Bitwarden raises $100M
bitwarden.com
bitwarden.com
I switched because I lost all trust in LastPass.
Managing credentials and sensitive information is all about trust. The second I lose trust in that kind of service, I don't just stop using it, I will most likely never even consider coming back as a customer and I will warn people against them. I don't give second chances to services that are trust based.
I'm pretty happy with Bitwarden so far. But if they betray my trust I'll be out of there in a day, never to return. I switched from LastPass to Bitwarden in a day. LastPass never gets a second chance.
What the VCs have to understand is that if their greed makes them push Bitwarden to engage in silly tactics, they risk driving away their customer base.
Read the "reception" section.
There were press releases and emails and stuff.
I also switched away from last pass then.
You might run out of services then at some point.
Human beings are fallible, full stop. Also, a company isn't an individual -- management teams change, corporate priorities change, security practices improve. Judging a whole company by what a few employees did or didn't do a decade ago isn't always going to yield an optimal approach.
Refusing to give any company a second chance ever is pretty extreme. Each individual case needs to be handled on its merits -- what happened, why did it happen, do you think the company learned and implemented new policies, how many other undiscovered vulnerabilities do you think are still there? But also, how many other undiscovered vulnerabilities do you think are still there for competitors as well? Just because a competitor hasn't had a breach doesn't necessarily means it's better, it might just be lucky so far.
Not the OP but i have a similar stance. However a mistake from individual employee doesn't mean that i instantly loose trust. Its the handling of the mistake what matters to me. Sweeping it under the carpet, dening their mistakes or outright lieing about mistakes is what results in me loosing trust.
I don’t know guys, should we tell him?
I've been out of that world for a while, and I still see the compaq name now and then, but it looks like it's more of just a name licensing deal now?
The final straw for me was purchasing an HP laser printer (probably the 6th or 7th one I ever bought) and it shockingly had the same extreme-low-quality level that I had experienced with HP laptops, CD ROM drives and other peripherals.
It is probably not fair but I blame Carly Fiorina for this degradation of once reliable hardware manufacturer.
This. Every SW creator (OS, framework, app) manages the risk of security vulnerabilities. It's not black and white or simple and easy.
I prefer using services for my password management (I'm a bitwarden user who's currently happy as well), but I would jump back to some sort of self-hosted or even offline/manual sync solution if I thought that was the only way to keep my passwords safe. I like the convenience of a service, but I would sacrifice it over my security if it got to the point where I had to choose between the two.
The hypocrisy is just intolerable at this point.
HP and Dell are just marketing companies now.
I don’t know if I can manage another service switch. I can do it just fine, but my wife is more resistant to these kinds of changes and we need to be on the same page on this.
With the base service, Vault, and this, it's a nice overall package.
They don't care as long as they can extract their profit before that happens. This is VC, they will prioritize medium term gains over long term stability.
I checked out Bitwarden and it seemed like a better version of LastPass that just happened to be free. Their paid model doesn't appeal to me so I don't subscribe, but I would enjoy paying if they offered something that did.
(Off-topic: Bitwarden seems like an exact LastPass clone all the way down to the UI. Do they share a similar codebase or something? Like was one forked from an OSS version of the other?)
Looking at Google, Dropbox, and Apple, storage pricings range from 4GB/$ (Apple) to 20GB/$ (Google's 5+TB plans). I'm willing to bet that offering 5GB would make it more worthwhile and a very small fraction of your users would actually use it. What are you going to store? Your passport photo and driver's license? I wonder if there would be a psychological effect here because it is really hard to tell if 1GB is enough or not. At least your average person has no idea.
And that includes setting up Duo for push notification 2FA.
I exported my existing passwords, converted the result to the JSON format using vim or something, and imported it. Job done.
Jumped from a paid LP plan to a Bitwarden family plan with sharing and emergency access and quite happy.
Also - to the people who analyze funding rounds - $100M sounds like a huge amount to me. Why would a password manager need so much money?
The announcement suggests they are looking to also launch their own authentication service and tools for managing application secrets.
I'm cautiously optimistic that this could mean we won't see the end of Bitwarden, as those are areas where companies will pay big money.
Welcome to Hacker News
Now, as for whether one should worry because the company screwed their existing customers once already ... that's personal risk tolerance, I guess
My opinion is that 1Password is the best product out there for the majority of users, because they're pretty good about documenting their formats, have a very good export story, their customer service is mostly good, it's a reasonable price, and their UX absolutely spanks Bitwarden up one side and down the other
But, if a few years from now they rip the ssh-agent out of their Electron apps citing some "well, we decided" reason, or they ban 3rd party clients from using their API because "of sekurity," then no one should be surprised that the scorpion stung them
And according to HN guidelines, we aren't supposed to comment on if someone has read the article or not. Stellar.
[1] https://www.apple.com/newsroom/2022/05/apple-google-and-micr...
A $100M round probably means a valuation around $500-600M. They now need to grow the company to a couple billion so it can either go public (when the IPO market is alive again in a few years) or be sold to a bigger enterprise player.
$10/year customers are completely irrelevant to a company at this stage. Open source is nice as a sales bullet point, but not a central focus.
I hope it won't go this way here but such a cash buyin is usually the start of a difficult time.
> $10/year customers are completely irrelevant to a company at this stage.
Yet it's exactly the plan most customers and supporters would be on. So in other words, we don't matter anymore. This is why we can't have nice things :(
I'm sure someone will, like clockwork, reply to me that that could be done by one developer in C, sold for $0.50 and then never patched again because UI designers just mess everything up and no one should have a smartphone anyway. If that's your idea of "nice" then you're likely living a happy life, but if you expect a UI and reliability like even oldschool 1Password or Lastpass, then $10/year isn't buying you that level of development and support.
And the kind of user that picks bitwarden over LastPass or 1Password is not the kind that needs a ton of support.
It just always feels too easy to assume that it was sustainable to run/maintain some minimally priced service. Perhaps they realized they needed more developers to have a healthy relationship with their job, and instead of raising the price to $30/year or more to match the new costs, they decided to shoot for the moon.
I'm certainly not trying to say that it's obvious that they're making the right call by taking this investment, or that this won't all fall apart. It's just also important to not assume that the status quo for them was something they could keep going on for the next 3 years.
The money isn't for the password manager particularly. In the article they list a number of new things they want to develop.
I think there will come a point when most mainstream web services will require "passwordless" authentication, which means users will have to register with one of a few commercial passwordless providers. Think "login to service X with Google/GitHub/Facebook" but more integrated with your phone and biometrics, and no longer optional as email and password authentication go out of fashion.
