Live data from Hacker News

Bitwarden Acquires Passwordless.dev

bitwarden.com

261–270 of 399 posts

Re: Bitwarden Acquires Passwordless.dev

#261
post #178

Earlier quoted context omitted.

And can be enough if you don't need large quantities of investment capital. If you don't _need_ it, but _want_ it to get fabulously wealthy... well, "lifestyle business" is not the path to that, by definition. It's almost like the interests of those who want to get fabulously wealthy -- whether founders or investors -- become misaligned with the interests of the users, even steeper/faster than when you "just" have a…

The thing is, founders can get fabulously wealthy with a lifestyle business or at least very wealthy, but it might take longer. But all the established money seeking rent parked at VC firms can't get a cut if you don't play ball with them.

Yeah, wealthy enough if not billionaire, true.

> But all the established money seeking rent parked at VC firms can't get a cut if you don't play ball with them.

OK, but why does a founder care about that? Either they think their business model can't get them to a sustainable lifestyle business without external capital investment... or they want to get more-than-lifestyle-business wealthy, right?

Re: Bitwarden Acquires Passwordless.dev

#262
post #178

Earlier quoted context omitted.

The thing is, founders can get fabulously wealthy with a lifestyle business or at least very wealthy, but it might take longer. But all the established money seeking rent parked at VC firms can't get a cut if you don't play ball with them.

Millions, even tens of millions, for founders isn't unheard of at all for small "lifestyle" businesses. Not VC billions, but fuck you money is certainly doable.

I don't know if a couple million is "fuck you" money in 2023 (enough to never work again and eventually retire while living a fairly luxurious lifestyle?), but point taken.

Re: Bitwarden Acquires Passwordless.dev

#263
post #231
post #53

Earlier quoted context omitted.

Ah for fuck's sake. It keeps happening to all the software I love. I guess I'll have to stop relying on convenience (I was a 1Password user years ago) and go 100% open-source. None of the libre offerings seem to be as convenient and polished, but at least they're not into some VC's pocket ready to squeeze as much profit as possible out of my paid membership. What's a good OSS alternative that works with iOS and Linux…

In your opinion, what would the ideal password management business model be? A non-profit like Signal? (Not rhetorical, actually curious what people want here.) As a thought experiment, let's say there are 1000 people who get annoyed when a software product they use takes VC funding. For those 1000 people to sustain a software product with a team of 5 for 10 years at 150k average per head. you'd need 7.5MM dollars ju…

I'm not sure if there is a good business model in password management. I can't answer that question. What I do know is, a good password manager is the type of software that should strive to be feature complete. And at that point resources should be used for maintenance, security, and software/OS compatibility updates. In other words, a low-if-any growth, but profitable business assuming the software is good.

But once you get into VC funding or acquisitions, businesses tend to want to grow and bloat their products by adding features no one asked for to increase their perceived value. I know I'm tired of seeing this happen to beloved software time and time again.

Re: Bitwarden Acquires Passwordless.dev

#264

Earlier quoted context omitted.

(Full disclosure: I work at https://passage.id ) WebAuthn is the short name for the "FIDO Alliance Web Authentication Protocol". "Passkey" is the trade name (that Apple tries to own) for the "stuff" that results from using the WebAuthn protocol. At it's root, a passkey is really the private key portion of that "stuff" that is kept. So yes, in practice, a passkey is the result of a WebAuthn implementation. MS, Apple,…

Do old Yubikeys and similar U2F devices, which do still work for webauthn, still work for sites that a going to require a "passkey"? Or are MS+Google+Apple doing an "embrace, extend and extinguish" on webauthn? Are the "small adjustements that ever so slightly reduces the security" sufficient to effectively kick security keys hardware vendor out of the game?

Re: Yubikey -- I confess I don't know. The folks in r/yubikey definitely will, though.

The "Big Three" are on the FIDO board, along with 1Password. They can't really do the extinguish thing, and it really isn't in their interst to do so.

An no, the small tweaks don't kick anyone out of the game.

There will be other, perhaps more trusted, companies that you can use to move your passkeys around between eco-systems.

Re: Bitwarden Acquires Passwordless.dev

#265

Earlier quoted context omitted.

(Full disclosure: I work at https://passage.id ) WebAuthn is the short name for the "FIDO Alliance Web Authentication Protocol". "Passkey" is the trade name (that Apple tries to own) for the "stuff" that results from using the WebAuthn protocol. At it's root, a passkey is really the private key portion of that "stuff" that is kept. So yes, in practice, a passkey is the result of a WebAuthn implementation. MS, Apple,…

I don't think Apple is trying to own the name passkey. Quote from this video: https://developer.apple.com/videos/play/wwdc2022/10092/ > Here are some guidelines for how to refer to passkeys in your apps and websites. "Passkey" is a generic, user-visible term. This video focuses on Apple's implementation, but as I've just shown you, other major platforms have already started building their own support for passkeys. "P…

Fair enough.

