Live data from Hacker News

Bitwarden Acquires Passwordless.dev

bitwarden.com

291–300 of 399 posts

Re: Bitwarden Acquires Passwordless.dev

#291
post #48

As a recent convert to Bitwarden from LastPass, I start to get a bit nervous when I see acquisitions happening. LastPass getting acquired was the beginning of the end for it, IMO, before stagnating into criminal negligence. Granted this is Bitwarden acquiring rather than being acquired, but I still worry it leads to a trend of building "portfolio value" rather than focusing on the product. I sincerely hope I'm wrong.

A good note for bitwarden is that it has a self hosting open source version, vaultwarden that is easy to switch to: https://github.com/dani-garcia/vaultwarden I see this as downside protection, as I can quickly migrate if I disagree with bitwarden's direction with minimal changes to my clients. I do worry about VC pressure on Bitwarden for hypergrowth. However in my personal opinion, the benefits outweigh the cons (f…

The official open source repo is https://github.com/bitwarden/server

Vaultwarden is a compatible but 3rd party software.

Re: Bitwarden Acquires Passwordless.dev

#292

As a recent convert to Bitwarden from LastPass, I start to get a bit nervous when I see acquisitions happening. LastPass getting acquired was the beginning of the end for it, IMO, before stagnating into criminal negligence. Granted this is Bitwarden acquiring rather than being acquired, but I still worry it leads to a trend of building "portfolio value" rather than focusing on the product. I sincerely hope I'm wrong.

Also Bitwarden recently raised 100M from VC so yeah, the clock is ticking now.

Ugh. I JUST migrated to Bitwarden.

VCs ruin everything.

Re: Bitwarden Acquires Passwordless.dev

#293
post #165
post #68

I really dislike the idea of giving complete access to my digital life to any company, particularly one that needs to grow quickly. The tech for password vaults is so simple, I use keepass + icloud syncing and get free end-to-end encrypted password syncing, without sharing any data with anyone. Outlined in more detail here: https://magoop.substack.com/p/how-to-manage-500-passwords-se...

Services like 1Password are often more secure than your solution because they need to harden vaults against full leaks. In the case of 1Password, a secret key in addition to the password ensures that brute forcing is (at the moment) not feasible, even if your password is really crappy.

How is 1Password's secret key more secure than using keepass's key file feature?

Re: Bitwarden Acquires Passwordless.dev

#294
post #85

Earlier quoted context omitted.

I did this some time ago when 1Password announced switching from having native apps to being containerized web apps. Have not regretted it one bit.

The "containerized web app" is not a correct description here. 1Password 8 on macOS, Windows, and Linux is a full-fledged desktop app. It is built in Rust with Electron/React providing the UI. It can work completely offline and does not require a network connection. 1Password 8 has greatly improved security architecture compared to the previous versions. Just one example of many: when rendering the item details, the…

Electron providing the UI is exactly what most people are referring to when they say "containerized web app", only because this paradigm of split backend for electron apps is less common.

Re: Bitwarden Acquires Passwordless.dev

#295

Earlier quoted context omitted.

Same was said about LastPass many times and look at what happened, everything turns out to be a false promise.

That's not a fair comparison. The differences in LP and 1P encryption approaches have been well known for years, and they are fundamentally different. Now, while 1P encrypted vaults are not brute-forceable the way LP's are, that doesn't mean it's impossible to hack 1P (e.g. malicious code injection in any of their apps or plugins), but I don't like the "everything turns out to be a false promise" broad-brushing when…

Unless you want to spend the time doing RE of crypto (so fun!), how to do you even know who works for 1Password?

Are you waiting for Snowden 2.0 to explain how things work a decade later?

Re: Bitwarden Acquires Passwordless.dev

#296
post #48

Earlier quoted context omitted.

A good note for bitwarden is that it has a self hosting open source version, vaultwarden that is easy to switch to: https://github.com/dani-garcia/vaultwarden I see this as downside protection, as I can quickly migrate if I disagree with bitwarden's direction with minimal changes to my clients. I do worry about VC pressure on Bitwarden for hypergrowth. However in my personal opinion, the benefits outweigh the cons (f…

Note that Vaultwarden is the unofficial server, there is also an official one, that you can self host. Vaultwarden is much easier to set up and manage, I use it myself, and I heard that the official build is a little bit more tedious to go with.

I personally use vaultwarden myself as well, and am also quite pleased with it.

Re: Bitwarden Acquires Passwordless.dev

#297
post #143
post #134

Earlier quoted context omitted.

> VC funds and acquisitions are rarely good for users Where does this sentiment come from? I know very few applications I use that are VC funded or haven't gone through acquisitions...

It comes from a concern that VC backed investments demand a constant level of revenue growth, causing a company to add features or integrations that do not improve the base product. Organic growth is usually insufficient for stockholders, whose demands become a priority over stakeholders. If the user base does not increase at some rate determined by the investor, then growth comes in the form of advertising, partners…

More importantly, when organic growth falters, corners are cut to create synthetic growth.

When investors get involved in software, you end up with winners and users.

Re: Bitwarden Acquires Passwordless.dev

#298
post #37

Earlier quoted context omitted.

Also Bitwarden recently raised 100M from VC so yeah, the clock is ticking now.

They did? Oh JFC I just switched from 1Password to avoid using a VC backed service. At least there's always Vaultwarden, now all I need is a service I can pay to host an instance for me. ...and to not take VC funding. https://github.com/dani-garcia/vaultwarden Though I fear it’s only a matter of time before the VC gods demand the client apps remove compatibility and they have to be forked too.

Hey I’m building a service[0] that will do just that —- mind if I get in touch with you? Or feel free to send me an email!

I selfhost and use Vaultwarden myself and it is fantastic, so I wanted to support it on Nimbus fairly quickly (it’s going to jump the queue).

Deciding never to take VC funding is a big step but I’m definitely open to it as I’m trying to build a “lifestyle” competitor to AWS.

[0]: https://nimbusws.com

Re: Bitwarden Acquires Passwordless.dev

#299

Earlier quoted context omitted.

Also Bitwarden recently raised 100M from VC so yeah, the clock is ticking now.

Ugh. I JUST migrated to Bitwarden. VCs ruin everything.

If you want to switch to vaultwarden but don’t want to host it I’m working on something for that:

https://news.ycombinator.com/item?id=34434877

I’m not convinced Bitwarden will go down the drain quite so quickly…

Re: Bitwarden Acquires Passwordless.dev

#300

Earlier quoted context omitted.

1Password certainly added a ton of new features recently :) Did you check 1Password developer tools, like SSH-agent server, git commit signing, and CLI? https://developer.1password.com/ Or the new item and file sharing. https://support.1password.com/share-items/

I refuse to use a cloud-based password manager, they will all be hacked eventually. I will continue to use and pay for the standalone 1Password as long as possible, and then be forced to self-host vaultwarden.

Almost two decades without any serious breach does inspire some confidence.

I put them under the same reliability umbrella (maybe even a touch higher) than Fastmail, which is high praise IMO.

Post reply on HN