It makes sense for Bitwarden to aim to be one of those providers, if for no other reason than company survival if passwords and similar tokens become deprecated.
“It’s a feature not a product”
Also Bitwarden and other password managers are not just about storing the passwords. For example on a personal level I use bitwarden family to manage my Parents passwords and to assist them with issue on various service, this gives me away to setup accounts and securely share passwords with them for the services, and vice versa
For business we use the Enterprise products to share passwords for everything...
None of which is a "solved problem" at the OS or Browser level
Isn’t sharing a password in a business context like “Things you shouldn’t do” 101?
Because not all products businesses use have fine grain authentication and authorization. For example, their registar for their domain names. And differing employees need access to it at different times.
> Isn’t sharing a password in a business context like “Things you shouldn’t do” 101?
What do you think Bitwarden does? It's fine grain authorization over shared resources (passwords) that control who can access them. You categorize, create roles, and give those roles access to specific passwords. When an employee leaves, you rotate the password. Every access is recorded for auditing. It solves a real business problem.
Say I work for a large company where everything is gated via an SSO - email, Slack, internal apps, ADP for payroll, my brokerage account containing my 401K information (of course I do have a separate non SSO password for this since it is my account), and Bitwarden (I see it does support SAML).
If I leave my very large organization, it’s easy enough for a manager to disable my SSO and be mostly assured that I don’t have access to anything I shouldn’t. Because “security is job 0” (How do you say where you work without saying where you work /s).
Now let’s say that BitWarden stores 10 passwords to external services and I had access to those passwords through Bitwarden. Does someone then have to go in and manually change passwords to those 10 services every time someone leaves?
To reframe this: Companies use both SSO and BitWarden, but because a typical company utilizes so many differing services with differing auth coverage (supports SSO? supports roles, permissions, etc.?) BitWarden fills the gap. BitWarden wouldn't be used for your ADP, and 401K. It may be used for your company's payment processor under one main username / password. It may be used for your root AWS account username and password. It may be used for your DNS management. Production API keys for Stripe may be stored there in plain text, but encrypted in your secret store of choice. Those are the typical use cases I see. The list of things you keep in BitWarden are small(er), but they're business critical. Whereas before they were held by the CTO of the early stage startup, now they're centralized, secured, have an audit trail, can be easily shared with others, etc. etc.
In the company I used BitWarden with, these passwords were rotated manually when an employee who had access to that password left and the new value updated in BitWarden. Maybe that's easier now?
Also just useful for things like API keys - my team just has all of our team's allocated API keys for various services in our password manager so we don't have to go look them up in all of the various service's sites if we need them.
https://zapier.com/engineering/apikey-oauth-jwt/
https://cloud.google.com/endpoints/docs/openapi/when-why-api...
We all have done it at one point or another. But if I am ever in the middle of a technical presentation and mention “API Keys”, I get all types of dirty looks from security.
Notice that Square for instance strongly discourages API Keys for production.
https://developer.squareup.com/docs/build-basics/access-toke...
On the AWS side (where I work) we always discourage long term use of access key/secret keys for accessing resources even though I realize it’s necessary for some integrations. Even then, most organizations also put a condition that you can only use it from known IP addresses.
Including
1. Hardware Passwords
2. BreakGlass Accounts (used if SSO Fails)
3. Vendor Passwords
4. Recovery Passwords
5. Local Admin Passwords for Servers
We also use it to store Backup Encryption Keys, VPN Tunnel Keys, SSL Cert Passwords, File Encryption Passwords, License Keys, etc etc etc
We also have our own Personal Vaults that are indivualized, so we can access both our Personal Passwords and Company passwords in one interface, that is Cross OS, Cross Browser, and has API for programming interfaces.
none of which is possible with BrowserBased or OS Based Password Storage.
1Password is doing just fine..
1Password’s desktop app is much worse than it use to be all while each platforms built in capabilities are getting better.
I keep reading this but as a user of 1Password over the past decade or so, the functionality hasn't changed much. I'm confused as to what they're spending all the VC money on because these re-writes haven't done much but in terms of functionality, I think it's best in class.
What am I missing?
A full rewrite takes a lot of time. We did this twice in the past and it is always painful. We had to do it again this time because the discrepancies between the platforms became ridiculous and we had to fix this. For example, the same search would produce different results on Mac and Windows and Android.
We also took time to address some of the pain points that existed in 1Password 7. For example, it was technically possible to have a different Master Password on your Mac and iPhone, etc.
The local database was rewritten and we made sure that everything that is possible is fully encrypted. For example, all rich icons are now stored encrypted. We also changed the logging system to make sure no personal information is ever logged. At the same time, we had to make sure the data format is backwards compatible with the old version so that both 1Password 8 and 1Password 7 can be used during the transition.
We ran over 100 studies with both existing users and people who never tried 1Password before to make sure the apps are more usable by everyone.
For new users we added New Item experience that made it easier to navigate through templates and understand how to use 1Password. For developers, we added CLI integration, support for SSH keys, and a built-in SSH agent that secures your ssh private keys.
Brand new Linux app, more than 100 new features and improvements overall, on top of the full rewrite.
I'm a fan (been using it for 10yrs I think?) and think the HN sentiment around it is not representative (it's the only app I'd actually recommend to people and that I trust my family can use).
The family vault features are really great and I was glad to see the browser dropped (I didn't really get why it existed).
I do miss some native features (like the iOS letter column on the right that made it very fast to find something in the list), but generally get that there are tradeoffs to be made.
Thanks!
> I do miss some native features (like the iOS letter column on the right that made it very fast to find something in the list), but generally get that there are tradeoffs to be made.
You are not the only who missed this feature and it is coming back soon. It wasn't available in SwiftUI and we had to go back to UIKit to implement it.
Why does 1Password not support Duo Push 2FA for personal accounts? I shouldn't need to pay for a business account to get that.
Common rust library code with platform specific UI code.
Native UI code for Android, macOS and iOS. The app is Electron based on Windows and Linux for the reasons they give in the article.
Article from a year ago, so maybe outdated.
1Password 8 has a ton of new features and it is faster than the previous version. Some of the new features like Universal Autofill and SSH Agent do not exist in any other product. It also fixes many problems that accumulated in the app over the years.
More on features here: https://1password.com/products/features/
a more visual description of what's new is here: https://1password.com/mac/
Also, I certainly understand being the long time Mac expect. However, when we tested 1Password with new customers we found a ton of usability issues and many of these problems are solved in 1Password 8. One example, most new users couldn't even figure out how to create new items right away because of the look and the location of "New Item" button in the old app.
