Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Claude discovers a novel enzyme system with CRISPR-like repeats(anthropic.com)
    425comments
  2. VSCode's SSH Agent Is Bananas (2025)(fly.io)
    52comments
  3. Linux support is coming to Snapdragon X2 Series(qualcomm.com)
    6comments
  4. Fixing the Portobello Police Station Clock(pointinthecloud.com)
    83comments
  5. LensVLM: Compressing long context as images, expanding only relevant pages(huggingface.co)
    2comments
  6. Italian parliament votes for return to nuclear energy(apnews.com)
    312comments
  7. A brief history of Windows scroll bar shortcuts(devblogs.microsoft.com/oldnewthing)
    39comments
  8. The mystery animal on an ancient god's head(signoregalilei.com)
    8comments
  9. We just shipped support for the ugliest part of HTTP: Vary – Cloudflare Blog(cloudflare.com)
    discuss
  10. The Curious Power of Punctuation(newyorker.com)
    2comments
  11. Jev in 25 Lines of Python(nobodywho.ai)
    193comments
  12. Gemini 3.8 text-to-speech(blog.google)
    115comments
  13. Radicle: Disclosure of Vulnerability in the Network Protocol(radicle.dev)
    42comments
  14. Mercury 2.5 LLM hits 770 tokens per second(artificialanalysis.ai)
    2comments
  15. Show HN: An atlas of system designs with interactive architecture diagrams(atlas-sysdes.vercel.app)
    17comments
  16. Tokens too cheap to meter(jyn.dev)
    173comments
  17. Making Tailscale Faster(tailscale.com)
    6comments
  18. Stripe's Knowledge AI Platform(stripe.dev)
    101comments
  19. Swap, ZRAM, Zswap and Hibernate on NixOS(matthewbrunelle.com)
    4comments
  20. I don't want the details(michaelheap.com)
    189comments
  21. Bwbach, My Guardian Goblin(robertmay.photography)
    4comments
  22. OpenAI breaches Medicare, Albanese reveals(smh.com.au)
    64comments
  23. Z80 REPL (2018)(abagames.github.io)
    18comments
  24. Claude Code reads AGENTS.md only when telemetry is on [fixed](szypowi.cz)
    242comments
  25. Once Claude can measure something, it can make it faster(claude.dev)
    83comments
  26. QuestDB (YC S20) Is Hiring a Sales Engineer(questdb.com)
    discuss
  27. A refined phylochronology of the second plague pandemic in Western Eurasia(pnas.org)
    discuss
  28. Show HN: I built a post-mortem debugger for native Windows x64/x86 crashes(forensicdbg.com)
    2comments
  29. UK military jamming other nations' satellites to defend itself, BBC told(bbc.com)
    173comments
  30. 28% of job postings on company career sites have been open over 90 days(unlisted.careers)
    272comments

Bitwarden integrates with OneCLI agent vault

63 pointsby 5mo agoonecli.sh
31 comments
5mo agoHN ↗

Did you actually read this article or try to understand what OneCLI does?

5mo agoHN ↗

Nobody wrote that article, why should anybody read it?

5mo agoHN ↗

Took VC money, here comes the AI enshittification.

5mo agoHN ↗

EDIT: My bad. I saw "agent" and immediately thought of AI.

5mo agoHN ↗

It doesn't, this is why this announcement is not about Bitwarden incorporating AI.

5mo agoHN ↗

Tangential: Where is Bitwarden on the below roadmap right now? It wasn’t even good to users, but was an alternative to 1Password and others that had long crossed this bridge.

‘Here is how platforms die: first, they are good to their users; then they abuse their users to make things better for their business customers; finally, they abuse those business customers to claw back all the value for themselves. Then, they die. I call this enshittification, and it is a seemingly inevitable consequence arising from the combination of the ease of changing how a platform allocates value, combined with the nature of a "two-sided market", where a platform sits between buyers and sellers, hold each hostage to the other, raking off an ever-larger share of the value that passes between them.’

- Cory Doctorow

5mo agoHN ↗

They switched from a purchase with local vault storage model (where you could sync it to the cloud if you wanted to) to subscription-only with cloud storage they control.

5mo agoHN ↗

Short of using pass, what are some good alternatives? My main critic of 1Password has been the cost, but it is a very good password manager, and price seems to have gone down... Or at least the dollars has weakened enough that the price has come down for me.

5mo agoHN ↗

and price seems to have gone down

They sent an email a couple months ago stating prices were increasing as of Mar 27. The family plan went from $59.88 USD per year to $71.88 But it's still worth it IMO.

