Live data from Hacker News

Bitwarden raises $100M

bitwarden.com

501–510 of 522 posts

Re: Bitwarden raises $100M

#501

Earlier quoted context omitted.

Why is it impossible to find out what the typical user experience of FIDO2 Passwordless Auth is? Every time I try and learn it's just a sea of acronyms I've never heard of before. How do I explain FIDO2 Passwordless Auth to my mother?

Most general case consumer explanation is likely this: No more passwords. Your biometric authentication along with your Apple/Google account on your iPhone/Android phone is all you need. A more detailed blurb would be: You sign-up and sign-in to websites/apps simply by responding to a biometric unlock prompt of your phone (same as unlocking your phone with DoubleClick side button + FaceID etc). Your sign-in details a…

Stupid question:

How to mitigate loss of phone, lets say on holidays?

Re: Bitwarden raises $100M

#502

Bitwarden already does one thing well. It's everything I'm looking for - open source, costs money but not much ($10/yr), 2FA, clean interface. I'm happy for the new investment, but I hope they don't start adding new things just for the sake of growing. Also - to the people who analyze funding rounds - $100M sounds like a huge amount to me. Why would a password manager need so much money?

> Why would a password manager need so much money? The announcement suggests they are looking to also launch their own authentication service and tools for managing application secrets.

I would love for Bitwarden to use this money to make SSO available to all pricing levels. Currently, in order to use SSO with Bitwarden you have to be on their "Enterprise" plan. I think SSO is too important to gate behind a paywall, especially for a company whose main product is security.

Re: Bitwarden raises $100M

#503

Earlier quoted context omitted.

>1Password’s desktop app is much worse than it use to be all while each platforms built in capabilities are getting better. I keep reading this but as a user of 1Password over the past decade or so, the functionality hasn't changed much. I'm confused as to what they're spending all the VC money on because these re-writes haven't done much but in terms of functionality, I think it's best in class. What am I missing?

While I don’t have any opinion about the features, they did have native app and now the app is Electron based.

I use Bitwarden and almost never use the app. Most of my interaction comes from the browser plug-in and Bitwarden.com.

Re: Bitwarden raises $100M

#504
post #97

Bitwarden replaced lastpass for me and really i'd never go back. My only gripe is filling in card details, there is never a floating icon to click to do it automatically, you need to go to the menu bar and select the card. Apart from that all perfect!

The only thing I miss from LastPass is the ability to store different types of credentials. Bitwarden offers a couple of basic things (login, credit card, identity, secure note) but LastPass allowed you to create new, custom credentials.

One of the things I used to store in LP was AWS IAM creds. Sure, you can store it in a Bitwarden "secure note" but it sure was convenient to have a defined format for it.

Re: Bitwarden raises $100M

#505

Earlier quoted context omitted.

If you got to that position by just selling something customers want, then good on you.

Selling some thing would be nice, but most of what Apple sells me is a license to my own stuff, sold in perpetuity. They don't want you to own anything. They want to own it all and have you pay them for the privilege of using their stuff. With their documented planned obsolescence., they don't even want us owning what little bit we do have for any extended duration of time. (Above statement applies to most consumer t…

I mean if they're making money from things people are freely choosing to buy, that's about as close to good as I can imagine for a large organisation.

Re: Bitwarden raises $100M

#506
post #152

I switched to Bitwarden when LastPass started using silly tactics to make customers pay. I didn't switch because of the price - the service pricing of Bitwarden was a pleasant surprise. I switched because I lost all trust in LastPass. Managing credentials and sensitive information is all about trust. The second I lose trust in that kind of service, I don't just stop using it, I will most likely never even consider co…

Dang changing a password manager seems like a nightmare. I use pen and paper which, given the trade offs, makes the most sense for me

Last I looked, Bitwarden data is a single JSON thingy (details are hazy now).

I exported my existing passwords, converted the result to the JSON format using vim or something, and imported it. Job done.

