Live data from Hacker News

Bitwarden Acquires Passwordless.dev

bitwarden.com

191–200 of 399 posts

Re: Bitwarden Acquires Passwordless.dev

#191
post #134
post #44

Earlier quoted context omitted.

> Bitwarden recently raised 100M from VC I wasn’t aware of this, but I’m glad I am now. If that’s the case it’s time to look elsewhere or self host, VC funds and acquisitions are rarely good for users so I’ll assume the worst.

> VC funds and acquisitions are rarely good for users Where does this sentiment come from? I know very few applications I use that are VC funded or haven't gone through acquisitions...

The issue is that there are a large number of products/companies (I think the vast, vast majority) whose addressable market size isn't that big, but when they take VC money they do all types of unnatural things to try to grow instead of focusing on the couple things they were really good at. Couple cases in point:

1. Totally agree with the comments that VC funding absolutely killed LastPass.

2. Twitter is probably another good example. Twitter was a really large business, but they were constantly wringing their hands about what they could do to get as big as Facebook or Instagram. What if the answer was always just "No, you'll never be that big, just don't even try". So instead of improving their core bread-and-butter (and fine, easy to argue they didn't even do that super well), they wasted a ton trying to get users who were never going to use Twitter in the first place.

3. Very closely related to this idea about "When large sums of money become toxic", the private equity consolidation in US health care is another ongoing disaster. PE comes in with the promise of "streamlining operations", but instead they are just vampires, cutting stuff to the bone so that the health care system isn't able to respond to spikes in demand (e.g. Covid): https://www.statnews.com/2022/12/14/moodys-private-equity-he...

Re: Bitwarden Acquires Passwordless.dev

#192

Earlier quoted context omitted.

Lifestyle businesses have a big flaw in American culture though; our safety net is not enough to make "meets expenses" a tenable long-term approach. We basically have to aim for a big wad of savings for later in life, which incentivizes going for exits and cash-outs.

This also means creation of billion dollar global platforms that Europe and other parts of the world have never accomplished. Trade offs.

I feel so happy that we have created "billion dollar global platforms" instead of universal healthcare or ensuring everyone was sleeping indoors. Woo-hoo!

Re: Bitwarden Acquires Passwordless.dev

#193

Earlier quoted context omitted.

The entire finance industry has a disdain for "lifestyle businesses", that just generate enough profits for the founders and employees to live on, but will never generate an exit beyond that. I get why, but for utility products, a solid lifestyle for the employees and a useful product for users is enough, and should be enough.

Lifestyle businesses have a big flaw in American culture though; our safety net is not enough to make "meets expenses" a tenable long-term approach. We basically have to aim for a big wad of savings for later in life, which incentivizes going for exits and cash-outs.

Seeing as only a few % of Americans achieve what you are saying I don’t think it’s strictly true. Maybe if you want to fatfire or something

Re: Bitwarden Acquires Passwordless.dev

#194

Earlier quoted context omitted.

Passkeys are effectively software security keys, stored in whatever keychain you're using (Chrome or iCloud Keychain or otherwise); for the major implementations you're hearing about, the goal of their implementation is improving the UX by syncing your passkeys between devices, so as long as you can access your passkey keychain, you won't have to worry about losing your security key for that website. As for how "pass…

It’s cool but until Apple lets Firefox use said keychain I’m not going to use it.

Most people will though, because they’re either in the Android or Apple ecosystems.

Re: Bitwarden Acquires Passwordless.dev

#195
post #35

Earlier quoted context omitted.

BitWarden is open source on both ends. So worst case one can self host then fork clients. (Server has already been reimplemented independently.)

This is true, but LastPass proved that by the time the worst case occurs it's already too late. A security breach means, at minimum, redoing all your passwords, and these sites are a very compelling target. OTOH I wouldn't want to self-host because I know I'm not going to spend the same amount of time and effort a full security staff would, even if my self-hosted box would make a much less attractive target. It's qui…

> A security breach means, at minimum, redoing all your passwords

Not necessarily. I wouldn't have felt compelled to redo all my passwords if 1Password's encrypted vaults were stolen the way LastPass's were, given that 1P's vaults are uncrackable with brute force but LastPass's critically depend on the entropy of the master password. This was discussed recently:

https://news.ycombinator.com/item?id=34359251

Re: Bitwarden Acquires Passwordless.dev

#196
post #60
post #53

Earlier quoted context omitted.

