Project ideas from Hacker News discussions.

Bitwarden Dual License Model

📝 Discussion Summary (Click to expand)

1. Fear of a gradual “boil‑the‑frog” lock‑in via licensing changes
Many commenters see the new dual‑license move as the first step toward making premium features closed‑source and eventually phasing out the free/open‑source offering.

“The new owners are just seeing how gradually they can boil the frog before the userbase moves elsewhere. Gotta maximize returns.” – Rebelgecko
“My concern is that this is usually step 1 in a boil‑the‑frog strategy to eventually split and break off enterprise features.” – freedomben

2. Conditional acceptance if source remains available and self‑hosting stays viable
Several users say they’ll keep paying as long as the code stays open and they can run their own instance.

“I actually find this somewhat understandable; and I'll be continuing my subscription; as long as all source continues to be available and personal self‑hosting remains a viable option.” – dannyw
“I struggle to think of solutions: … the main viable solution seems to be… changing the license.” – dannyw (continuing the same thought)

3. Self‑hosted alternatives (Vaultwarden, Keyguard, KeePass, etc.) as a safety net
The discussion repeatedly highlights Vaultwarden and compatible clients as ways to retain control if Bitwarden’s service deteriorates.

“Ran Vaultwarden for a team of ~15 for years and that's the part I'd watch here, the clients are the leverage, not the server.” – hn3ufz62f7
“The Bitwarden web client has actively broken Vaultwarden compatibility at least once … a hard fork of the entire ecosystem for Vaultwarden is fairly likely.” – chrismorgan

4. Complaints about Bitwarden’s performance, bloat, and UX
A noticeable share of comments criticizes the official clients as slow, heavy, or buggy, prompting interest in lighter alternatives.

“IMO Bitwarden really isn't that well engineered software… massive almost 400MB‑download behemoth (and is electron‑based)… slow and mediocre.” – 0l
“The main thing is it's just slow as molasses… Auto fill can be buggy… Opening vaults on iOS can be remarkably slow.” – Saris
“Besides being slow, I found it buggy as hell… there's even an open issue on Github about this, that they're doing absolutely nothing about.” – movsx


🚀 Project Ideas

MicroVault

Summary

  • A ultra‑lightweight, self‑hosted password manager backend written in Rust that uses <10 MB RAM and minimal dependencies, addressing complaints about Vaultwarden’s memory usage and sluggishness.
  • Core value proposition: drop‑in replacement for Bitwarden/Vaultwarden API that runs comfortably on low‑end VPS, Raspberry Pi, or even router‑level hardware, giving self‑hosters a truly “no‑nonsense” option.

Details

Key Value
Target Audience Self‑hosters, privacy‑conscious users, and devops teams running password managers on constrained hardware
Core Feature API‑compatible with Bitwarden (collections, orgs, 2FA, attachments) while storing data in SQLite with optional AES‑256‑GCM encryption; admin UI omitted to keep binary <5 MB
Tech Stack Rust (actix-web + sqlx), SQLite, Dockerfile for multi‑arch builds, optional Prometheus metrics
Difficulty Medium
Monetization Hobby

Notes

  • HN users complained “Vaultwarden … still a lot of memory … an order of magnitude more than what is realistically required” (movsx) and wished for a “lightweight” alternative; MicroVault directly targets that pain point.
  • Provides a practical utility for running a password manager on a $5/month VPS or home lab, reducing barrier to entry for self‑hosting.
  • Could spark discussion on trade‑offs between feature completeness and resource efficiency in open‑source security tools.

NativePass

Summary

  • A truly native, cross‑platform password manager client (desktop + mobile) built with Flutter/Tauri that avoids Electron, delivers <50 ms startup, and integrates platform‑specific biometrics and YubiKey support.
  • Core value proposition: fast, reliable autofill and unlock experience that matches 1Password’s polish while remaining fully open‑source and compatible with any Bitwarden‑compatible server (Vaultwarden, self‑hosted, or Bitwarden cloud).