You guys make a great product otherwise. It’s the only one where I strongly recommend it over the open source alternative (Bitwarden) even though I have a strong open source bias. There’s just a 1000 things in UI and UX that you guys do slightly better than the competition, sort of an inverse death by a thousand cuts.
Hasn't really caught on, despite being several years in the making already
Google, Apple, etc are building on WebAuthN in order to allow a trusted third party to "sync" the keys, solving the major usability hurdle for most people (as with all things security related, there's an obvious tradeoff in injecting a trusted third party, but for the vast majority of people that tradeoff still results in a significant net risk reduction). I assume Bitwarden is angling to build out their own version of something in this space.
Every company’s answer to that is also the same “we will target the enterprise”.
They aren’t “doing well” if they still require outside funding.
The OS? iCloud keychain does this, it's not a compelling offering though if you need to use any other OS.
Something like Google? Not sure I'd want to risk my Google account ever getting locked and loosing access to all my other accounts.
I'm not sure what that leaves.
They could reasonably tie in to whatever Office-suite you use (GSuite, Office 365).
In the enterprise, it could be part of a larger "credential management suite" product managed by security. Allow syncing and auditing of credentials, like "when was the last time this cred was changed?" with some kind of automation to generate and push a new credential when need be.
From the outside looking in, a basic credential manager doesn't seem complex enough to be a standalone product.
Spitballing, $100M, assuming investors want 20% per annum return and Bitwarden do 50% profit ... they need 24M paying customers. Where are they at now?
If BitWarden can use that $100m to 10x their valuation and then exit (whether that's an acquisition, going public etc.) the investors will have secured a win: if BitWarden's valuation stays where it is and returns ~$10m/year to the investor(s) over the next decade, that's not a great outcome considering the opportunity cost of capital.
Debt equity is the type of financing you're describing: lower risk, lower returns, not particularly exciting and not particularly attractive to investors if they believe the company has substantial upside potential.
Clearly Bitwarden isn't a unicorn, being a smaller entity in a growing market; do VCs really expect a 10x (in couple of years?) from that sort of investment?
So, do you agree with my basic premise that they'll need a whole heap of customers, that they don't seem likely to get, in order to make any dent in the investors hoped for returns?
Edit: An interesting conversation between Basecamp's DHH and 1Password's Teare on their series-a as an opportunity to de-risk the venture: https://archive.is/Kdnpz
Also "OSS" version is not really open source, it's just core and all the features you really want from password manager are behind the paid license anyway
A cynical take on this would be the business is at a large enough volume and growing fast enough to be valued at a certain price (eg 400M), VCs want to own a certain percentage (eg 20%), so the math dictates the round needs to be 100M (100 / (400 + 100) = 20%). Then the founders put together some story that explains why they'd need 100M.
Not saying that's what happened here but I've seen it happen this way.
The code for the mobile apps is GPLv3 https://github.com/bitwarden/mobile/blob/master/LICENSE.txt
The code for the clients is GPLv3 https://github.com/bitwarden/clients
These are all copyleft... with a CLA (contributor license agreement). It's the CLA that allows them the ability to dual-license for the server.
The VCs must really believe the company can produce a product based on Enterprise sales which would deliver a value North of $1B. And perhaps they can, as Bitwarden as we know it could be considered a strong beachhead to allow them to expand into other auth markets that have high value (hello Okta, Auth0, etc).
But this doesn't seem that scary for Bitwarden users at this point.
YSK they are one and the same. Okta bought Auth0 in 2021[0]
[0]: https://www.okta.com/press-room/press-releases/okta-complete...
And from my perspective as a BitWarden customer, both of those outcomes could be worse for me. Obviously for failure, but many companies in their rush for new pots of money can do things that aren't great for existing customers. And then if those rushes don't work out, things like layoffs, reorgs, and other chaos can diminish customer focus, leading to long-term product decline.
The hypocrisy is just intolerable at this point.
they're probably over-represented given that this is an incubator-adjacent forum but startups are vastly outnumbered by both mature businesses as well as bog-standard privately owned businesses so probably not.
Most firms don't get a hundred million dollars up front, they grow products and revenue just like everyone else, with significantly fewer distortions to users or business models.
We pay them $3600 per year.
Why is everyone so concerned? They’re popular enough in businesses. Their product is great for teams, hence why we pay for it. I’ve found it much better than alternatives. The killer feature for me has been safer account sharing, including 2FA (and I know it makes it somewhat redundant, but it’s safer than turning it off completely)
LastPass tried to grow the B2C business which put more stress on the consumer product.
Very encouraging to see the stack getting a big funding round.
.NET/C# is a very underrated backend stack for startups. Stable, mature, secure, supported by one of the tech behemoths.
Is this some weird SV bubble thing I'm seeing?
SV and startups are dominated by JavaScript/TypeScript and Python. It makes the parts of the team a bit more plug-n-play and in some calculus, makes it easier to grow the team as the company grows.
There's also a bit of cultural asymmetry that may make it harder to hire experienced senior C# engineers. C# tends to be heavily used in enterprise so a startup competing for those resources may have a hard time because of that asymmetry with such engineers seeking more stability (both in terms of employment and codebase). Startups are built to go fast and break things which is the cultural opposite of enterprise where you plod carefully, plan, test, document, release, repeat.
There's always some consideration that C# may be a liability at due diligence. I can understand to some extent since it's much easier to hire for JS/TS or Python in SV than it is to hire for C#. Not that it can't be done and C# as a language is close enough to TS that a strong TS backend engineer can easily be trained to C#.
I get the idea that most developers in SV don't know C#/.Net, that happens everywhere. Some areas are java, some .net, some Ruby/Python.
What I was surprised about was this weird rationalization that C#/.Net was somehow dangerous to a startup. Not only is that not true, C#/.Net is going to be better for a startup long term due to the stability that comes with that ecosystem that you flat don't get in ruby, python, js, etc.
There is absolutely nothing outside of the hiring difficulty that would ever cause problems for a startup wrt to C#/.Net.
It's "dangerous" in some scenarios for sure.
1) You want to hire locally in SV; there just isn't a concentration of developers there.
2) You want to hire senior resources for your *startup*; I emphasize startup because you're comparing apples to oranges when comparing startup to enterprise. C# is heavily used in enterprise so a startup competing for senior resources might be fighting an uphill battle
3) You want to make sure your team is plug-n-play; there's an abundance of JavaScript, TypeScript, and Python developers. For this reason, it's probably not a great idea to choose Go or Rust because now you're competing against Google and low number of senior Rust developers in general.
