Live data from Hacker News

Bitwarden raises $100M

bitwarden.com

391–400 of 522 posts

Re: Bitwarden raises $100M

#391
post #237

Earlier quoted context omitted.

How is that realistic? If they expect to get 10 billion in 10 years, they need to have 100 million paying users (if they charge $10 per user per year), which is like the entire active users count of StackOverflow - https://en.wikipedia.org/wiki/List_of_social_platforms_with_...

Or they launch entirely new products, in the same general space, with new pricing structures that aren't tied to their current offerings. They're Okta + 1Password + ... To clarify: I'm not sure I buy the above thesis, but VCs don't expect 2x returns at this stage was my general point. They're aiming for higher.

For sure. The way I sum it up: VCs are looking for 10-to-1 odds on 100-to-1 gains. It depends on the stage, of course. This is listed as a series B, but feels kinda C-ish to me. Later stage rounds like that are unlikely to be 100-to-1, but I agree the goal is still well over 2-to-1.

Re: Bitwarden raises $100M

#392

Oh dear, this isnt good news at all. Now they're going to be under pressure to produce excessive returns to fatten the company up for an IPO or sale. Having seen what happened to Lastpass when it was passed around from pillar to post this saddens me deeply. Lets see what anti consumer measures they start introducing to force us to pay more. Limitations on the free tier look likely and price rises as well.

Look for vaultwarden

Re: Bitwarden raises $100M

#393

Earlier quoted context omitted.

Much more difficult syncability between desktop and mobile. Similarly, sharing a vault between multiple users is also quite more involved.

Sounds tempting, but my experience has been that when these nice companies raise a lot of money they go to shit. Dropbox comes to mind. Can you even imagine what kind of stuff they had to tell their investors in order to get 100m?

That's where Vaultwarden (https://github.com/dani-garcia/vaultwarden) comes in. You can use the official Bitwarden clients and fully host the backend by yourself. You don't need to trust Bitwarden with your data and can probably upgrade only when you need to, as the clients surely have some sort of backward compatibility.

Re: Bitwarden raises $100M

#394
post #152

I switched to Bitwarden when LastPass started using silly tactics to make customers pay. I didn't switch because of the price - the service pricing of Bitwarden was a pleasant surprise. I switched because I lost all trust in LastPass. Managing credentials and sensitive information is all about trust. The second I lose trust in that kind of service, I don't just stop using it, I will most likely never even consider co…

> I don't give second chances to services that are trust based. You might run out of services then at some point. Human beings are fallible, full stop. Also, a company isn't an individual -- management teams change, corporate priorities change, security practices improve. Judging a whole company by what a few employees did or didn't do a decade ago isn't always going to yield an optimal approach. Refusing to give any…

> You might run out of services then at some point

I prefer using services for my password management (I'm a bitwarden user who's currently happy as well), but I would jump back to some sort of self-hosted or even offline/manual sync solution if I thought that was the only way to keep my passwords safe. I like the convenience of a service, but I would sacrifice it over my security if it got to the point where I had to choose between the two.

Re: Bitwarden raises $100M

#395

Any Apple-devices users here? Why would I use this instead of Apple built-in password manager?

I tried bitwarden, and went back to 1Password. My ecosystem needs to be a bit independent for apple, just in case Apple starts acting like google, and locking users out of their accounts forever. The apple keychain has a really awful interface (surprising for apple) and family management is poor.

Not sure I understand, why did you switch back?

Re: Bitwarden raises $100M

#396

Earlier quoted context omitted.

I understand the temporary password use case. But what do you do when an employee leaves? Do you change all of the API keys?

Aren't we supposed to be rotating our keys when someone leaves no matter what technical solution to this problem we're using?

Well, I was trying to avoid the entire rant about using API Keys for security in the first place.

https://zapier.com/engineering/apikey-oauth-jwt/

https://cloud.google.com/endpoints/docs/openapi/when-why-api...

We all have done it at one point or another. But if I am ever in the middle of a technical presentation and mention “API Keys”, I get all types of dirty looks from security.

Notice that Square for instance strongly discourages API Keys for production.

https://developer.squareup.com/docs/build-basics/access-toke...

On the AWS side (where I work) we always discourage long term use of access key/secret keys for accessing resources even though I realize it’s necessary for some integrations. Even then, most organizations also put a condition that you can only use it from known IP addresses.

Re: Bitwarden raises $100M

#397

Earlier quoted context omitted.

from the founder of 1Password: would love to learn where you think it is worse. 1Password 8 has a ton of new features and it is faster than the previous version. Some of the new features like Universal Autofill and SSH Agent do not exist in any other product. It also fixes many problems that accumulated in the app over the years. More on features here: https://1password.com/products/features/ a more visual descriptio…

It’s more of a preference for a “real native Mac app” instead of an Electron app. Long time Mac users can feel the difference.

I see it from a different perspective. There are not that many real native Mac apps that both look and feel great. You could probably count them all on your hands.

Also, I certainly understand being the long time Mac expect. However, when we tested 1Password with new customers we found a ton of usability issues and many of these problems are solved in 1Password 8. One example, most new users couldn't even figure out how to create new items right away because of the look and the location of "New Item" button in the old app.

Re: Bitwarden raises $100M

#398
post #380
post #335

Earlier quoted context omitted.

I wish we’d stop with the cup of coffee comparison. Not everyone lives in the USA and drinks Starbucks. A cup of coffee costs 0.70€ where I live¹, cheaper than the cheapest (non-free) App Store app. Furthermore, I don’t drink coffee. For me it’s not about the price but the recurring cost and the lock in. I’d rather pay a larger sum upfront when I’m sure I can afford it and reevaluate when it’s time to upgrade than be…

Totally agree. Every single new subscription product someone buys that can't be run independently or avoid updates adds tech debt to their personal life. At some point that product will be killed, degraded, or made much more expensive. Software that can be purchased once and run indefinitely is all upside on the long tail. I wish more companies followed the Jetbrains model where a subscription buys lasting access to…

[deleted]

Re: Bitwarden raises $100M

#399
post #295
post #4

I would never have someone else manage my passwords for me. You have to trust the server. It could serve the user with malicious JS code or an app update at any time. You can self host it though.

I have bad news: it's not only true for the password manager. You have to trust the OS and every single apps you install on your computer because any of them could install a malicious update and steal all your passwords whenever you use them.

Not to mention all the code running at Ring -50 or whatever they're down to now (at least -3 iirc).

Re: Bitwarden raises $100M

#400
post #152

I switched to Bitwarden when LastPass started using silly tactics to make customers pay. I didn't switch because of the price - the service pricing of Bitwarden was a pleasant surprise. I switched because I lost all trust in LastPass. Managing credentials and sensitive information is all about trust. The second I lose trust in that kind of service, I don't just stop using it, I will most likely never even consider co…

> I don't give second chances to services that are trust based. You might run out of services then at some point. Human beings are fallible, full stop. Also, a company isn't an individual -- management teams change, corporate priorities change, security practices improve. Judging a whole company by what a few employees did or didn't do a decade ago isn't always going to yield an optimal approach. Refusing to give any…

BitWarden is based almost entirely on open source so it's possible to branch the project. Given some of the language on their website and their more recent attitude towards OS licenses, my prediction is that they will use the new funding to build as many closed source modules as possible to increase user switching costs, similar to what Google is trying to do with Chrome on top of Chromium. But that is a slow process that takes years, and a lot can happen between now and then.
Post reply on HN