7 ms·
Bitwarden already does one thing well. It's everything I'm looking for - open source, costs money but not much ($10/yr), 2FA, clean interface. I'm happy for the
by NickHoff 4y ago
Bitwarden already does one thing well. It's everything I'm looking for - open source, costs money but not much ($10/yr), 2FA, clean interface. I'm happy for the new investment, but I hope they don't start adding new things just for the sake of growing.
Also - to the people who analyze funding rounds - $100M sounds like a huge amount to me. Why would a password manager need so much money?
- xani_ 4y agoI just hope we won't get repeat of LastPass - some company buys it then just keeps on life support while raising prices. Also "OSS" version is not really open source, it's just core and all the features you really want from password manager are behind the paid license anyway
- mirzap 4y agoLike what? All the features that password manager needs to have (and features that 99% of people need) OSS version have it. SSO, organization management etc. is not something that "password manager" needs to have.
- sleepless 4y agoLike TOTP, which is part of payed variant and I consider that an essential feature of a password manager in 2022. Don't get me wrong, I am not complaining about that business decision, just answering since you asked.
- Avamander 4y agoTo be fair, TOTP should be a separate device to fulfil the criteria of actually being 2FA.
- bmurphy1976 4y agoI totally agree, however there are some low-criticality services where 2FA is a burden and having it in your main password manager app is a tradeoff worth consideration. Definitely NOT your primary email address.
- elcomet 4y agoTOTP should be on a separate device.
- deleted 4y ago[deleted]
- alex_suzuki 4y agoMarketing
- michaelmior 4y ago> Why would a password manager need so much money? The announcement suggests they are looking to also launch their own authentication service and tools for managing application secrets.
- cmeacham98 4y agoHow did I have to scroll this far down to find someone who's actually read the post? Everybody seems to think the money is purely for expanding the password manager, while in the post they call out adjacent markets they want to expand to. I'm cautiously optimistic that this could mean we won't see the end of Bitwarden, as those are areas where companies will pay big money.
- gundamdoubleO 4y ago>How did I have to scroll this far down to find someone who's actually read the post? Welcome to Hacker News
- Macha 4y agoIt's not that people didn't read the statement, it's that people have learned not to trust statements like this. Ask all Heroku's customers who were just fired by Salesforce to focus on their enterprise offering for example.
- ShamelessC 4y ago
- pavlov 4y agoEnterprise sales presumably? A $100M round probably means a valuation around $500-600M. They now need to grow the company to a couple billion so it can either go public (when the IPO market is alive again in a few years) or be sold to a bigger enterprise player. $10/year customers are completely irrelevant to a company at this stage. Open source is nice as a sales bullet point, but not a central focus.
- GekkePrutser 4y agoI don't really want them to grow. Growing usually means overinflated expectations and when they aren't met by the new products they will try to retrieve the shortfall from their existing customer base with additional monetisation, driving them away in the process. I hope it won't go this way here but such a cash buyin is usually the start of a difficult time. > $10/year customers are completely irrelevant to a company at this stage. Yet it's exactly the plan most customers and supporters would be on. So in other words, we don't matter anymore. This is why we can't have nice things :(
- noirbot 4y agoWhen 10/year is often less than .01% of even a junior developer's salary with benefits, then yea, that does kinda mean we can't have nice things, if nice things require a few devs to implement. We've all gotten so used to getting things where the VC discount was already fully priced in over the last decade that we're deeply conditioned to expect everything to be sold at VC subsidized prices, which it turns out isn't really economical for most non-VC backed businesses to sell at. I'm sure someone will, like clockwork, reply to me that that could be done by one developer in C, sold for $0.50 and then never patched again because UI designers just mess everything up and no one should have a smartphone anyway. If that's your idea of "nice" then you're likely living a happy life, but if you expect a UI and reliability like even oldschool 1Password or Lastpass, then $10/year isn't buying you that level of development and support.
- GekkePrutser 4y agoWell, the thing is, we have nice things now. I don't think most bitwarden users are screaming for new features. Simply continuing as they are with current staffing would be preferable to risking the farm with a big new product. And the kind of user that picks bitwarden over LastPass or 1Password is not the kind that needs a ton of support.