4) You want a full stack team; if you hire C# backend, you'll need to train your JS/TS front-end folks to be full stack. If you're full stack C#, well, you're not going to have a good time unless your app is desktop.
----
I'm a big time advocate for C# and part of the reason I joined my current startup was to see what sort of crazy team would pick C# for a SV backed startup, but I can also see the flip side of the coin.
The C#/.Net ecosystem is a batteries included ecosystem, we're not talking about trying to use C++ to implement a website.
Functionally the major difference between C#/.Net and things like node, et al, is that the C#/.Net framework will be supported far longer than the other and the upgrade path will be a lot smoother. That's not opinion, it's objective fact. I've made a lot of money supporting companies that paid for the flavor-of-the-day du jour and didn't realize they needed to stay on the rat wheel that is major upgrades. There's literally a company dedicated to support out-of-date RoR frameworks, including older versions of popular gems with security updates they maintain themselves because of this phenomenon.
My point here is this.
There is nothing inherent in C# or .Net that is dangerous to startups, that's a bubble you seem to exist in. Not choosing C# because the area is mostly Python and JS is a legitimate decision. What isn't legitimate is rationalizing that into C#/.Net itself being inappropriate for startups in general, rather than being inappropriate for that area (for ALL companies, not just startups).
This whole thing about enterprise is a red herring. Enterprise companies use Python and Ruby as well. It smacks of a community trying to rationalize something that has no true rationalization.
As a side note, I've been tempted so many times at this point on getting a payed subscription and getting rid of my "keepass+keepassdb sync via Google drive+keepass keyfile local copy on each device" for the sake of making things simpler. I've read how the internals work, checked the auditories, read forums etc. Everything looks great, but I am always paranoid of some security issue arising and my passwords being leaked. I have my entire life pretty much on my password manager and that being exposed would be disatrous at so many levels. Probably just me being irrational.
I am also looking to self-host Bitwarden.
It has worked for me great without any issues for over a year now.
As for Wireguard, this looks pretty comprehensive: https://dev.to/tangramvision/what-they-don-t-tell-you-about-...
There are nice mobile clients available for both BW and WG.
This works great for my family. Simple set up, and I've done 0 maintenance on it.
My biggest issue is that I have wireguard automatically enable itself when not on my home network. But there are some other networks that need to be excluded, like most airline wifis, as they don't have internet access when just trying to watch a movie.
iCloud private relay does a good job of detecting these types of networks and correctly disabling itself. I wish there was something in the wireguard client to do this, rather than just retrying over and over again...
And since wireguard sets the DNS to use the pihole on my home network, this becomes problematic if they connect to a network that has a captive portal, and needs the wifi's DNS to accept the agreement and get access to the internet before switching over to wireguard and my home DNS.
While I recommend Bitwarden to my not-so-technical friends, I don't think I'm ever going to move away from my Keepass/Nextcloud setup, it just works for me.
In corporate market, I would expect more ubiquitous integration of cloud hosted identity providers and separate SSO auth providers (which will do MFA with device bound certs, biometric auth and FIDO2 auth) with all the services and they would all be protected behind BeyondCorp style VPN solutions (think Cloudflare, Tailscale etc). In this market, I wonder how they will continue to grow.
How do I explain FIDO2 Passwordless Auth to my mother?
No more passwords. Your biometric authentication along with your Apple/Google account on your iPhone/Android phone is all you need.
A more detailed blurb would be:
You sign-up and sign-in to websites/apps simply by responding to a biometric unlock prompt of your phone (same as unlocking your phone with DoubleClick side button + FaceID etc). Your sign-in details are saved to your iCloud / Google account. You can sign-in to the same website/app on another device (iPhone/Mac; or Android/Chrome device) by signing into your cloud account.
For Pro users, there may be more advanced flow:
Instead of using built-in phone authenticators, you may use a reputed third party secure authentication app paired with an external FIDO key (like yubikey) to do the same thing. In it's most secure configuration, it may combine device binding secret unlocked with biometric auth, an physical FIDO key you possess, and a cloud hosted MPC key that is used based on fuzzy signals like your device location and other fingerprint data etc. All this gives you secure multi-factor authentication that is safe against phishing, theft, loss etc.
How to mitigate loss of phone, lets say on holidays?
0. First, immediately after they lost their phone, they should call the customer care number and report loss of their phone and get their sim blocked. This is critical to avoid SMS OTP based account hijacking.
1. They will buy a new iPhone and sim and recover their phone number first. (security of this step is a function of how well telcos operate this process. In my country you have to physically go to a telco authorised dealer shop, verify your identity with a government id proof – this is the weakest step and then initiate a lost sim replacement flow. You have to get a new physical sim and then you can change that to an esim if you wish. To avoid rampant hijacking, there is a mandatory waiting/cooloff period with multiple notifications being sent to old sim if it is still active).
2. They will have to recover their iCloud account on to this new phone. This involves the iCloud password, a verification code sent via SMS to your phone and your old device passcode. This will restore your iCloud account and escrowed keychain on the new phone. For this to work, you should have opted into iCloud Keychain backup.
Obviously, the biggest problem here is if you forgot either of the two passwords (iCloud account password and iPhone screen lock passcode). This is quite likely if you have been using FaceID to unlock all the time.
Bitwarden remains committed to
A fully featured free version, forever
An open source architecture
The ability to self-host
Advanced business features
This is great!At least vaultwarden is independent and someone can fork the clients when needed.
If tomorrow bitwarden decides to do "a mongodb" (= violating the AGPL, and make it closed-source), you would have to spin up a new community to maintain the AGPL fork.
My assumption is this is so that they're legally protected from contributors revoking the right to use their contribution at some later point or other obnoxious legal shenanigans.
The other common form of CLA is a copyright assignment (or something equivalent) to a foundation or company representing the project, which is much more troublesome. This allows them to basically do whatever they want with your contribution, including charging for it, or closing the source all together.
This is why I never sign CLA. Since I'm basically signing my rights away.
That's not to say I agree with them and it's obviously shitty behaviour – but license violation is a specific act that they aren't guilty of.
Plus it is AGPL + CLA so bitwarden themselves can do what they want
But I agree it's a great thing to strive for.
Just wait for the inevitable “Our Amazing Journey” post on their website.
But maybe "are they profitable" is the wrong question. I remember 5 years ago my brother in law said "Tesla isn't profitable" and I countered with "They don't want to be profitable right now, they are growing an inventory and investing heavily in that. Showing a profit is the last thing they want to do." He seemed to be accept that answer, I mean now he has 2 Teslas. :-)
I hope things goes well for Bitwarden, but I'm also expecting an amazing journey in their future. I really doubt that there's enough money to be made as is to yield an acceptable return on investments for the $100M, plus whatever Battery Ventures have already put forward.