Ah for fuck's sake. It keeps happening to all the software I love. I guess I'll have to stop relying on convenience (I was a 1Password user years ago) and go 100% open-source. None of the libre offerings seem to be as convenient and polished, but at least they're not into some VC's pocket ready to squeeze as much profit as possible out of my paid membership. What's a good OSS alternative that works with iOS and Linux…

I use KeePass. It’s up to you to sync passwords and they’re stored locally. I see those as features despite that they’re inconvenient.

I love Bitwarden. I've been a customer for years. Great product. Great team. However, I recently quit for this exact reason (evil VC influence), and migrated all of my secrets to KeePass. Yes, a slight inconvenience to manually sync across devices, but I sleep better at night knowing my secrets are no longer in the hands of some VC suit.

Re: Bitwarden Acquires Passwordless.dev

#197
post #111

Passwordless as a concept needs to die along with biometric auth. You have really good newer methods of auth. Instead of selling them as good MFA alternatives security vendors decided to replace passwords because that differentiates them more. But in reality, the layer of defense "what you know" should be complemented not replaced. A reduction in security being sold as a feature is dishonest and harmful.

Please explain how this is a reduction in security.

They are pointing out that while the "something you have" factor may be stronger than "something you know", multi factor is still better. I agree. Also, passwords are decentralized, whereas passwordless puts the power into fewer hands, so this too reduces complexity for attackers.

2FA>1FA

Re: Bitwarden Acquires Passwordless.dev

#198

Earlier quoted context omitted.

My guess is they will follow 1Password and have more strategies to monetize users. I wonder what the difference between the two services will be at the end of the day.

1Password in my experience was the biggest scum of bait and switch I ever faced. They used to do "lifetime" licenses which I bought into, but wouldn't support it beyond one year of release and stop giving me updates. Later, they invested heavily into the cloud side of things, and brought in confusing subscription-based pricing which made it expensive and difficult to understand. All they're doing as of now is trying…

1Password NEVER had lifetime licenses. We made this decision since day one because we had a product before that died because it was a "lifetime" purchase. The 1Password license is valid for the major version of the app. The license purchased would still work with that version today. If you look at the release history of 1Password apps — every version had a ton of updates made long after the app was no longer on sale. For example, 1Password 7 was updated just a month ago: https://app-updates.agilebits.com/product_history/OPM7

The licenses are also confusing — people had to purchase apps separately for every platform: macOS, Windows, iOS, Android. And then they had to purchase upgrades separately as well.

Re: Bitwarden Acquires Passwordless.dev

#199
post #178

Earlier quoted context omitted.

And can be enough if you don't need large quantities of investment capital. If you don't _need_ it, but _want_ it to get fabulously wealthy... well, "lifestyle business" is not the path to that, by definition. It's almost like the interests of those who want to get fabulously wealthy -- whether founders or investors -- become misaligned with the interests of the users, even steeper/faster than when you "just" have a…

The thing is, founders can get fabulously wealthy with a lifestyle business or at least very wealthy, but it might take longer. But all the established money seeking rent parked at VC firms can't get a cut if you don't play ball with them.

Millions, even tens of millions, for founders isn't unheard of at all for small "lifestyle" businesses.

Not VC billions, but fuck you money is certainly doable.

Re: Bitwarden Acquires Passwordless.dev

#200
post #125
post #103

Earlier quoted context omitted.

Bitwarden is the first password manager I ever used. Where would it use drag and drop and for what? I wish it would be better controllable vie keyboard-only. That is, when you use the Firefox add on and tab out of the Bitwarden popup and tab back in again it remembers the focus on e.g. the copy password button, you just have to hit space again and tab back to the terminal window where you need to use the password. Bu…

In 1Password there's at least a half dozen ways that drag and drop could be used: - Drag a password into a password field - Drag an attachment from Finder/Explorer into an item - Drag an item from vault to vault (or collection in Bitwarden parlance) - Drag an item into a tag or folder to add that item to the folder, or add that tag to the item - Drag an app to the 1Password icon to create a software license item with…

You must be on mac, because my 1pw experience is horrible on Linux. Edit a password in the browserextention opens an new tab in n which i have to login all again. Ugh. Bitwarden at least doesn't do that. Drag and drop? Nope.
Post reply on HN