Live data from Hacker News

Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

bitwarden.com

131–138 of 138 posts

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#131
post #49
post #42

Earlier quoted context omitted.

How do you mean that?

A compromised Apple developer account login pushing out a compromised Bitwarden mobile app to the Apple App Store that steals everyone's master passphrases.

If the Bitwarden developer account is compromised, one can indeed send an app that steals the passwords. But the devs would (most likely) see that someone else is pushing updates, and that would be the end of Bitwarden, so you can consider it is their job to not let that happen :-).

This is not specific to Bitwarden though, it's the same for all apps. Now because Bitwarden is open source, you can actually compile and install it yourself (if you're confident that the sources you are compiling are the legitimate ones, and not a fork that will steal your passwords ;-)).

Same applies for e.g. Signal Messenger: since it's difficult to check what version of the code is coming from your store, you can always compile it from source and install it yourself.

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#132

Earlier quoted context omitted.

No, it's because it uses _several_ docker containers and runs mssql.

"No" then go on to reinforce my explanation. Those minimums are taken from Docker. The person above asked why they were what they were, I answered. You're just further reinforcing what I explained.

Vaultwarden also uses docker and is a single container with minimal resources.

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#133
post #30

That's very nice, well done! For a moment there I had hoped that maybe it would solve the problem in the opposite direction: I'm typing the master password so mechanically when I'm on my laptop, that I really struggle to remember it when I have to type it on a screen - to the point that I must go sit at a computer open a notepad, let muscle memory take over and then look at the screen to see what I typed /facepalm An…

I just have the master password saved in my browser. I realise this is probably sub-optimal for a lot of people but for my workflow (i.e. the kinds of passwords I put in BitWarden) it works out OK.

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#134
post #109
post #73

This is a really great user experience. One thing I wonder about is if people start logging in without their password all the time, will they slowly forget what their password is over time? Partly to force memory reinforcement, I set the password cache time of gpg-agent on my machine to 24 hours maximum. Thus I have to enter my password once a day, which helps me to remember it; but it isn't overly burdensome. Althou…

My master password is "public" (I put it in a mail draft, also a note on my phone and printed it out on a piece of paper, just to be sure), and I have 2FA enabled via Yubikey. I never really understood why I had to always provide my master password anyway when logging in even on a trusted device, as the whole point of a password vault is to no longer have to remember any passwords... but we are getting there, eventua…

You bring up good points: ideally, there would be no need to remember a passphrase at all! Especially since the passphrase has to be long and unwieldy in order to be resistant to offline dictionary attack.

The thing I worry about is that the security of the passphrase is only as secure as the mechanism guarding it. If it's written on a piece of paper, then how is the paper secured? It could be put in a vault, but then the vault itself is a conspicuous target for thieves. Hiding the paper somewhere is probably pretty reasonable, but if it's too well hidden, it could get forgotten or accidentally thrown out over time.

I use a YubiKey as well as an ultimate backup, and it has a PIN code mechanism that will lock after a few incorrect attempts, so that is a reasonable tradeoff for security and usability I feel.

I wonder if the best solution is to have a distributed copy of a recovery passphrase to friends and family. Then separately have a distributed copy of the vault itself (in my case, it's GPG-protected Password Store). This must have been an area of study already, I need to do some research!

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#135
post #85

Am I the only one who just cannot STAND MFA? Having to get a notification text etc. Like what if I don’t want to give an app capability to notify my phone? What if I want something totally NOT connected to my phone? I just envision a future where there is some near-circular dependency of passwords/phrases/notifications/authenticators/keys/email verifications etc across different devices and services - the end result…

Passwords, credit card numbers, social security numbers, etc are old outdated technology that can't go away fast enough. They're unfixably insecure...identifying yourself to someone by giving your secret identifying information to them immediately allows them to impersonate you! We've had the technology to fix this problem for close to 50 years now: public-key cryptography. We can't get to a password-less world fast…

What you are talking about? I reset user's forgotten passwords daily. People can't remember simplest of passwords and you can easily ask them to give you their passwords if you are persuasive enough. Human brain is weakest link not passwords, credit card numbers or social security numbers. They are just fine and will be for a long time.

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#136

Earlier quoted context omitted.

Yes it is. https://blog.mozilla.org/en/internet-culture/mozilla-explain...

But this comes down to bad security practices at the telco, doesn't it? I don't know about other countries, but you can't even buy/activate SIM cards in Germany without "proper" identification through VideoIdent or another system where your passport is checked against. At least that's what I remember. I'm not sure any type of "I've lost my SIM, please use this one" would work on German carriers without proper ID. Mov…

Sort of yeah, it wouldn't be possible with my carrier for example as they would just tell you "login online and swap it" because things like switching sim etc. is just something you do there and not something you call them about. And to login to the website you must use the national 2factor authentication.

So essentially they would have to breach the national 2factor authentication system first here.

And there is absolutely no way that you could "social engineer" the guy on the other end of the phone who works for the telecompany as there is no way you shouldn't be able to use their online tools.

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#137
post #43
post #28

Earlier quoted context omitted.

Better security for sure. Bitwarden is a massive target while I am not. The chance that bitwarden has a databreach is way bigger than the chance that my server gets hacked. No one cares about my server, I am nobody not worth attacking. As long as I don't leave any big holes that can be found by an untargeted attack (which I won't, I run everything behind a personal VPN) it is safer.

> I am nobody not worth attacking. You’re probably not worth individually attacking, but a brief look at the failed ssh login logs of any insignificant server shows that you probably are worth automated attacks… so I suppose the question is “Are you more vulnerable due to a) the risk of getting pwnt by an automated attack (due to a misconfiguration or being even a little slow to install a critical patch) or b) due to…

I can contest to this, I am by no mean important and none of my servers that I own have any importance, BUT I have thousands of people trying to remote into the servers every day and also thousands of requests into some of my webservers with things like /admin /phpmyadmin or whatever, you name it.

So yeah even if you aren't a big target then you are still a target for automated attacks as they just pick whatever IPs they can find and try to breach.

Re: Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password

#138
post #63

Earlier quoted context omitted.

The Bitwarden webvault infrastructure is a doomsday target. If it's compromised, no evidence of a client backdoor will exist except in the server logs. You can't avoid using it, because you need to sign into the webvault to configure 2FA. Want to change the encryption passphrase? Guess what, you need to use the webvault. Bitwarden's vault encryption is essentially reduced to the security model of TLS.

And? If you don't trust TLS then I assume you don't trust web banking, or purchasing anything over the internet for that matter. Might as well give up on technology and go find yourself a nice quiet pastoral life.

For me personally, I don't actually trust any of that.

Any purchase I do online is done with a virtual card that links to a bank account that only ever has the amount I need to pay for whatever it is I am currently purchasing. That way it doesn't matter if the information is stolen etc. because there is no more money to use and I can cancel the card as easily as I can create a new.

For banking I also only use my banks official app, I don't know how exactly it works and I assume it does use some form of http and whatnot, but I wouldn't trust using a bank through the browser as you never know what kind of thing an extension or something have in there.

Post reply on HN