The only company that I can think of that has managed the transition well and gone public is BackBlaze.
When I ask “how can you trust the company”, I don’t mean to imply that the founders have less than good intentions. But once you take VC money, the founders intentions don’t mean much.
I’m sure the founders of both Instagram and WhatsApp - just two companies that come to mind where the founders were idealistic and they were hit hard with the reality stick once they got acquired - really believed that their company wouldn’t change for the worse once they were acquired.
Keybase said the same thing.
I still love the idea, but I don't see how it is a business.
To clarify: I'm not sure I buy the above thesis, but VCs don't expect 2x returns at this stage was my general point. They're aiming for higher.
It just means the VC was able to sell their shares for that 10 billion -a price which may or may not be related to the company’s actual fiscal performance
"Open source architecture" doesn't mean all the parts you need to self host it is open.
Their "ability to self-host" already includes having to buy a license to even get 2FA
It doesn't say they won't have ads or sell your data. Hint: their privacy policy is already terrible. No mention of GDPR or of them complying with any privacy laws. Their privacy policy mentions "EU-U.S. Privacy Shield Frameworks" for exporting user data to the US, a framework which has been declared bogus by the EU courts years ago.
> An open source architecture
There's no many examples of "open core" calling itself "open source" that if they decide to switch to open core they'll just be another drop in the bucket.
They also require contributors to sign a CLA, which is always a huge red flag.
> Advanced business features
What happened to "fully featured free version" above? Are the business ones separate?
Why? What is a promise like that supposed to be worth? Even if the people making it are completely honest when saying this (which I now doubt), once leadership changes this will go out the window quick.
This is in line with "Keeping our users happy is our main priority" and other quotes from the infinite pool of empty PR speak.
I've been using vaultwarden purely because I wanted to play around with rust and it turned into my favourite manager of all time.
10/10 would recommend!
That’s feature.
(As a matter of fact, it’s grown quite a bit since I started using it; it used to be under 20MB of disk space and 10–15MB of RSS.)
1. Release great product for free
2. Attract as many free users as possible to signal growth to investors
3. Keep running the unprofitable free tier at a loss as long as possible using your massive VC war chest, while locking in your users with various gotchas
4. Once you reach critical scale and gained mass user adoption and you've obliterated your competition with your bigger war chest, start monetizing and rentseeking your locked in userbase and squeezing them so the VC investors can start getting their money back or cross your fingers for an exit from a FAANG with big pockets
5. Gain a lot of negative publicity, so now a lot of startups pop up like mushrooms after rain, to poach your disgruntled users and compete with you using the exact same M.O. you did. Rinse and repeat.
Did I miss anything?
Or, you're Apple, and your cloud hosts the digital lives of all your users from teenage years to adulthood, so they're not gonna switch to any competitor no matter what.
I don't understand why anyone would celebrate and worship monopolies? Publicly listed companies are not your friends. You're just a dollar sign for them.
Also: no one is worshipping, and no monopoly has been mentioned. Nor has companies being anyone's friend. There is more non sequitur than content here :)
That made me chuckle.
(Above statement applies to most consumer technology and "digital media" companies, social networks, etc)
The whole idea is the thing you "buy" is really just an ephemeral vehicle of consumption and steady revenue stream for the corporation. Good for them, bad for you.
But my overall point is that getting rich from making something high quality that lots of people what is about as honest a way as there is.
Or they are simply in businesses with enormous barriers to entry such as designing some of the most complex microchips, writing some of the most complex software, building huge facilities all over the world, and, of course, being prepared to take advantage of a new opportunity at the right place at the right time.
At worst, we'll have to fork a current release if BW does stupid things in the future.
Even the unofficial Rust-based server looks to have more features than I need:
Self hosted was a nice middle ground. No one else has a copy of my password database, and it's always in sync between devices. Stick nginx as a proxy in front of it for https and easy let's encrypt certificate management. The downside is that Keepass by default allowed me to have copies in multiple locations. Bitwarden is only on the server, but since the database is encrypted it's easy enough to have regularly scheduled backups of it. It just is an added step to find another docker host for it if my home server goes down, during which time I may not have access to my passwords.
What were your issues? For the browser, I have some extremely minor complaints (not always detecting the correct subdomain for my selfhosted servers mainly), none for Android with Keepass2Android.
Also, no sync issues at all, but that might be related to having only 2 devices ;)
I got tired of Lastpass's janky clients, UI, and data breaches. Now I control the security of my passwords.
Arguably, they did with Bitwarden already, no? Ie even if they don't do anything bad - they still executed steps of free users and large VC checks.
Which is to say, does it not seem like they've already executed the "trick"? Users are already there, they have cash in hand. Their motivations don't matter much here, we as users can only see their actions.
But i don't follow bitwarden at all. I avoid free products for this "trick" reason. If i'm not paying or self hosting, i'm not interested heh. Am i reading Bitwarden wrong?
I can think of a way to lower costs... :-/
How do they increase their valuation 10+x without pulling those tricks.
Because that's what the VC funding demands. No VC is giving out $100mm for a 20% or even 100% return, which could possibly be achieved by simple growth. They're giving that money because they're expecting exponential return.
Maybe there is an enterprise play somewhere here which justifies this, while maintaining the core product in its current form. I guess we will see, but I'm not holding my breath.
The post mentions the plan to implement advanced business features, and also "Business users deserve consumer ease-of-use along with advanced integration and deployment features."
The way it works is if the free/small customer cost to maintain is just absolutely minuscule compared to the total costs/revenue.
I wonder, aren't the majority of HNers working at a for-profit company funded by VCs?
The hypocrisy is just intolerable at this point.
At the end of the day, engineers/programmers are the ones who implement these changes. I find it unacceptable that lots of HNers get so high minded about these issues but then go on to contribute to the problem by working at for-profit companies. Nothing wrong with either one, just choose one.
I think for BW this kind of falls apart at #3. The main draw of this product for me and many others is that it's actually pretty no-frills. It's also broadly compatible with importing and exporting between dozens of other password managers.
That said, this could be a blind spot for me. Let me know if there's any gotchas I should know about here.
That is the only direction which I think could charitably use this $100m productively.
- They have a hosted/managed version with a free tier and a paid tier. Paid adds things like MFA and support for orgs. The more you pay, the enterprisey-er the org support gets.
- There's also a self-hosted version which follows a very similar scheme. You can start out for free, but if you want things like MFA or a self-hosted org, you're paying the Warden.