Re: Bitwarden Acquires Passwordless.dev

#266

Earlier quoted context omitted.

(Full disclosure: I work at https://passage.id ) WebAuthn is the short name for the "FIDO Alliance Web Authentication Protocol". "Passkey" is the trade name (that Apple tries to own) for the "stuff" that results from using the WebAuthn protocol. At it's root, a passkey is really the private key portion of that "stuff" that is kept. So yes, in practice, a passkey is the result of a WebAuthn implementation. MS, Apple,…

Are Passkeys exportable and re-importable by another service, site, or system? I am strongly opposed to any authentication system that makes my authorization workflow for unrelated third-party sites dependent on any company whose terms of service allow them to suspend or terminate my use without reasonable recourse or recovery. Passwords have problems, but I can print them out on a piece of paper in a fire safe.

You own your own passkeys on your own device, ultimately. Google/Apple/MS have no ownership or knowledge of the actual keys.

Re: Bitwarden Acquires Passwordless.dev

#267

One can easily self host a bitwarden server on digitalocean. https://bitwarden.com/blog/digitalocean-marketplace/ However, I'm curious what y'all think about the cost. A digitalocean droplet for the recommended specs (4 GiB memory) is $24/month. This is hard to stomach when you compare with Bitwarden Premium which is <$1/month. I guess it depends on how much you value your own data.

They are working on reducing the requirements - see https://bitwarden.com/help/install-and-deploy-unified-beta/ which claims 200 MB RAM and 1GB storage requirements.

Re: Bitwarden Acquires Passwordless.dev

#268
post #216

Earlier quoted context omitted.

Ya, but can you name any products where this is the opposite? Meaning, how many products do you use that aren't VC backed?

craigslist famously rejected taking outside money for years. But more importantly, I don't think VC or VC money is always bad, but I get extremely wary when a relatively small company gets a shitload of money that they'll then be forced to grow into a way that means they'll lose focus on their core product. I remember when I told a friend of mine that Postman raised nearly half a billion dollars in total funding, and…

> but I get extremely wary when a relatively small company gets a shitload of money that they'll then be forced to grow into a way that means they'll lose focus on their core product.

Irrationally so. That's my point. There isn't a strong indicator that correlates to a company being a craigslist vs a company being a Postman. The median is somewhere in between and its not as dire as you pose it to be.

Re: Bitwarden Acquires Passwordless.dev

#269
post #243

Earlier quoted context omitted.

Is it not possible to point BW Android to your Vaultwarden instance?

It's fragile if you do that. Bitwarden updated their API last month on the clients so you couldn't connect to Vaultwarden at all until the Vaultwarden team could reverse engineer the change and produce a new release.

This is interesting. I use BW daily (many times) on Android against my self-updating VW instance.

I did not notice anything, maybe the break happened during the night in Europe. Or the Android app did not want about problems.

Re: Bitwarden Acquires Passwordless.dev

#270

Earlier quoted context omitted.

Best practice is unlikely to help here, as people just aren't going to register passkeys from multiple services unless it happens automatically. I might bother to enroll multiple passkeys for my bank, but I'm unlikely to do it often. Are Passkeys exportable and re-importable by another service, site, or system? As described above, if my Google Account is terminated by Google without recourse (which absolutely happens…

It should start to happen automatically. Apple, Google, and Microsoft have all stated the goal that they are hoping for deep inter-operation across all of a user's devices, regardless of ecosystem. If you are truly paranoid that your major device accounts are subject to termination without recourse (which if that happens you generally have lots of other problems and should maybe cause you to rethink your other trust…

> It should start to happen automatically. Apple, Google, and Microsoft have all stated the goal that they are hoping for deep inter-operation across all of a user's devices, regardless of ecosystem.

If this is the case, then maybe there will be some solution through Google Takeout. Apple and MS seem less interested in this, but if one of them can generate an export, I can see services appearing that can work with that exported data.

> you can build your own Passkeys with WebAuthn standards and roll your own recovery/backup strategy.

This....or I can stick with passwords, print them out annually and put them in my fire safe. The KISS principle works here, and I can't imagine a non-techie person who works in a socially-risky field being able to do so.

> If you are truly paranoid that your major device accounts are subject to termination without recourse (which if that happens you generally have lots of other problems and should maybe cause you to rethink your other trust relationships with such vendors and which devices you are buying)

Complaints by users who have Big 3 cloud accounts closed for unspecified "violations" are common enough to make it a concern. I take other protections against something like this, but I absolutely do consider it a risk, and would generally advise people not to keep all their digital services under one roof. If you use Gmail for email, then use Microsoft or Apple for Passkey, Bitwarden or 1Password for Password Vaults, etc., etc.

Post reply on HN