5mo agoHN ↗

Weird that their website isn't updated yet. My subscription renewed earlier this year and I noticed that the price had come down, but that's because the dollar has lost 15% of it's value since last year.

That is a pretty big price bump though, and I think it's going to cost them. It's certainly enough that I'll reconsider Bitwarden.

5mo agoHN ↗

Bitwarden also increased their prices earlier this year, although it's still less than half the price of 1Password.

5mo agoHN ↗

It wasn’t even good to users

I may be out of the loop, but how was Bitwarden not "good" to users? Does this relate to the recent price increase?

5mo agoHN ↗

I don't get what semantic value you're getting by pasting this. It's almost like saying "VC-funded tech = bad", which is an ironic stance to take on this platform.

Is there anything that bitwarden did that is actually bad for you as a customer of theirs?

5mo agoHN ↗

How soon until those of us who are running Vaultwarden need to fork the Bitwarden clients, too?

5mo agoHN ↗

Reading the article, it sounds like this is the other way around? Bitwarden is offering a new API, and OneCLI Agent Vault is integrating with the new API.

5mo agoHN ↗

integration is a two-way street. it doesn't matter which is stated first

5mo agoHN ↗

I disagree that integration is commutative.

Often, we see a feature which is important to free use of a computer as a general-purpose tool locked behind an ever-changing and/or poorly documented API in a closed-source, centralized, de-facto-government-subsidized project.

The power dynamics of that situation are not symmetrical, so it does matter which project(s) are using which API(s) of the other(s).

5mo agoHN ↗

I added "login with google" to my website. Should I go to the news media to brag about how google is launching an integration with me?

5mo agoHN ↗

I really don't understand the HN comments here.

Lots of assumptions that the article is AI-authored (it could be but I'm not seeing overtly obvious signs - it's quite readable) & a lot of ungrounded assumptions that this is somehow related to Bitwarden integrating AI into their product.

I really thought reading comprehension among HN users was better than this.

5mo agoHN ↗

There are worse things to mention about OneCLI as it looks like a completely vibe-coded mess, seeing that CLAUDE.md and Claude itself being one of the contributors [0]

Perhaps the most damning discovery is that they don't even do basic dependency pinning [1] [2] which just risks another supply chain attack.

As soon as I saw that, that was everything I needed to know about the project. No security audit whatsoever and Bitwarden believes this is something worth integrating.

[0] https://github.com/onecli/onecli/graphs/contributors

[1] https://github.com/onecli/onecli/blob/main/packages/ui/packa...

[2] https://github.com/onecli/onecli/blob/main/packages/db/packa...

5mo agoHN ↗

Having agents contribute to a tool designed for agentic coding is thoroughly unsurprising - if anything, your contributor link showing that 873 LoC were written by Claude, in a project with tens of thousands of lines contributed, seems to show far fewer agentic contributions than I would normally expect. It seems far from vibe coded looking at those stats alone.

The lack of package pinning is unfortunate but common enough that I'd simply open a ticket (& expect them to address it) rather than writing off the entire project.

The lack of a security audit for a project this young is also unsurprising & hardly notable.

5mo agoHN ↗

Yeah, it seems like this is at minimum an "ok" thing. Honestly having a good way to do secrets management with agents seems like a good idea.

5mo agoHN ↗

OneCLI does not even have a security audit and a VC backed password manager believes that it is secure enough to integrate in their password manager.

I could not be anymore bearish on Bitwarden than before after looking at this and very glad that I don't use them.

5mo agoHN ↗

I don't understand why this would change any opinion on Bitwarden. Bitwarden offers an API and OneCLI calls the Bitwarden API. How does a 3rd party calling Bitwarden's API say anything about Bitwarden?

Edit: I can see on Bitwarden's site they also call out their support for OneCLI, so I suppose that looks like Bitwarden saying they approve of and recommend OneCLI. But I see recommending an open source solution as a lot less problematic than recommending any other random private startup solution.

5mo agoHN ↗

These tools are useful, but I can't help to feel like they're solving the wrong part of the problem. I really don't have much concern that an agent has access to one of my credentials. Outside of production, most of these credentials are going to be limited in privilege and self-rotatable.

What remains terrifying is the ability to exfil important data or run commands that are malicious.

5mo agoHN ↗

exfiltrating a credential provides persistent access (until detected and rotated) tho! probably one of the more leveraged things to prevent