Once they're set up with it, the idea of "importing and exporting between dozens of password managers" is meaningless. And gotchas aren't always limitations but can be "positive" like well meaning features, integrations, your company using it (so you too), etc. Lock-in comes in many forms.
Hardly locked in.
Basically chasing the new shiny.
Having said that: I haven't dug into it much. I don't know what the current state of auditing on it is, or how widespread adoption is relative to the mainline BW backend. I hope they use a database backend other than BW's default MSSQL, which has always seemed like a weird choice to me coming from mostly Linux, and so mostly Postgres and Maria/MySQL, though I skew heavily developer over DBA, and that distinction may as well be personal preference (as in, I don't have an intelligent reason to dislike MSSQL beyond my habit of using other things).
If everyone expected a car to be free cars would be loaded with all kinds of convoluted bolted-on features to extract money from you: ads, special fuels that can only be produced by the maker, special licenses to drive on roads, special deals with repair shops, and so on.
What you describe is actually one of the less shady ways of funding software. The more common, successful, and shady methods are surveillance capitalism, addictionware (most of mobile gaming), and cryptocurrency scams.
If you structure the market such that honest business is difficult to impossible, things don't stop costing money. They just find less honest ways to make it.
When I see capital raised, the treadmill for an expected return starts running and it is not for everyone.
JetBrains was also founded in Eastern Europe which probably helped a lot in getting off the ground with little money as there your dollars used to go way, way further than in the west and the local job opportunities were scarce.
In the early 2000's an experienced SW dev in my corner of Eastern Europe was lucky to take home 300 USD and would not shy away form overtime as needed. Replicating the same thing in present day would be impossible as now no self respecting experienced dev here would get out of bed for less than 2k EUR take home pay and would absolutely do the bare minimum with zero overtime, or even work way less than the contracted working time.
The 90's to early 2000's was a wild west in Eastern Europe. Few job opportunities, low wages and low CoL, plus fast internet in every home, meant that everyone was hustling hard in their free time to make a great SW product using no money at all to sell on the international market and get rich.
Now things are different here. Plenty of great paying jobs at established western companies or startups means that the people here are more likely to just want to work at random big corp or new startup for good pay and WLB rather than put 50h+ workweeks in building their own product at home like their predecessors did.
My point is that JetBrains was more of an exception by catching a great wave in time and space that can't be replicated today.
My only gripe is filling in card details, there is never a floating icon to click to do it automatically, you need to go to the menu bar and select the card.
Apart from that all perfect!
At one point I became convinced that this is actually a security feature. If I recall, an article demonstrated tricking users into entering their master password using those "in-browser" decorations. I could write some html/js to build your password manager icon/etc and trick you into thinking I'm your password manager? I now accept it as a necessary UX chore to leave the browser page, but would be interested in being wrong.
One of the things I used to store in LP was AWS IAM creds. Sure, you can store it in a Bitwarden "secure note" but it sure was convenient to have a defined format for it.
I feel like I might be grandfathered in and they switched to a new model now, but I got Enpass years ago and haven't paid since. I sync my password archive through iCloud so I don't have to trust a random company to store my password archive safely. If anything, by doing that you're centralizing a ton of user logins in a single place that would be a great target if you found a way to hack in and read them.
I also didn't want to run the Dropbox client just to sync passwords. Paying Bitwarden $10/year made sense to me.
I think it's an impedance mismatch trying to take a single-user database format and trying to use it from multiple devices
I don't have an iCloud client installed on my devices (well, other than whatever is built into Apple devices) but Enpass just uses their APIs to sync passwords. Occasionally I have to reauthenticate on one of my machines but it tells me as soon as it loses access. Previously I synced it over Google Drive and I never installed a Google Drive client either.
I had many instances of not noticing Android had killed the Syncthing backend again despite being explicitly told not to, and then I had two out-of-sync password databases and would have to go merge them again.
I'm still bitter about it, because Syncthing as a syncing layer is so much more elegant than everyone implementing their own server and sync protocol.
- I selfhost it on my NAS so I don't have to depend on a 3rd party to sync all of my password (even though they are encrypted).
- If I need to access my passwords from a new/temp machine, there's a web UI I can access very quickly
- The client is much prettier and nicer to use. The KeyPass clients all felt very dated and clunky.
I was lucky enough to have a brief exchange with their CEO on his recent customer interview tour, and my impression was his product view was enterprise focused, which made sense in the context of this raise now. My relatively cold read was he seemed laser focused on a kind of "do what we do really well," philosophical vision on their current product, which I think is a strong asset to secure their LTCV with current customers, and that will drive their valuation.
However, I get overexcited at the growth prospect because security products are never what anyone but security people actually want, and all the products in the identity space suffer from the same problem of being top down management frameworks with integration and federation as just something you say but never do. A consumer security product people actually choose for themselves and want their employers and services to integrate with because they already like the experience of it, is just infinite level growth potential in a market of slow moving dinosaurs. Okta's massive expansion in just the last decade established that the gerontocracy of enterprise behemoths was too slow footed to respond to an incursion into the very foundation of their market (user identity), and what impressed me about this raise is that I think a well capitalized startup with traction could absolutely sack it.
What a waste.
Bitwarden will now be pressured to try to grow and monetize to make a return on that investment.
Both app and server need so much polish. Like this is literally like touching something from 00s and everyone seems to be content with it.
I truly hope Bitwarden would put money to better their app and technology, focusing on User Experience, not on feature checklist.
I can’t imagine needing $100M for developing this kind of product. Anyone has a guess?
That, and their UI is pretty cluttered and ugly, though the latter is subjective.
Building and maintaining clients for all operating systems and browsers probably costs the most, but it can likely be done by 1 or 2 full time engineers.
Or am I completely underestimating the complexity of something like this?
"Additional security has been placed on your Bitwarden account. We've detected several failed attempts to log into your Bitwarden account. Future login attempts for your account will be protected by a captcha."
Thanks HN! =)
I find lastpass clunky.. ipad app is flakey (or is it the iOS integration layer itself?)
Integrating with chrome, iOS, etc, I assume is a difficult problem so I've assumed most password managers have the same issues. But it drives me crazy they haven't innovated much either, e.g., searching for specific passwords in my vault. I have to export it to excel and then look for them, then make sure / hope that the excel file didn't drop any temporary file copies anywhere.
Which has taken more time? Learning how to use gopass and a yubikey, or migrating password services every few years and paying hundreds for arbitrarily pay-walled features?
Edit: idk, maybe there's some UX aspects of the password sharing features that are more important to other folks, otherwise, the diy option is not that hard, or a UX sacrifice.
