Live data from Hacker News

Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

bitwarden.com

91–100 of 138 posts

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#91

Earlier quoted context omitted.

MFA is not going away, but neither is it going to become what you are describing. MFA using an SMS is not secure. If people reliably made good passwords and never reused them, we probably wouldn't need MFA as much. Unfortunately, we live in a society. Bitwarden will remember your TOTP codes for you across any device you login from. It will even copy the code to you paste buffer during a login. I enable MFA everywhere…

> MFA using an SMS is not secure. Why not? Is it that easy to intercept a SMS or is that just due to poor handling with some providers?

Yes it is.

https://blog.mozilla.org/en/internet-culture/mozilla-explain...

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#92

Earlier quoted context omitted.

MFA is not going away, but neither is it going to become what you are describing. MFA using an SMS is not secure. If people reliably made good passwords and never reused them, we probably wouldn't need MFA as much. Unfortunately, we live in a society. Bitwarden will remember your TOTP codes for you across any device you login from. It will even copy the code to you paste buffer during a login. I enable MFA everywhere…

> MFA using an SMS is not secure. Why not? Is it that easy to intercept a SMS or is that just due to poor handling with some providers?

No the parent, but I’m assuming they’re referring to the East of SIM spoofing to convince providers you’re another phone number that’s not your own.

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#93
post #47
post #44

Passwordless is going to be great. Though, this is just for unlocking your bitwarden account. Real cross-device passwordless is likely coming in the next year or so. WebAuthn/Passkey is in its 3rd public working draft[1] and once finalized, we'll likely start to see it across sites. Most devices, browsers and managers have added or are adding support for it: Apple, Microsoft, Google, Auth0, Duo, 1Password, etc. If yo…

Passkeys are definitely the future, and I think will eventually eliminate a lot of phishing attempts and other insecurity caused by passwords. I'm hoping that we will eventually see transferable, secure identities that you can use to log in anywhere, rather than having to constantly create account credentials for everything. As a side note, if you want to try out passkeys now and don't want to tie it to your device,…

Apparently it is possible to make WebAuthn phishable:

https://mjg59.dreamwidth.org/62175.html https://news.ycombinator.com/item?id=33810984

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#94
post #85

Am I the only one who just cannot STAND MFA? Having to get a notification text etc. Like what if I don’t want to give an app capability to notify my phone? What if I want something totally NOT connected to my phone? I just envision a future where there is some near-circular dependency of passwords/phrases/notifications/authenticators/keys/email verifications etc across different devices and services - the end result…

MFA is not going away, but neither is it going to become what you are describing. MFA using an SMS is not secure. If people reliably made good passwords and never reused them, we probably wouldn't need MFA as much. Unfortunately, we live in a society. Bitwarden will remember your TOTP codes for you across any device you login from. It will even copy the code to you paste buffer during a login. I enable MFA everywhere…

and if developers would always mitigate brute force attacks/limit the amount of attempts you can do.not limit the amount of accounts you can try to access from a single source

and it’s all developers will give you the tools to check every login session, including ip addresses used, and number of failed attempts

and off everybody uses full disk encryption and other measures so that your passwords cannot be stolen, such as only use signed applications and proper sandboxes

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#95

I just looked at the requirements to host your own Bitwarden server. Why does a password manager need 2GB of ram (4GB recommended) and 25GB[1] of storage? That seems quite excessive, how much data and traffic does this thing need to handle for me plus family members? [1] https://bitwarden.com/help/install-on-premise-linux/

Honest question: do you believe that you’ll be able to guarantee the same/better uptime, performance, and security compared to the SaaS version? Hosting your own password manager seems like something you really shouldn’t do, just like hosting your own e-mail. This stuff is critical to your life.

"Bitwarden has the right to suspend or terminate your access to all or any part of the Website at any time, with or without cause, with or without notice, effective immediately. Bitwarden reserves the right to refuse service to anyone for any reason at any time."

Who would trust their passwords to a service with such a clause?

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#96
post #70

Hardware keys are better. Phone’s operating system is a huge code base. Also, iPhone’s operating system is a closed source proprietary black box.

How do you link your hardware key to the website? You still have to plug it into a proprietary black box. If you think your computer security is weak, it will continue to be the weak link even with with a hardware key.

If the computer is compromised or backdoored, it will have access to private keys for websites that I access on that computer, one per each touch, not the database of all private keys. For example, I may not connect my Yubikey to some computers at all.

Hardware keys are made not to give out secret keys without physical touch.

Firmware in Yubikey is not updated, unlike over the air phone update.

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#97
How long before you need 3 devices to log into something?

Like the other commenter I don't want or need MFA. It's more complicated and a pain to use. Just seems like a convenient opportunity for online companies to gather more data points about you. Keepassxc with a key file is still going strong for me. You've no need for my phone number! And I don't want my device linked to any account.

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#98

I just looked at the requirements to host your own Bitwarden server. Why does a password manager need 2GB of ram (4GB recommended) and 25GB[1] of storage? That seems quite excessive, how much data and traffic does this thing need to handle for me plus family members? [1] https://bitwarden.com/help/install-on-premise-linux/

I'm hosting Bitwarden on RPI4B, but using bitwarden-rs lightweight server. Along with nextcloud, home assistant and photo gallery.

Well, yes, after adding photo gallery, I now want a faster device.

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#99

How long before you need 3 devices to log into something? Like the other commenter I don't want or need MFA. It's more complicated and a pain to use. Just seems like a convenient opportunity for online companies to gather more data points about you. Keepassxc with a key file is still going strong for me. You've no need for my phone number! And I don't want my device linked to any account.

It is off by default.
Post reply on HN