I see a lot of comments challenging the founder's choice on the trade-off "e2e encryption vs users losing their passwords", so I will explain my use case.
I am building a social network (https://www.quidsentio.com) with the idea of creating one that reduces the noisiness of current ones (that's why I am calling it a "quiet social network") and also is more privacy-oriented.
I see privacy as freedom from being observed, and I am considering three dimensions: free from being observed by strangers (you only add real friends to your network), free from being observed by companies (no ads, no tracking), and free from being observed by thieves (prepared for data breaches).
That last point is the harder technical problem to solve and Userbase seems to solve it well. As privacy is a big part of what I am building, I consider the trade-off acceptable for my product. Of course, my copy and UX will have to be especially good to not frustrate users on that end.
Still, it is a hard decision to make for a product. But the recovery after lost password option that one of the founders mentioned in one of the comments below (https://news.ycombinator.com/item?id=22145878) was decisive, so now I am pretty sure I will add e2e to my product.
Other features that make it perfect for me:
- It's a SaaS, which helps a lot a solo founder not having to build and maintain an authentication service
- It's an API, fits well my serverless architecture (I am using Netlify hosting, Netlify Functions, and FaunaDB)
- It's cheap (I am using now Netlify Identity, which is $99/month per 5,000 users after the free tier of 1,000)
So, thanks for your work, I will for sure be a happy customer, and I am more excited to make this bet that privacy is/will be something that matters for all people, not just worried developers