Live data from Hacker News

Bitwarden: Free, open-source password manager

bitwarden.com

141–150 of 306 posts

Re: Bitwarden: Free, open-source password manager

#141
post #117

I don't agree with the self hosted Bitwarden philosophy. Having a "server" to manage passwords is overkill for most people. The best is to use an encrypted keepass file stored on your cloud storage (Google drive, Dropbox etc). It is portable and easy to access from anywhere ( don't need to VPN to your local network). Not a fan of the self hosted server password management model. Doesn't make any sense unless managing…

I agree with the first part of your statement, but how do you access an encrypted keepass file from mobiles?

There are mobile apps for keepass e.g. KeypassDroid https://play.google.com/store/apps/details?id=com.android.ke...

Re: Bitwarden: Free, open-source password manager

#142
post #105
post #90

Earlier quoted context omitted.

> The new CEO concerns me. I didn't know who the founder was but I always had the impression it was a lone hacker. They passed the baton. Now it's some old Web 1.0 guy who was the CEO of eFax in the 90's. This sounds like ageism to me. I don't know if this guy is any good or not, but calling out someone as a 'concern' just because they were successful in the past isn't a good look. Is there anything more substantive…

I've never heard "web 1.0 guy" as a pejorative, on top of what you said. For the curious, Michael Crandell is the CEO and he founded Right Scale in 2007 which exited in 2018 with 250 employees. He was EVP at eFax in the early aughts, which would have been somewhere in his twenties. He's a Stanford and Harvard graduate as well as a self-taught programmer in assembly. Here's an interview with him: https://medium.com/au…

> he founded Right Scale in 2007 which exited in 2018 with 250 employees.

A strong negative signal as far as I am concerned.

For a consumer-oriented software startup, an “exit” is most of the time a polite euphemism for selling the userbase to a juicing machine of some sort; the second place is taken by selling the product to an enterprise-oriented business which doesn’t want the userbase and eventually will, with more or less grace, show them the door.

Therefore, when I see a consumer-oriented, VC-funded startup, I don’t see why I should consider trusting them for even a second. Dine on the free lunch while it lasts, yes; squirrel away every bit of software they’re willing to release, yes; trust, depend on, or invest even a tiniest bit of my time, no.

Re: Bitwarden: Free, open-source password manager

#143

FYI - Bitwarden took $100M in VC money last year. At some point, the pressure to aggressively monetize will unfortunately happen. https://techcrunch.com/2022/09/06/open-source-password-manag...

As someone who much prefers bootstrapping businesses, this seems like a just insane amount of money to raise. If you had a growing popular product like this, why on earth would you raise that amount of money? This isn't a rhetorical question btw! I would honestly like to know the rationale here?!

I guess a lot of people have a hard time saying no when offered a hundred million dollars.

Re: Bitwarden: Free, open-source password manager

#144

I’ve been a happy user of Pass ( https://www.passwordstore.org/ ) for a few years now. Can’t see it being monetized any time soon, which is a Good Thing. So is its strict adherence to the Unix philosophy.

I really wanted to try switching to pass, but I use my password manager on my phone too much, and I dual-boot on my desktop besides. WSL solves the desktop issue, but I'm not sure what the best option is for syncing Linux, Windows, and an Android phone. Heck, I don't even know how `pass` stores the db so I don't know if it can be synced.

Got any insight there?

Re: Bitwarden: Free, open-source password manager

#145
post #79

I have no passwords. Don't get me wrong, I don't use a password manager either. Not a single one of them is truly portable, safe or secure. What if you lose all your electronics? All your belongings? Your house burns down in a fire? The cloud gets hacked? You have conflicting interests with US government and they kindly request your passwords from Apple? You have conflicting interests with any other country and they…

Interesting. If say 3 passwords using that algorithm leaked, would it be possible to deduce the algorithm itself? Edit: what about digit-only password?

With a password manager, you only need to know 1 password to "deduce" all the others. So wouldn't a 3-password system be better anyway?

Re: Bitwarden: Free, open-source password manager

#146

FYI - Bitwarden took $100M in VC money last year. At some point, the pressure to aggressively monetize will unfortunately happen. https://techcrunch.com/2022/09/06/open-source-password-manag...

What could a password managing service possibly need this amount of money for - or worse - what could they possibly plan to be doing with it to convince the VC that they will get even more money back from this deal?

Re: Bitwarden: Free, open-source password manager

#147
post #105

Earlier quoted context omitted.

I've never heard "web 1.0 guy" as a pejorative, on top of what you said. For the curious, Michael Crandell is the CEO and he founded Right Scale in 2007 which exited in 2018 with 250 employees. He was EVP at eFax in the early aughts, which would have been somewhere in his twenties. He's a Stanford and Harvard graduate as well as a self-taught programmer in assembly. Here's an interview with him: https://medium.com/au…

> he founded Right Scale in 2007 which exited in 2018 with 250 employees. A strong negative signal as far as I am concerned. For a consumer-oriented software startup, an “exit” is most of the time a polite euphemism for selling the userbase to a juicing machine of some sort; the second place is taken by selling the product to an enterprise-oriented business which doesn’t want the userbase and eventually will, with mo…

Right Scale was a cost management platform; this is the product now: https://www.flexera.com/products/cloud-management-platform. I don't think I'd refer to it as consumer oriented. The exit seems to be motivated by an industry shift to containers, which building cost models for is a significantly different business: https://www.forbes.com/sites/janakirammsv/2018/09/26/flexera...

Based on the interview I linked BitWarden is going down a venture of trying to offer vault-like enterprise secrets management on top of BitWardens tech, which could mean they're trying to monetize the more enterprise side of their business.

Re: Bitwarden: Free, open-source password manager

#148
post #7

I am a happy user and find it very convenient but how safe is it really to have all your jewels centralized in the cloud, including 2FA. It seems such a worthwhile target. On the other hand keeping everything in sync manually seems a hassle and in the end you just encrypt on your machine and the syncing goes through the cloud anyway, so where's the difference? I'd be happy to hear thoughts on this.

Assuming the cryptography is solid (big if), you primarily have to worry about end-device compromise or a supply chain attack. Is it the latter you're worried about?

Re: Bitwarden: Free, open-source password manager

#149

FYI - Bitwarden took $100M in VC money last year. At some point, the pressure to aggressively monetize will unfortunately happen. https://techcrunch.com/2022/09/06/open-source-password-manag...

As someone who much prefers bootstrapping businesses, this seems like a just insane amount of money to raise. If you had a growing popular product like this, why on earth would you raise that amount of money? This isn't a rhetorical question btw! I would honestly like to know the rationale here?!

You mostly take VC money when you can’t get credit from ordinary lenders, and your product hasn’t generated a profit.

Re: Bitwarden: Free, open-source password manager

#150

I’ve been a happy user of Pass ( https://www.passwordstore.org/ ) for a few years now. Can’t see it being monetized any time soon, which is a Good Thing. So is its strict adherence to the Unix philosophy.

I really wanted to try switching to pass, but I use my password manager on my phone too much, and I dual-boot on my desktop besides. WSL solves the desktop issue, but I'm not sure what the best option is for syncing Linux, Windows, and an Android phone. Heck, I don't even know how `pass` stores the db so I don't know if it can be synced. Got any insight there?

There is no "database", it's just a bunch of GPG encrypted files synced with git. (Their default location is ~/.password-store.)

For Android there is https://github.com/android-password-store/Android-Password-S....

The only Windows client listed at https://www.passwordstore.org/#other is unmaintained.

Post reply on HN