It would be cool if there were a Bitwarden "extension vault" that is only accessible so long as you are employed somewhere and which suggests rotation as part of offboarding etc. Anyway, congratulations and good luck.
How much would I pay for that? Perhaps with ACLs and stuff I think $10 / user-month
They are betting their future on the enterprise market and the announcement blog post links to their Partner [2] page—a central part of their strategy to gain a foot-hold in that market.
In the enterprise market, inertia and regulations cause user habits to change much slowly relative to the consumer market that Bitwarden is most familiar with, plus enterprises are not price sensitive, so they can get away with charging really high prices, to justify their huge capital raise.
1: https://bitwarden.com/blog/accelerating-value-for-bitwarden-...
I strongly suspect that this new VC-funded Bitwarden will eventually close off their applications API and client applications, but with an open-source server API provided by Vaultwarden it should be possible to create new, open-source clients, too.
How much time do we have left before Bitwarden gradually becomes as bad as LastPass for the sake of high growth? 2-3 years? I’m not passing any judgement on this raise, entrepreneurs do what they gotta do.
Bitwarden though actually has an API, and in turn interesting community implementation potential such as the Rust-based Vaultwarden [0]. While I agree seeing them get a huge round does raise some concern in terms of the revenue generation pressure (1Password sticks in my mind as a worse example though with their switch to forced subs-only, no local/non-1P vaults, abandonment of native apps etc), to me the real sign would be if they broke self-hosting. But even so, of course with self-hosting one could simply stop there. Doesn't feel like quite the same situation as 1P or LastPass where one was really in a fully vs partially proprietary system.
I'd be OK with paying for updates to quality clients though so long as it was a regular payment system (not paying means staying on that version vs having it stop working).
----
Nothing wrong with charging for a premium version, just curious how users handle things and why there seem to be so many users on the free plan. They all just don't know or care about 2FA?
Once I locked out of Bitwarden because of Cloudflare blocking my IP address for some unknown reason. I restarted my router and the problem got fixed.
I think bitwarden's TOTP generation is a paid feature, but it still provides the option to store the secrets in the free version
https://community.bitwarden.com/t/linux-fingerprint-and-or-b...
Since their codebase is in the open, and there's already at least one other Open Source implementation, that's likely about as "clear/open" as its going to get unless this newfound $100M spawns an API team or something
And even though I don’t use Windows much, it’s nice that I can use the win client there.
Personally I use bitwarden so I can have unified access to passwords on my windows laptop, iphone and android phones.
You can store a lot more data in Bitwarden as well, including custom fields, so you aren't stuck with just a username and password and optional 2FA. With Bitwarden you can do security questions, a notes field, etc.
Sharing with family is another big feature. Sharing your cable login, wifi password, streaming services, etc.
There's a whole list of them, but I think those are sort of the top 3 for me.
Because BitWarden works on more devices than what Apple supports.
It sucks. Gone are the days where you could buy Microsoft Office and run it for 10-15 years.
The thing is, I've never used any other password manager on Android so I can't tell if the problem is Bitwarden or if the problem is Android.
A lot of password managers have some simple UI to show you your weak passwords and it's a but of a fun game when you first import all of your passwords. Take a few days and browse all of your accounts and either delete the account or beef up the password!
- Ecosystem agnostic, from before I was all in on Apple
- Ties into other services I use seamlessly
* Fastmail masked emails for signups
* Privacy.com one time use cards/vendor locked cards for signups
Other add on I'm more dubious about:- 1Password supposedly alters password suggestions based on the domain, adjusting password length requirements, special symbols, etc
If they do something stupid, I'll run one of 2 OSS servers available and it's done (or have someone else host it for me).
Been using google password since lastpass turning on paywall. What's your opinion of Bitwarden? Reasons to give it a try? Having all passwords locked up is no fun.
This means if worst comes to worst, the community will fork the code and set up a new server or 2.
I switched to it after the Lastpass changes and BW literally has everything LP had plus more. It even imported my thousands of LP entries on first try with no issues.
The UX might be a bit uphill for non-techies. (Example: Tab, Vault, Send, Generator, Settings are what is displayed for the main browser interface. Can you guess what they do? Selecting a Keyboard icon is "view account".)
Having said that, I do think there is an opportunity for Bitwarden to expand into application secret management, and that could be a lucrative market with big enterprise customers if they get it right.
The announcement seems to be a generic “nothing will change” announcement though, which doesn’t inspire confidence as:
- These are almost always reneged on later
- Clearly something has changed (or why bother getting investment), they’re just not telling us what “we can deliver on our roadmap more quickly” could not possibly be more vague.
I expect to see a rapid push to enterprise with individual users left behind and a lot of broken stuff along the way :/
The market does seem to have space, 1password has an estimated ~235m revenue, and lastpass and dashlane ~70m. And all of them are quite a bit larger than the latest headcount I saw for bitwarden (reap. 800, 400, and 400, versus <100 for BW).
But it is worrying, especially with bitwarden having low TCOs currently, especially for the free-er side of the offering.
You mean like they mention in the announcement that they will be doing?
What's wrong with saying "this is a useful tool" and leaving it at that?
It doesn't matter how well intentioned the founders are - once you accept that kind of money, it's not your product anymore. You are now in the business of making money, nothing else, and those skewed incentives will start bleeding into their product and business practices sooner or later.
As a company, Bitwarden has been a huge role model for me, and I hope they'll be the exception to the rule. But $100M is a lot of money, and I simply can't imagine it having a net-positive effect on the company and product. But we'll see...
For anyone looking for a bootstrapped, open source alternative to Bitwarden, check out Padloc:
https://padloc.app/ https://github.com/padloc/padloc
(Disclaimer: I'm the founder)
Hope this won't happen to Bitwarden but we'll see. But anything is still possible.
There's even an unofficial Rust reimplementation of the server which is even better.
Parent post is spreading FUD on this one.
https://bitwarden.com/blog/bitwarden-network-security-assess...
I also hope it won't happen but many good projects have gone this way before.
In this case the investment is not for the password manager but for a new identity service. However if that doesn't end up providing the promised results, the shareholders will start looking at the existing successful product to extract more value. After all they own part of that now and they want their returns. It's just what they do. This will clash with the users' best interests sooner rather than later.
Then it becomes forking time but can they find a good maintainer? Open source is not always a guarantee for continuity.
Of course if the new project pans out this won't happen but it's a gamble, and one the existing userbase never asked for.
This doesn't worry me that much. In the event that incentives get skewed (which isn't certain), I guess I could just stop updating the app before that happens, or fork the last good version?
