Earlier quoted context omitted.
MFA is not going away, but neither is it going to become what you are describing. MFA using an SMS is not secure. If people reliably made good passwords and never reused them, we probably wouldn't need MFA as much. Unfortunately, we live in a society. Bitwarden will remember your TOTP codes for you across any device you login from. It will even copy the code to you paste buffer during a login. I enable MFA everywhere…
> MFA using an SMS is not secure. Why not? Is it that easy to intercept a SMS or is that just due to poor handling with some providers?
Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password
91–100 of 138 posts
Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password
#92Earlier quoted context omitted.
MFA is not going away, but neither is it going to become what you are describing. MFA using an SMS is not secure. If people reliably made good passwords and never reused them, we probably wouldn't need MFA as much. Unfortunately, we live in a society. Bitwarden will remember your TOTP codes for you across any device you login from. It will even copy the code to you paste buffer during a login. I enable MFA everywhere…
> MFA using an SMS is not secure. Why not? Is it that easy to intercept a SMS or is that just due to poor handling with some providers?
Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password
#93Passwordless is going to be great. Though, this is just for unlocking your bitwarden account. Real cross-device passwordless is likely coming in the next year or so. WebAuthn/Passkey is in its 3rd public working draft[1] and once finalized, we'll likely start to see it across sites. Most devices, browsers and managers have added or are adding support for it: Apple, Microsoft, Google, Auth0, Duo, 1Password, etc. If yo…
Passkeys are definitely the future, and I think will eventually eliminate a lot of phishing attempts and other insecurity caused by passwords. I'm hoping that we will eventually see transferable, secure identities that you can use to log in anywhere, rather than having to constantly create account credentials for everything. As a side note, if you want to try out passkeys now and don't want to tie it to your device,…
https://mjg59.dreamwidth.org/62175.html https://news.ycombinator.com/item?id=33810984
Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password
#94Am I the only one who just cannot STAND MFA? Having to get a notification text etc. Like what if I don’t want to give an app capability to notify my phone? What if I want something totally NOT connected to my phone? I just envision a future where there is some near-circular dependency of passwords/phrases/notifications/authenticators/keys/email verifications etc across different devices and services - the end result…
MFA is not going away, but neither is it going to become what you are describing. MFA using an SMS is not secure. If people reliably made good passwords and never reused them, we probably wouldn't need MFA as much. Unfortunately, we live in a society. Bitwarden will remember your TOTP codes for you across any device you login from. It will even copy the code to you paste buffer during a login. I enable MFA everywhere…
and it’s all developers will give you the tools to check every login session, including ip addresses used, and number of failed attempts
and off everybody uses full disk encryption and other measures so that your passwords cannot be stolen, such as only use signed applications and proper sandboxes
Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password
#95I just looked at the requirements to host your own Bitwarden server. Why does a password manager need 2GB of ram (4GB recommended) and 25GB[1] of storage? That seems quite excessive, how much data and traffic does this thing need to handle for me plus family members? [1] https://bitwarden.com/help/install-on-premise-linux/
Honest question: do you believe that you’ll be able to guarantee the same/better uptime, performance, and security compared to the SaaS version? Hosting your own password manager seems like something you really shouldn’t do, just like hosting your own e-mail. This stuff is critical to your life.
Who would trust their passwords to a service with such a clause?
Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password
#96Hardware keys are better. Phone’s operating system is a huge code base. Also, iPhone’s operating system is a closed source proprietary black box.
How do you link your hardware key to the website? You still have to plug it into a proprietary black box. If you think your computer security is weak, it will continue to be the weak link even with with a hardware key.
Hardware keys are made not to give out secret keys without physical touch.
Firmware in Yubikey is not updated, unlike over the air phone update.
Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password
#97Like the other commenter I don't want or need MFA. It's more complicated and a pain to use. Just seems like a convenient opportunity for online companies to gather more data points about you. Keepassxc with a key file is still going strong for me. You've no need for my phone number! And I don't want my device linked to any account.
Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password
#98I just looked at the requirements to host your own Bitwarden server. Why does a password manager need 2GB of ram (4GB recommended) and 25GB[1] of storage? That seems quite excessive, how much data and traffic does this thing need to handle for me plus family members? [1] https://bitwarden.com/help/install-on-premise-linux/
Well, yes, after adding photo gallery, I now want a faster device.
Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password
#99How long before you need 3 devices to log into something? Like the other commenter I don't want or need MFA. It's more complicated and a pain to use. Just seems like a convenient opportunity for online companies to gather more data points about you. Keepassxc with a key file is still going strong for me. You've no need for my phone number! And I don't want my device linked to any account.