Re: Bitwarden raises $100M

#507

Earlier quoted context omitted.

Most general case consumer explanation is likely this: No more passwords. Your biometric authentication along with your Apple/Google account on your iPhone/Android phone is all you need. A more detailed blurb would be: You sign-up and sign-in to websites/apps simply by responding to a biometric unlock prompt of your phone (same as unlocking your phone with DoubleClick side button + FaceID etc). Your sign-in details a…

Stupid question: How to mitigate loss of phone, lets say on holidays?

Let's take the case of regular consumer with just one smart phone (let's say iPhone) as their only digital device and they don't have another phone/laptop etc. In this case, if the user lost their phone, then recovering access to their digital identity is going to be several steps:

0. First, immediately after they lost their phone, they should call the customer care number and report loss of their phone and get their sim blocked. This is critical to avoid SMS OTP based account hijacking.

1. They will buy a new iPhone and sim and recover their phone number first. (security of this step is a function of how well telcos operate this process. In my country you have to physically go to a telco authorised dealer shop, verify your identity with a government id proof – this is the weakest step and then initiate a lost sim replacement flow. You have to get a new physical sim and then you can change that to an esim if you wish. To avoid rampant hijacking, there is a mandatory waiting/cooloff period with multiple notifications being sent to old sim if it is still active).

2. They will have to recover their iCloud account on to this new phone. This involves the iCloud password, a verification code sent via SMS to your phone and your old device passcode. This will restore your iCloud account and escrowed keychain on the new phone. For this to work, you should have opted into iCloud Keychain backup.

Obviously, the biggest problem here is if you forgot either of the two passwords (iCloud account password and iPhone screen lock passcode). This is quite likely if you have been using FaceID to unlock all the time.

Re: Bitwarden raises $100M

#508
post #149

Earlier quoted context omitted.

I do the same. I run bitwarden_rs as a docker container on a raspberry pi on my home network. Then use wireguard so I am always connected to my home network. This works great for my family. Simple set up, and I've done 0 maintenance on it.

Have you set your family up with Wireguard as well? Did you do the setup manually or do something else clever to get their devices in your network? I've been spending a lot of time thinking about this, and always end back up at MDM, which is not a terribly desirable ending, but can't necessarily put hands on a device readily for some of them.

I set it up manually for my family members.

My biggest issue is that I have wireguard automatically enable itself when not on my home network. But there are some other networks that need to be excluded, like most airline wifis, as they don't have internet access when just trying to watch a movie.

iCloud private relay does a good job of detecting these types of networks and correctly disabling itself. I wish there was something in the wireguard client to do this, rather than just retrying over and over again...

And since wireguard sets the DNS to use the pihole on my home network, this becomes problematic if they connect to a network that has a captive portal, and needs the wifi's DNS to accept the agreement and get access to the internet before switching over to wireguard and my home DNS.

Re: Bitwarden raises $100M

#510

Earlier quoted context omitted.

Selling some thing would be nice, but most of what Apple sells me is a license to my own stuff, sold in perpetuity. They don't want you to own anything. They want to own it all and have you pay them for the privilege of using their stuff. With their documented planned obsolescence., they don't even want us owning what little bit we do have for any extended duration of time. (Above statement applies to most consumer t…

I mean if they're making money from things people are freely choosing to buy, that's about as close to good as I can imagine for a large organisation.

My point was "buying" typically implies ownership in conversations like these, when these corporations are actively resisting you actually completely owning their products. We are more like temporary renters. And this has unfortunate consequences for the rest of the goods economy. Won't be long, as an example, before Samsung doesn't want you to actually own your refrigerator, TV, or washer, or Tesla and GM not wanting you to own your vehicle, and instead, pay them a monthly service fee for the pleasure of using your own car you "bought" (spoiler alert).

The whole idea is the thing you "buy" is really just an ephemeral vehicle of consumption and steady revenue stream for the corporation. Good for them, bad for you.

Post reply on HN