Live data from Hacker News

Bitwarden raises $100M

bitwarden.com

221–230 of 522 posts

Re: Bitwarden raises $100M

#221
post #192

Earlier quoted context omitted.

The people at Bitwarden and their supporters are familiar with countless examples of this playbook. Those tricks are not as easy to pull anymore. I have seen Bitwarden be very ethical in their business so far. I recommend it to my friends and family and to my company to pay for the service. It is a similar model to Nextcloud who successfully funds their business from governments and companies and provides it free to…

The server and client-side apps/extensions for Bitwarden are open source unlike Lastpass too. At worst, we'll have to fork a current release if BW does stupid things in the future.

until they aren't open source anymore and once the FOSS forks are many features behind the product, then they adjust pricing

Re: Bitwarden raises $100M

#222

I'm not referring to Bitwarden here but isn't this the standard M.O. of any SV startup? 1. Release great product for free 2. Attract as many free users as possible to signal growth to investors 3. Keep running the unprofitable free tier at a loss as long as possible using your massive VC war chest, while locking in your users with various gotchas 4. Once you reach critical scale and gained mass user adoption and you'…

Full disclosure, I'm a paying user of Bitwarden. I think for BW this kind of falls apart at #3. The main draw of this product for me and many others is that it's actually pretty no-frills. It's also broadly compatible with importing and exporting between dozens of other password managers. That said, this could be a blind spot for me. Let me know if there's any gotchas I should know about here.

I think the gotchas aren't for the early adopters and power users. It's for the people who will eventually make up the larger, more lucrative percentage of their user base starting with the friends and family of early adopters who are recommended to it.

Once they're set up with it, the idea of "importing and exporting between dozens of password managers" is meaningless. And gotchas aren't always limitations but can be "positive" like well meaning features, integrations, your company using it (so you too), etc. Lock-in comes in many forms.

Re: Bitwarden raises $100M

#223
post #4

I would never have someone else manage my passwords for me. You have to trust the server. It could serve the user with malicious JS code or an app update at any time. You can self host it though.

Do you trust yourself to do a good job though? It's a big responsibility. I know plenty of developers that would probably mess that job up one way or another. Certainly in a corporate situation, I'd not want to take that responsibility. Because now the company suffers if I mess up. That, in a nut shell is why companies like Bitwarden exist and why many companies choose to pay them rather than people like you and me to manage their passwords.

Re: Bitwarden raises $100M

#224

I'm not referring to Bitwarden here but isn't this the standard M.O. of any SV startup? 1. Release great product for free 2. Attract as many free users as possible to signal growth to investors 3. Keep running the unprofitable free tier at a loss as long as possible using your massive VC war chest, while locking in your users with various gotchas 4. Once you reach critical scale and gained mass user adoption and you'…

This is bad but how else do you fund a serious software project? Polished well tested and supported software is massively expensive to produce yet we've conditioned the market to believe it should be "free," which means the only way to really do it is to do something like the above.

If everyone expected a car to be free cars would be loaded with all kinds of convoluted bolted-on features to extract money from you: ads, special fuels that can only be produced by the maker, special licenses to drive on roads, special deals with repair shops, and so on.

What you describe is actually one of the less shady ways of funding software. The more common, successful, and shady methods are surveillance capitalism, addictionware (most of mobile gaming), and cryptocurrency scams.

If you structure the market such that honest business is difficult to impossible, things don't stop costing money. They just find less honest ways to make it.

Re: Bitwarden raises $100M

#225
post #181
post #133

Earlier quoted context omitted.

Isn't bitwarden[0] already open source and aren't you just asking people to trust you till you take VC money? [0] - https://github.com/bitwarden/server

Not only that but even the clients are open source ( https://github.com/bitwarden/clients ). There's even an unofficial Rust reimplementation of the server which is even better. Parent post is spreading FUD on this one.

The server and client are open-source, and independently audited regularly since 2018

https://bitwarden.com/blog/bitwarden-network-security-assess...

Re: Bitwarden raises $100M

#226
post #221
post #192

Earlier quoted context omitted.

The server and client-side apps/extensions for Bitwarden are open source unlike Lastpass too. At worst, we'll have to fork a current release if BW does stupid things in the future.

until they aren't open source anymore and once the FOSS forks are many features behind the product, then they adjust pricing

I switched to Bitwarden after using Lastpass for years and it's pretty feature-complete for me -- it has feature parity with LP and there's a bunch of features that I don't even use.

Even the unofficial Rust-based server looks to have more features than I need:

https://github.com/dani-garcia/vaultwarden/wiki

Re: Bitwarden raises $100M

#227
post #181
post #133

Earlier quoted context omitted.

Isn't bitwarden[0] already open source and aren't you just asking people to trust you till you take VC money? [0] - https://github.com/bitwarden/server

Not only that but even the clients are open source ( https://github.com/bitwarden/clients ). There's even an unofficial Rust reimplementation of the server which is even better. Parent post is spreading FUD on this one.

The product being open source doesn't prevent the situation the OP mentions. It just provides a mitigation or a workaround by forking.

I also hope it won't happen but many good projects have gone this way before.

In this case the investment is not for the password manager but for a new identity service. However if that doesn't end up providing the promised results, the shareholders will start looking at the existing successful product to extract more value. After all they own part of that now and they want their returns. It's just what they do. This will clash with the users' best interests sooner rather than later.

Then it becomes forking time but can they find a good maintainer? Open source is not always a guarantee for continuity.

Of course if the new project pans out this won't happen but it's a gamble, and one the existing userbase never asked for.

Re: Bitwarden raises $100M

#228

Keypassxc,keypassxc browser plug-in, strongbox app for iPhone. Cloud drive of your choice for syncing. Works well

Or SyncThing. This setup works and more people aren't considering it. The UI is great and the desktop app is not Electron based.

Re: Bitwarden raises $100M

#229
post #152

I switched to Bitwarden when LastPass started using silly tactics to make customers pay. I didn't switch because of the price - the service pricing of Bitwarden was a pleasant surprise. I switched because I lost all trust in LastPass. Managing credentials and sensitive information is all about trust. The second I lose trust in that kind of service, I don't just stop using it, I will most likely never even consider co…

> I don't give second chances to services that are trust based.

You might run out of services then at some point.

Human beings are fallible, full stop. Also, a company isn't an individual -- management teams change, corporate priorities change, security practices improve. Judging a whole company by what a few employees did or didn't do a decade ago isn't always going to yield an optimal approach.

Refusing to give any company a second chance ever is pretty extreme. Each individual case needs to be handled on its merits -- what happened, why did it happen, do you think the company learned and implemented new policies, how many other undiscovered vulnerabilities do you think are still there? But also, how many other undiscovered vulnerabilities do you think are still there for competitors as well? Just because a competitor hasn't had a breach doesn't necessarily means it's better, it might just be lucky so far.

Re: Bitwarden raises $100M

#230
post #152

I switched to Bitwarden when LastPass started using silly tactics to make customers pay. I didn't switch because of the price - the service pricing of Bitwarden was a pleasant surprise. I switched because I lost all trust in LastPass. Managing credentials and sensitive information is all about trust. The second I lose trust in that kind of service, I don't just stop using it, I will most likely never even consider co…

I bailed on lastpass when they doubled the annual price for the second year in a row. They had also just been acquired by LogMeIn, who didn’t have a great reputation.

I don’t know if I can manage another service switch. I can do it just fine, but my wife is more resistant to these kinds of changes and we need to be on the same page on this.

Post reply on HN