Live data from Hacker News

Bitwarden raises $100M

bitwarden.com

431–440 of 522 posts

Re: Bitwarden raises $100M

#431

Earlier quoted context omitted.

I think the gotchas aren't for the early adopters and power users. It's for the people who will eventually make up the larger, more lucrative percentage of their user base starting with the friends and family of early adopters who are recommended to it. Once they're set up with it, the idea of "importing and exporting between dozens of password managers" is meaningless. And gotchas aren't always limitations but can b…

I have rotated out and back in to BW at least 3 times. Hardly locked in.

Out of curiosity, why so many rotations away (and back to) BW? Most people I know stick with a single password manager almost permanently, or at least unless their manager has some kind of earth-shattering vuln announced that just shakes their trust enough to move.

Re: Bitwarden raises $100M

#432

Earlier quoted context omitted.

How did I have to scroll this far down to find someone who's actually read the post? Everybody seems to think the money is purely for expanding the password manager, while in the post they call out adjacent markets they want to expand to. I'm cautiously optimistic that this could mean we won't see the end of Bitwarden, as those are areas where companies will pay big money.

It's because we're all still in the middle of getting burned by 1Password spending millions to make our app run worse and do less.

That perfectly describes the 1password situation.

Re: Bitwarden raises $100M

#433

Earlier quoted context omitted.

The company is providing a service of vault hosting around the free software they maintain. Hosting and maintenance has many costs that need to be covered somehow, and we want them to improve the service. The hosting costs of individual users with a free though generous account is supplemented by paying companies and governments. Users are not locked in, as they can easily download their vaults and move to another so…

> The hosting costs of individual users with a free though generous account is supplemented by paying companies and governments. I can think of a way to lower costs... :-/

Password vaults are trivially small to host. The marginal costs for these individual users is small. The bigger concern is if they try to monetize these users in some way that harms them. If they ever pulled something like that, many of us would quickly switch from being proponents to vociferous enemies of the company.

Re: Bitwarden raises $100M

#434
I really like bitwarden, but I do wish their internal API was more clear/open so 3rd party clients were easier to write. There have been a few times where I've been on an obscure OS on a device too slow to run a modern web browser, but wanted to use Bitwarden.

Re: Bitwarden raises $100M

#435

Earlier quoted context omitted.

> Why would a password manager need so much money? The announcement suggests they are looking to also launch their own authentication service and tools for managing application secrets.

How did I have to scroll this far down to find someone who's actually read the post? Everybody seems to think the money is purely for expanding the password manager, while in the post they call out adjacent markets they want to expand to. I'm cautiously optimistic that this could mean we won't see the end of Bitwarden, as those are areas where companies will pay big money.

Welcome to HN/Reddit. Most threads have people commenting without reading the article at all (or very briefly skimming). More or less just reacting to the headline.

And according to HN guidelines, we aren't supposed to comment on if someone has read the article or not. Stellar.

Re: Bitwarden raises $100M

#436
post #394

Earlier quoted context omitted.

> You might run out of services then at some point I prefer using services for my password management (I'm a bitwarden user who's currently happy as well), but I would jump back to some sort of self-hosted or even offline/manual sync solution if I thought that was the only way to keep my passwords safe. I like the convenience of a service, but I would sacrifice it over my security if it got to the point where I had t…

KeePass on a Google Drive or iCloud setup is pretty easy.

KeePassXC & KeePassDX + Syncthing is also pretty simple.

Re: Bitwarden raises $100M

#437

In the next couple of years, I expect FIDO2 Passwordless Auth to be ubiquitous, natively supported by all OS platforms. Built-in authentication credentials managers within Apple and Google/Android platforms will get more focused attention to improve them significantly. I suspect this should basically render the consumer market not monetizable. So, their free forever strategy here is aligned. In corporate market, I wo…

Why is it impossible to find out what the typical user experience of FIDO2 Passwordless Auth is? Every time I try and learn it's just a sea of acronyms I've never heard of before. How do I explain FIDO2 Passwordless Auth to my mother?

Most general case consumer explanation is likely this:

No more passwords. Your biometric authentication along with your Apple/Google account on your iPhone/Android phone is all you need.

A more detailed blurb would be:

You sign-up and sign-in to websites/apps simply by responding to a biometric unlock prompt of your phone (same as unlocking your phone with DoubleClick side button + FaceID etc). Your sign-in details are saved to your iCloud / Google account. You can sign-in to the same website/app on another device (iPhone/Mac; or Android/Chrome device) by signing into your cloud account.

For Pro users, there may be more advanced flow:

Instead of using built-in phone authenticators, you may use a reputed third party secure authentication app paired with an external FIDO key (like yubikey) to do the same thing. In it's most secure configuration, it may combine device binding secret unlocked with biometric auth, an physical FIDO key you possess, and a cloud hosted MPC key that is used based on fuzzy signals like your device location and other fingerprint data etc. All this gives you secure multi-factor authentication that is safe against phishing, theft, loss etc.

Re: Bitwarden raises $100M

#438

Earlier quoted context omitted.

It’s more of a preference for a “real native Mac app” instead of an Electron app. Long time Mac users can feel the difference.

I see it from a different perspective. There are not that many real native Mac apps that both look and feel great. You could probably count them all on your hands. Also, I certainly understand being the long time Mac expect. However, when we tested 1Password with new customers we found a ton of usability issues and many of these problems are solved in 1Password 8. One example, most new users couldn't even figure out…

[deleted]

Re: Bitwarden raises $100M

#439
post #436

Earlier quoted context omitted.

KeePass on a Google Drive or iCloud setup is pretty easy.

KeePassXC & KeePassDX + Syncthing is also pretty simple.

I actually used to use KeePassXC and have my (encrypted) password file sync'd through Dropbox, but their Android client changed to no support a way to have the file stored offline but also automatically sync changes, so I ended up swapping to Bitwarden. In the past I had used Nextcloud instead of Dropbox, so that would probably be one of my first ideas if I did end up deciding to stop using bitwarden.

Re: Bitwarden raises $100M

#440
post #194

Earlier quoted context omitted.

I think the biggest is simply having access to your data on non-apple devices and non-apple browsers. I.e. using it in Chrome or Firefox or whatever browser you want, as long as there's an extension that supports the browser it's likely available. You can store a lot more data in Bitwarden as well, including custom fields, so you aren't stuck with just a username and password and optional 2FA. With Bitwarden you can…

Keychain supports a 'secure note' type item which is just a blob you could drop some structured data into, but no way to specify a custom fancy form.

Right, but I often leave notes in my login items themselves. If the account doesn't use an email address to authenticate I might just put the email address in so if that email ever gets shut down I know which accounts need to be migrated, as an example of why I might do that.
Post reply on HN