I'm interested in your alternative. I hadn't heard of it, went on your site and it looked decent, I think if I had seen this before going with Bitwarden I'd have seriously considered it, BUT now that I'm a keen BW user, it doesn't seem as if there is enough for me to switch.
Are you also definitely never going to take VC money? Or an acquisition, say, by Bitwarden? Why should I trust you (and a product I've only just learned about)?
This is easily said, but remember you're talking about a security-sensitive application. Do you really trust yourself to keep your fork secure? I know it doesn't look like it on the surface, but password managers have become wickedly complex, especially if you require things such as shared vaults, audit logs, a zero-knowledge architecture etc. The reality is maintaining your own fork won't be feasible for the vast majority of users, even those with a technical background.
> Why should I trust you (and a product I've only just learned about)?
The simple answer is that you shouldn't. You should ALWAYS be sceptical, and look for possible indicators of a company heading down the path to the dark side. Like taking a 9-figure sum of VC money for example ;)
No, but I don't need to. Considering how many people are already contributing to Bitwarden's Github in the form of PRs and such, if worst comes to worst, there should be plenty of people who can maintain it.
Althought I wonder how much it will take for this padloc fellow to turn around and announce that he decided to accept VC or even worse, issuing tokens on Ethereum.
We are almost at the Minsky moment and lot of founders are going to realize they no longer own the companies built.
"We're building padloc because we see no way to avoid X Y Z"
Keychain will continue to get better and better for those in the Apple ecosystem, and for much of those outside it, Chrome provides enough.
Having a windows box as well as all my macs make it less nice.
1. sure, it's great that it is open source and that I could self host, but honestly, it's just not worth the trouble for me and I'd rather pay 10-20 euros for someone to take care of that for me. Self hosting my password manager would take a significant time investment and constant worry whether I'm doing it right. It might be because I'm primarily an app developer now and not a backend expert anymore.
2. Most big projects like Bitwarden are alive because there is a company and many full time employees behind it. Once that's gone, relying on a couple of passionate volunteers might not be enough to keep the project alive.
All in all, I've been using Bitwarden since the LastPass fiasco, I'm very happy with it, paid user with my family, but if I had to self host or volunteer, I'd not have the bandwidth to do so and I'd rather switch to another solution, even if it would mean I need to pay.
I think that when people say "it's open source, I could just self host and maintain the project" often underestimate how much effort that really is. Sure, it's possible, but will you actually do it?
I'm (casually) looking to move off LastPass. Padloc looks pretty good, but I'm hesitant to go with an 'unproven' solution.
Change how exactly? More money needs to flow.
VC investments: a mechanism where the rich invest their spare money on other in order to extract more wealth for themselves.
As a customer, what I can do is compare with the competition. Padloc is more expensive than basically every other option out there. And as far as we can tell, Bitwarden was already running privately before this VC round (which seems aimed at expanding their offerings past password management) which doesn't seem to point to it being unprofitable at its current price point.
That all depends on the margins of what is being offered. If you are proposing they sell a dime's worth of product for a nickel, then I would see the above post as a much more polite version of the correct response, which is "get lost."
I'd have no problem paying more for a good product if it brings me something. In the meantime, I'm still left pondering. "Get lost" would be a rather crappy way to treat customers simply asking questions, wouldn't it?
For me it’s not about the price but the recurring cost and the lock in. I’d rather pay a larger sum upfront when I’m sure I can afford it and reevaluate when it’s time to upgrade than be sucked dry bit by bit and have to drop everything to scramble to find an alternative when the developer decides to remove features and jack up the price overnight as they keep the data hostage.
¹ Smaller than a Starbucks coffee, but also higher quality.
I wish more companies followed the Jetbrains model where a subscription buys lasting access to the current version and recurring payments gets you continuous updates. It's easy to see why companies mostly avoid this model though; it's easier to squeeze users for money when you have them held captive.
Argh. If only there was a decent cloud-based open source alternative that worked on Windows, Linux, iOS, macOS, Firefox and Chrome.
Since the Bitwarden feature-set is pretty darn good my hope is that some foss "bitwarden-api" client applications come along and that'll offer a more independent solution.
https://github.com/padloc/padloc/runs/8205722258?check_suite...
Is it just that our anticipation (or foreboding) of the effects of capital infusion is biased by our priors about the company? Or, some other reason?
* What makes you invincible to investment? * What makes you different from BitWarden? (they are also opensource, might have been bootstrapped too, also claim being autdited) You seem to only really be "an alternative", which is great, but you kind of oversell it I think. * "I simply can't imagine it having a net-positive effect" --> or do you mean on "your" company? Because, you seem to also sell a product: access to the hosted solution of your open source product. * Open source BitWarden server-side API implementations exist... Even in Rust (not that that matter that much given the nature of e2e encryption). * Are you not interested to one day provide an enterprise tier over you family tier?
Disclaimer, I'm a satisfied user of BitWarden's free tier for some years.
So here my main gripes with BitWarden:
* There is an option to send them your password file for them to import it. This goes against their e2e philosophy that I believe it should have huuuuuge red tape, and it does not. They should deliver this type of functionality in a manner that I can run it on my local machine.
* Horrible UX. I've often been searching where they hide the save or edit button this time. You're product looks nicer in this department.
Good luck with your product! I'm a little busy, but I may give it a try some day. To me there is a safety in BitWarden not going belly up, and alternatives (self-hosting and your product) existing.
Can you even imagine what kind of stuff they had to tell their investors in order to get 100m?
You have to trust the server. It could serve the user with malicious JS code or an app update at any time.
You can self host it though.
Likely though they will be stored and kept properly, and there won't be leaks. I only said 'unfortunately' because it hands dependence over to Google. Loss of access is the main concern.
I still use the Bitwarden extension in Firefox, which is a similar attack surface to what you describe, though probably a shade less vulnerable in practice. I’d like to replace it with something leaner and functionally superior (it’s pretty heavy, and has the major problem of mostly not working in Private Browsing windows, and some other timing/focus issues that I suspect stem from the same bad design), but I have too much other stuff I want to use.
I don’t serve the Bitwarden web interface on my server at all, but I could.
More often than not these corporate open source projects include spyware features (Bitwarden included) that phone home without user consent.
They claim selfhosting is a goal, yet their published client will report on your activity to Microsoft without your consent.
More info here: https://bitwarden.com/help/security-faqs/#q-what-third-party...
F-Droid: https://mobileapp.bitwarden.com/fdroid/
Self-hosting: https://bitwarden.com/help/install-on-premise-linux/