Am I reading it right that this allows people to designate access to their password manager via email ? I feel like I have to missing something, like a previous step that fingerprints the emergency contact's key or something. (I get that we rely on email for stuff like this all the time, but your password manager is part of what protects your email account, which is why we rely on email as much as we do for resets).
Bitwarden releases “emergency access” feature
11–20 of 154 posts
Re: Bitwarden releases “emergency access” feature
#12> On confirmation, the grantor’s Master Key is encrypted using the grantee’s public key and stored once encrypted. Grantee is notified of confirmation. > When the request is approved or the wait time lapses, the public-key-encrypted Master Key is delivered to grantee for decryption with grantee’s private key. I'm not quite sure how I feel about the way they're doing this. Whilst this is a feature a lot of people desi…
I'm under the impression that the "encrypt master key with the receiver's public key" step is done on-client, so you could verify that the master key isn't being stored the same way you can very they're not sending the master key when logging into the web ui: looking at devtools and seeing everything that leaves the network.
However, what would prevent them sending two public keys, one for your contact, and one for someone else? Or sending the wrong public key?
How is the key exchange itself verified other than "Bitwarden user"?
Those questions aren't answered.
Re: Bitwarden releases “emergency access” feature
#13Nice! I was already satisfied using Bitwarden, and now I will no longer have to manually manage my ICE backup. In the past I've kept an offline copy of my 'vault' on a few USB keys in a safe deposit, for my family in case of death or similar. I'm curious how others have solved this problem.
I have a similar and opposite problem. I would be fine with all my secrets dying with me, but what i want to protect against is me going into a coma/for some reason I forget how to access my accounts. How to securely manage it so that only I can open it if my biological self is there? I don't trust bank safe deposit boxes and I can't put a safe worth using inside my Apt. https://www.nytimes.com/2019/07/19/business/sa…
Re: Bitwarden releases “emergency access” feature
#14Am I reading it right that this allows people to designate access to their password manager via email ? I feel like I have to missing something, like a previous step that fingerprints the emergency contact's key or something. (I get that we rely on email for stuff like this all the time, but your password manager is part of what protects your email account, which is why we rely on email as much as we do for resets).
> To ensure the integrity of your encryption keys, verify the displayed fingerprint phrase with the grantee before completing confirmation.
https://bitwarden.com/help/article/emergency-access/#confirm...
> The fingerprint phrase is an important security feature that assists in uniquely and securely identifying a Bitwarden user account when important encryption-related operations are performed (such as sharing).
Re: Bitwarden releases “emergency access” feature
#15> On confirmation, the grantor’s Master Key is encrypted using the grantee’s public key and stored once encrypted. Grantee is notified of confirmation. > When the request is approved or the wait time lapses, the public-key-encrypted Master Key is delivered to grantee for decryption with grantee’s private key. I'm not quite sure how I feel about the way they're doing this. Whilst this is a feature a lot of people desi…
I'm under the impression that the "encrypt master key with the receiver's public key" step is done on-client, so you could verify that the master key isn't being stored the same way you can very they're not sending the master key when logging into the web ui: looking at devtools and seeing everything that leaves the network.
https://github.com/bitwarden/web/commit/3c5a972bc9e959c5ced9...
Reminder: bitwarden isn't just an awesome service, it's also committed to open source!
Re: Bitwarden releases “emergency access” feature
#16I'm curious on how others have planned around this?
edit: typo
Re: Bitwarden releases “emergency access” feature
#17The pandemic has made me (re)evaluate how my family can get to my finances and online services. Such solutions can solve issues related to bank/trading account access and key documents but what about subscription services? All my subscription services from Netflix/Plex (less important) to VPN/Blackblaze (more important) are tied to my credit cards, which upon my untimely demise will be deactivated. My family will sur…
For passwords and such, she has a Bitwarden account too and we share all important passwords (finances, medical, etc) in a shared organization between the two of us.
Re: Bitwarden releases “emergency access” feature
#18Re: Bitwarden releases “emergency access” feature
#19Bitwarden is just fantastic. It's open source, the interface is clean, works fine on all platforms for me and pretty much everything is free. If the devs browse here, thanks for making it.
Re: Bitwarden releases “emergency access” feature
#20Earlier quoted context omitted.
I have a similar and opposite problem. I would be fine with all my secrets dying with me, but what i want to protect against is me going into a coma/for some reason I forget how to access my accounts. How to securely manage it so that only I can open it if my biological self is there? I don't trust bank safe deposit boxes and I can't put a safe worth using inside my Apt. https://www.nytimes.com/2019/07/19/business/sa…
I think you are going to have to rely on another human being (or perhaps a group of trusted individuals) even in that case. Depending upon what caused your incapacitation, you may or may not be able to actually retain and manage your secrets going forward. Put another way, if your wetware is damaged you may need a backup (aka trusted human) to handle your secrets on your behalf.
This would give you protection both against the amnesia route (where you fall unconscious, lose your memory but are totally fine afterwards) and the route where you're unable to manage your secrets at all (eg stroke resulting in longterm failure to maintain memories or make decisions).
You'd still, for the total lose route, need a replacement actor (someone acting on your behalf) to assemble and receive the key, and be the keyholder moving forward - and you would likely need to leave instructions with the flock of people having pieces of the key on how to select or confirm your future keyholder.