Live data from Hacker News

Yubico is merging with ACQ Bure and intends to go public

yubico.com

61–70 of 222 posts

Re: Yubico is merging with ACQ Bure and intends to go public

#62

Honestly, do any companies improve in the long term when going public? It seems like the business model is always to make short term profits and then slowly (or in some cases quickly) die about.

Lots of companies found greater success post-IPO.

Apple, Google, Facebook, Microsoft (especially recently), Nintendo, Tesla, etc.

The IPO is a statement to investors that the company believes it will grow bigger and seeks public market funds to accelerate growth. That doesn't always happen.

Some companies and investors see the IPO as merely a liquidity event, which is the wrong perspective to take. SPACs were clearly being abused for this.

Re: Yubico is merging with ACQ Bure and intends to go public

#63
post #17

Earlier quoted context omitted.

The idea of authenticator hardware is inherently hostile to DIY and open source because you cannot produce or extract a keypair to generate valid attestation statements. Unless you are part of the cartel of course. https://w3c.github.io/webauthn/#attestation-statement

WebAuthn doesn’t require the RP to enforce any particular hardware attestation, and many sites (the overwhelmingly majority?) allow anonymous attestation, self-attestation, or simply no attestation at all. Having hard-to-extract device keys isn’t “DIY hostile”; it’s critical to the attestation security model. If you want to build your own WebAuthn authenticator, then you can either form your attestation root (there’s…

I am aware how attestation works and what problem it addresses. But I strongly believe the power imbalance it creates outweighs the benefits.

Especially with bullshit like CF using it as a captcha substitute. https://blog.cloudflare.com/introducing-cryptographic-attest...

Re: Yubico is merging with ACQ Bure and intends to go public

#65

I have an irrational concern about using security products from a company post-merger or acquisition. It has never ended well for me as an anecdotal user. Going public is taking that worry even further. Make keys, sell keys. The end. What's there to raise funding for? Build yet another password vault?

I agree with this as well. Capitalist influence creates a powerful conflict of interest. When it cuts down to it, which master will yubico serve? The customers or their shareholders? Now Yubico has a fiduciary responsibility to their shareholders. I frankly can't think of very many companies that are able to resist this core capitalist corruption. Even Costco is implementing shareholder over customer policies. 1Passw…

This is not a matter of going public, but I note that when MS bought Github, there was a lot of concern over whether that would degrade the service's customer-friendliness. So far, that doesn't seem to have happened? You don't need a MS365 identity to set up a github account, for example.

Also not going public, but Fastmail was bought by Opera in 2009 I think but then bought themselves back out again, and they've continued to offer excellent customer service (including yubikey support of which they were an early adopter) all the time.

So I'd say there's precedent for companies staying customer-focused under capitalism if the stars align: it has to be a place where (1) staying customer-focused is a clear net positive for the domain they're working in, even from a revenue perspective and (2) the people running the company understand this.

I imagine this is much more the case for companies where the customers are specialists / power users (think: developers) or other businesses, rather than the general public. I hope that means yubico of all places is lower risk. Although I consider them one of the best if not the best in the market, were they to go under, there are alternatives (google's own titan keys are ok replacements for the end user, though obviously they don't have the yubico back-end infrastructure). FIDO/U2F etc. are standards and come with certifications, so I'd hope there's only limited room for maneuvre for any new yubico owners to mess up, and a sufficient threat of losing their business that they are not incentivised to try anything too shady.

Re: Yubico is merging with ACQ Bure and intends to go public

#66

I have an irrational concern about using security products from a company post-merger or acquisition. It has never ended well for me as an anecdotal user. Going public is taking that worry even further. Make keys, sell keys. The end. What's there to raise funding for? Build yet another password vault?

I don't think it's irrational, it rarely improves the service

Re: Yubico is merging with ACQ Bure and intends to go public

#67
post #62

Honestly, do any companies improve in the long term when going public? It seems like the business model is always to make short term profits and then slowly (or in some cases quickly) die about.

Lots of companies found greater success post-IPO. Apple, Google, Facebook, Microsoft (especially recently), Nintendo, Tesla, etc. The IPO is a statement to investors that the company believes it will grow bigger and seeks public market funds to accelerate growth. That doesn't always happen. Some companies and investors see the IPO as merely a liquidity event, which is the wrong perspective to take. SPACs were clearly…

[deleted]

Re: Yubico is merging with ACQ Bure and intends to go public

#68

Earlier quoted context omitted.

I agree with this as well. Capitalist influence creates a powerful conflict of interest. When it cuts down to it, which master will yubico serve? The customers or their shareholders? Now Yubico has a fiduciary responsibility to their shareholders. I frankly can't think of very many companies that are able to resist this core capitalist corruption. Even Costco is implementing shareholder over customer policies. 1Passw…

This is not a matter of going public, but I note that when MS bought Github, there was a lot of concern over whether that would degrade the service's customer-friendliness. So far, that doesn't seem to have happened? You don't need a MS365 identity to set up a github account, for example. Also not going public, but Fastmail was bought by Opera in 2009 I think but then bought themselves back out again, and they've con…

Those look very much as an exception to the rule

Re: Yubico is merging with ACQ Bure and intends to go public

#69
post #62

Honestly, do any companies improve in the long term when going public? It seems like the business model is always to make short term profits and then slowly (or in some cases quickly) die about.

Lots of companies found greater success post-IPO. Apple, Google, Facebook, Microsoft (especially recently), Nintendo, Tesla, etc. The IPO is a statement to investors that the company believes it will grow bigger and seeks public market funds to accelerate growth. That doesn't always happen. Some companies and investors see the IPO as merely a liquidity event, which is the wrong perspective to take. SPACs were clearly…

Not talking about company being more successful but better to the actual customers. Google isn't exactly a good example here

Also Microsoft went public almost 4 decades ago, apple went public over 4 decades ago, the landscape looked a bit different there.

Re: Yubico is merging with ACQ Bure and intends to go public

#70

I really hope this does not affect their current mode of operation. The reason I bought my Yubikeys in the first place were the one off purchase cost and the promise that the keys would do their job without me having to interact with Yubico from that point onwards. This has worked great so far! Now with shareholders in the mix I fear they will try to find recurring income models to increase profits. I guess we'll jus…

How would that model work considering the key is a piece of hardware, built to implement an open standard (at least for the U2F mode)? There's no "key phone home" phase in U2F.

Also, though I would miss yubikeys if they went under like this, in practice I could switch to google titan or something else and it wouldn't be the end of the world.

Post reply on HN