Details

Key Value
Target Audience Power users frustrated by slow/boggy Bitwarden extensions, YubiKey owners, and anyone seeking a snappy native UI on Windows/macOS/Linux/iOS/Android
Core Feature Unified vault access with platform‑native biometric unlock (Touch ID, Windows Hello, Android fingerprint), YubiKey challenge‑response, and system‑level autofill via accessibility services (Android) / native browser messaging (desktop)
Tech Stack Flutter for mobile/desktop UI, Tauri for lightweight desktop wrapper, platform‑specific plugins for YubiKey (yubico‑rust), native bridge for autofill
Difficulty Medium
Monetization Revenue-ready: “Supporter” tier $4 / mo for early access builds and priority support; core client remains free/Hobby

Notes

  • Commenters praised Keyguard for being “much faster/lighter” but lamented lack of browser addon and YubiKey issues (movsx, 0l); NativePass would give a native alternative with those features.
  • Addresses the UI/UX frustrations: “the Windows desktop client is a massive … Electron‑based… slow” (0l) and “autofill sucks so much on chrome desktop” (maxo133).
  • Could become a focal point for discussion on balancing native performance with open‑source collaboration.

PassMesh

Summary

  • A decentralized password manager that stores encrypted vault shards on IPFS (or Filecoin) and uses a libp2p mesh for peer‑to‑peer sync, removing the need for any central server or self‑hosted instance.
  • Core value proposition: “password manager that can’t be enshittified” – data lives only encrypted on distributed storage, accessible from any device with the master key, appealing to users who want a trust‑less, server‑free solution.

Details

Key Value
Target Audience Privacy absolutists, cryptocurrency enthusiasts, and users wary of any centralized password‑store (including self‑hosted) who still desire cross‑device sync
Core Feature End‑to‑end encrypted vault split into IPFS‑pinable chunks; sync via gossip‑sub libp2p rooms; conflict‑resolution using CRDT‑style merge; optional PIN‑protected recovery shares
Tech Stack Rust (libp2p, ipfs‑core), WebAssembly port for browser extension, React‑Native mobile frontend, optional Filecoin incentivized pinning
Difficulty High
Monetization Hobby (open‑source); potential future “pinning service” premium for guaranteed availability

Notes

  • Several users dreamed of “an ipfs/torrent version without a central authority” (Cort3z) and wanted a “provably private client‑based browser decryption script”; PassMesh directly fulfills that vision.
  • Eliminates concerns about server compromise, licensing changes, or hosting costs, aligning with the sentiment “password managers should not involve hosting at all” (torzer321).
  • Would generate rich discussion on trade‑offs between usability and decentralization, and on integrating CRDTs with secret sharing.

BuildGuard

Summary

  • A service that provides reproducible, audited builds of popular open‑source password manager clients (Bitwarden desktop/browser extensions, KeePassXC, etc.) with signed binaries, SBOMs, and automatic F‑Droid/Play‑Store publishing pipelines.
  • Core value proposition: eliminates the “trust the binary” worry by letting users verify that the client they install matches the published source, addressing fears of hidden telemetry or malicious forks.

Details

Key Value
Target Audience Security‑conscious users, sysadmins distributing password managers to teams, and anyone who wants verifiable builds without maintaining their own CI
Core Feature CI pipeline that builds clients from tagged source in isolated environments, generates SBOM (CycloneDX), signs artifacts with cosign, publishes to a transparent log (Rekor) and optionally to app stores; UI/dashboard shows build provenance and diff‑against‑source
Tech Stack GitHub Actions / Bazel for reproducible builds, cosign for signing, Rekor for transparency log, SQLite DB for metadata, lightweight React dashboard
Difficulty Low
Monetization Revenue-ready: “BuildGuard Pro” $9 / mo per organization for private builds, priority signing, and audit logs; free tier offers public builds for popular clients

Notes

  • Users expressed distrust: “I have no idea how Bitwarden works…” (ricericerice) and “I’d be interested in hearing about this too” regarding LLM‑written forks (InsideOutSanta); BuildGuard gives a concrete way to verify authenticity.
  • Directly tackles the “boil‑the‑frog” fear by ensuring that any future client changes are visible and auditable before distribution.
  • Low effort to launch (reuse existing build scripts) yet high practical utility for enterprises and privacy advocates who need provable supply‑chain integrity.

Read Later