too), etc. Lock-in comes in many forms.
Re: Bitwarden raises $100M
#223I would never have someone else manage my passwords for me. You have to trust the server. It could serve the user with malicious JS code or an app update at any time. You can self host it though.
Re: Bitwarden raises $100M
#224I'm not referring to Bitwarden here but isn't this the standard M.O. of any SV startup? 1. Release great product for free 2. Attract as many free users as possible to signal growth to investors 3. Keep running the unprofitable free tier at a loss as long as possible using your massive VC war chest, while locking in your users with various gotchas 4. Once you reach critical scale and gained mass user adoption and you'…
If everyone expected a car to be free cars would be loaded with all kinds of convoluted bolted-on features to extract money from you: ads, special fuels that can only be produced by the maker, special licenses to drive on roads, special deals with repair shops, and so on.
What you describe is actually one of the less shady ways of funding software. The more common, successful, and shady methods are surveillance capitalism, addictionware (most of mobile gaming), and cryptocurrency scams.
If you structure the market such that honest business is difficult to impossible, things don't stop costing money. They just find less honest ways to make it.
Re: Bitwarden raises $100M
#225Earlier quoted context omitted.
Isn't bitwarden[0] already open source and aren't you just asking people to trust you till you take VC money? [0] - https://github.com/bitwarden/server
Not only that but even the clients are open source ( https://github.com/bitwarden/clients ). There's even an unofficial Rust reimplementation of the server which is even better. Parent post is spreading FUD on this one.
https://bitwarden.com/blog/bitwarden-network-security-assess...
Re: Bitwarden raises $100M
#226Earlier quoted context omitted.
The server and client-side apps/extensions for Bitwarden are open source unlike Lastpass too. At worst, we'll have to fork a current release if BW does stupid things in the future.
until they aren't open source anymore and once the FOSS forks are many features behind the product, then they adjust pricing
Even the unofficial Rust-based server looks to have more features than I need:
Re: Bitwarden raises $100M
#227Earlier quoted context omitted.
Isn't bitwarden[0] already open source and aren't you just asking people to trust you till you take VC money? [0] - https://github.com/bitwarden/server
Not only that but even the clients are open source ( https://github.com/bitwarden/clients ). There's even an unofficial Rust reimplementation of the server which is even better. Parent post is spreading FUD on this one.
I also hope it won't happen but many good projects have gone this way before.
In this case the investment is not for the password manager but for a new identity service. However if that doesn't end up providing the promised results, the shareholders will start looking at the existing successful product to extract more value. After all they own part of that now and they want their returns. It's just what they do. This will clash with the users' best interests sooner rather than later.
Then it becomes forking time but can they find a good maintainer? Open source is not always a guarantee for continuity.
Of course if the new project pans out this won't happen but it's a gamble, and one the existing userbase never asked for.
Re: Bitwarden raises $100M
#228Keypassxc,keypassxc browser plug-in, strongbox app for iPhone. Cloud drive of your choice for syncing. Works well
Re: Bitwarden raises $100M
#229I switched to Bitwarden when LastPass started using silly tactics to make customers pay. I didn't switch because of the price - the service pricing of Bitwarden was a pleasant surprise. I switched because I lost all trust in LastPass. Managing credentials and sensitive information is all about trust. The second I lose trust in that kind of service, I don't just stop using it, I will most likely never even consider co…
You might run out of services then at some point.
Human beings are fallible, full stop. Also, a company isn't an individual -- management teams change, corporate priorities change, security practices improve. Judging a whole company by what a few employees did or didn't do a decade ago isn't always going to yield an optimal approach.
Refusing to give any company a second chance ever is pretty extreme. Each individual case needs to be handled on its merits -- what happened, why did it happen, do you think the company learned and implemented new policies, how many other undiscovered vulnerabilities do you think are still there? But also, how many other undiscovered vulnerabilities do you think are still there for competitors as well? Just because a competitor hasn't had a breach doesn't necessarily means it's better, it might just be lucky so far.
Re: Bitwarden raises $100M
#230I switched to Bitwarden when LastPass started using silly tactics to make customers pay. I didn't switch because of the price - the service pricing of Bitwarden was a pleasant surprise. I switched because I lost all trust in LastPass. Managing credentials and sensitive information is all about trust. The second I lose trust in that kind of service, I don't just stop using it, I will most likely never even consider co…
I don’t know if I can manage another service switch. I can do it just fine, but my wife is more resistant to these kinds of changes and we need to be on the same page on this.