Live data from Hacker News

Bitwarden releases “emergency access” feature

bitwarden.com

11–20 of 154 posts

Re: Bitwarden releases “emergency access” feature

#11
post #6

Am I reading it right that this allows people to designate access to their password manager via email ? I feel like I have to missing something, like a previous step that fingerprints the emergency contact's key or something. (I get that we rely on email for stuff like this all the time, but your password manager is part of what protects your email account, which is why we rely on email as much as we do for resets).

While I make heavy use of a password manager, I still choose to memorize my email password, and not store it in a password manager, precisely because it is is relied on so much, and can be used to reset the majority of the passwords stored in the manager anyway.

Re: Bitwarden releases “emergency access” feature

#12
post #5

> On confirmation, the grantor’s Master Key is encrypted using the grantee’s public key and stored once encrypted. Grantee is notified of confirmation. > When the request is approved or the wait time lapses, the public-key-encrypted Master Key is delivered to grantee for decryption with grantee’s private key. I'm not quite sure how I feel about the way they're doing this. Whilst this is a feature a lot of people desi…

I'm under the impression that the "encrypt master key with the receiver's public key" step is done on-client, so you could verify that the master key isn't being stored the same way you can very they're not sending the master key when logging into the web ui: looking at devtools and seeing everything that leaves the network.

> I'm under the impression that the "encrypt master key with the receiver's public key" step is done on-client

However, what would prevent them sending two public keys, one for your contact, and one for someone else? Or sending the wrong public key?

How is the key exchange itself verified other than "Bitwarden user"?

Those questions aren't answered.

Re: Bitwarden releases “emergency access” feature

#13

Nice! I was already satisfied using Bitwarden, and now I will no longer have to manually manage my ICE backup. In the past I've kept an offline copy of my 'vault' on a few USB keys in a safe deposit, for my family in case of death or similar. I'm curious how others have solved this problem.

I have a similar and opposite problem. I would be fine with all my secrets dying with me, but what i want to protect against is me going into a coma/for some reason I forget how to access my accounts. How to securely manage it so that only I can open it if my biological self is there? I don't trust bank safe deposit boxes and I can't put a safe worth using inside my Apt. https://www.nytimes.com/2019/07/19/business/sa…

I think you are going to have to rely on another human being (or perhaps a group of trusted individuals) even in that case. Depending upon what caused your incapacitation, you may or may not be able to actually retain and manage your secrets going forward. Put another way, if your wetware is damaged you may need a backup (aka trusted human) to handle your secrets on your behalf.

Re: Bitwarden releases “emergency access” feature

#14
post #6

Am I reading it right that this allows people to designate access to their password manager via email ? I feel like I have to missing something, like a previous step that fingerprints the emergency contact's key or something. (I get that we rely on email for stuff like this all the time, but your password manager is part of what protects your email account, which is why we rely on email as much as we do for resets).

They encourage you to verify the grantee’s fingerprint phrase:

> To ensure the integrity of your encryption keys, verify the displayed fingerprint phrase with the grantee before completing confirmation.

https://bitwarden.com/help/article/emergency-access/#confirm...

> The fingerprint phrase is an important security feature that assists in uniquely and securely identifying a Bitwarden user account when important encryption-related operations are performed (such as sharing).

https://bitwarden.com/help/article/fingerprint-phrase/

Re: Bitwarden releases “emergency access” feature

#15
post #5

> On confirmation, the grantor’s Master Key is encrypted using the grantee’s public key and stored once encrypted. Grantee is notified of confirmation. > When the request is approved or the wait time lapses, the public-key-encrypted Master Key is delivered to grantee for decryption with grantee’s private key. I'm not quite sure how I feel about the way they're doing this. Whilst this is a feature a lot of people desi…

I'm under the impression that the "encrypt master key with the receiver's public key" step is done on-client, so you could verify that the master key isn't being stored the same way you can very they're not sending the master key when logging into the web ui: looking at devtools and seeing everything that leaves the network.

It's a little too much to sort through on mobile, but I believe this is a reasonable place to start looking (this is the web app, the server might be worth a look too). As far as I can figure out, it's not part of the cli client.

https://github.com/bitwarden/web/commit/3c5a972bc9e959c5ced9...

Reminder: bitwarden isn't just an awesome service, it's also committed to open source!

Re: Bitwarden releases “emergency access” feature

#16
The pandemic has made me (re)evaluate how my family can get to my finances and online services. Such solutions can solve issues related to bank/trading account access and key documents but what about subscription services? All my subscription services from Netflix/Plex (less important) to VPN/Blackblaze (more important) are tied to my credit cards, which upon my untimely demise will be deactivated. My family will surely get locked out if I don't leave clear instructions on each of the services and how they can access them, etc. Then there is a technical aspect of taking over these service.

I'm curious on how others have planned around this?

edit: typo

Re: Bitwarden releases “emergency access” feature

#17
post #16

The pandemic has made me (re)evaluate how my family can get to my finances and online services. Such solutions can solve issues related to bank/trading account access and key documents but what about subscription services? All my subscription services from Netflix/Plex (less important) to VPN/Blackblaze (more important) are tied to my credit cards, which upon my untimely demise will be deactivated. My family will sur…

After my wife watched the show “Dead To Me” on Netflix, we had this exact same discussion. I ended up writing a “death document” on Google Docs and sharing it with her. It just outlines “here’s where everything is and this is what you do with it”. It was done kind of jokingly, but now that it’s written it actually makes me feel much better.

For passwords and such, she has a Bitwarden account too and we share all important passwords (finances, medical, etc) in a shared organization between the two of us.

Re: Bitwarden releases “emergency access” feature

#19

Bitwarden is just fantastic. It's open source, the interface is clean, works fine on all platforms for me and pretty much everything is free. If the devs browse here, thanks for making it.

Just want to echo this. I've been using Bitwarden for about a year now, and a few months ago, my mum (not technologically literate) had her email hacked. Getting her set up with Bitwarden & teaching her how to use it was one of the easiest experiences I've had when introducing her to new software. Really well designed.

Re: Bitwarden releases “emergency access” feature

#20
post #13

Earlier quoted context omitted.

I have a similar and opposite problem. I would be fine with all my secrets dying with me, but what i want to protect against is me going into a coma/for some reason I forget how to access my accounts. How to securely manage it so that only I can open it if my biological self is there? I don't trust bank safe deposit boxes and I can't put a safe worth using inside my Apt. https://www.nytimes.com/2019/07/19/business/sa…

I think you are going to have to rely on another human being (or perhaps a group of trusted individuals) even in that case. Depending upon what caused your incapacitation, you may or may not be able to actually retain and manage your secrets going forward. Put another way, if your wetware is damaged you may need a backup (aka trusted human) to handle your secrets on your behalf.

Shamir's secret sharing is the algorithm for splitting a key and requiring only a subset of pieces (so you can disperse it to 20 friends but only need 11 to agree to reform the key).

This would give you protection both against the amnesia route (where you fall unconscious, lose your memory but are totally fine afterwards) and the route where you're unable to manage your secrets at all (eg stroke resulting in longterm failure to maintain memories or make decisions).

You'd still, for the total lose route, need a replacement actor (someone acting on your behalf) to assemble and receive the key, and be the keyholder moving forward - and you would likely need to leave instructions with the flock of people having pieces of the key on how to select or confirm your future keyholder.

Post reply on HN