- jlokier 4y ago> Why would a password manager need so much money? The money isn't for the password manager particularly. In the article they list a number of new things they want to develop. I think there will come a point when most mainstream web services will require "passwordless" authentication, which means users will have to register with one of a few commercial passwordless providers. Think "login to service X with Google/GitHub/Facebook" but more integrated with your phone and biometrics, and no longer optional as email and password authentication go out of fashion. It makes sense for Bitwarden to aim to be one of those providers, if for no other reason than company survival if passwords and similar tokens become deprecated.
- scarface74 4y agoAnd the three companies behind the major platforms - Google, Apple, and Microsoft - have all agreed on a standard and will integrate a solution into their operating systems.
- phpisthebest 4y agoYes, and what is that one like the 6th or more "auth standard" they all "agreed to" before promptly doing their own variations which then get spun into a new standard they all "agree" to before.......
- scarface74 4y agoEven if that is the case, storing passwords across devices is a solved problem and not enough people are willing to pay for it to be a profitable business. “It’s a feature not a product”
- jorvi 4y ago> and not enough people are willing to pay for it to be a profitable business. 1Password is doing just fine..
- 4y ago
- phphphphp 4y ago1Password, a competitor, raised ~$650m earlier in the year off the back of exceptional growth. The investment case is likely: Bitwarden are doing well, 1Password are doing very well, maybe Bitwarden can do very well too with some additional capital. Password management is rapidly growing in mindshare, there's a big market and great room for growth, the amounts involved are commensurate with the opportunity -- every single enterprise will have a robust password management setup soon enough.
- scarface74 4y agoOr 1Password could just suffer from the DropBox problem - it’s a feature not a product. Every company’s answer to that is also the same “we will target the enterprise”. They aren’t “doing well” if they still require outside funding.
- bengale 4y agoA feature of what service though? The OS? iCloud keychain does this, it's not a compelling offering though if you need to use any other OS. Something like Google? Not sure I'd want to risk my Google account ever getting locked and loosing access to all my other accounts. I'm not sure what that leaves.
- scarface74 4y agoIs that a large enough market to be a sustainable, profitable business?
- bengale 4y agoI would think so, on the business side of things. I'm not entirely sure what we pay for 1Password because we pay it without question tbh. We have a fair few subscriptions but 1Password would be up there with the indispensable ones.
- everforward 4y agoThe browser is the obvious option. Firefox and Chrome both implement ways to save passwords in the browsers. I believe Firefox has a service to sync them, Chrome may too (I don't use them, so I don't know). They could reasonably tie in to whatever Office-suite you use (GSuite, Office 365). In the enterprise, it could be part of a larger "credential management suite" product managed by security. Allow syncing and auditing of credentials, like "when was the last time this cred was changed?" with some kind of automation to generate and push a new credential when need be. From the outside looking in, a basic credential manager doesn't seem complex enough to be a standalone product.
- ignoramous 4y agoWith smartphones leading the push towards digital everything, passwords (auth / authz) have become the most important asset, even for consumers. Edit: An interesting conversation between Basecamp's DHH and 1Password's Teare on their series-a as an opportunity to de-risk the venture: https://archive.is/Kdnpz https://archive.is/Kdnpz
- phpisthebest 4y agoWhich has also become a single point of failure, and a target for social engineering since "lost device" or "stolen device" etc becomes to new defacto backdoor
- Ozzie_osman 4y ago> Why would a password manager need so much money? A cynical take on this would be the business is at a large enough volume and growing fast enough to be valued at a certain price (eg 400M), VCs want to own a certain percentage (eg 20%), so the math dictates the round needs to be 100M (100 / (400 + 100) = 20%). Then the founders put together some story that explains why they'd need 100M. Not saying that's what happened here but I've seen it happen this way.
- jbotz 4y agoThey'll probably aim for competing with the likes of Okta in delegated authentication and identity management, which is a huge market which need some more competition. I'm in favor, and it really doesn't need to have any negative impact on their existing user base, at least so long as they can manage their growth and don't become a dysfunctional org because of it.
- dmix 4y agoThe interface could use a lot of work: ie search for cards and logins should not be separate. It also visually doesn’t look great.