Earlier quoted context omitted.
That's fine if you're single but incredibly selfish if you're not.
I think an accusation like that warrants some elaboration. Please describe why you think this is selfish.
Bitwarden releases “emergency access” feature
101–110 of 154 posts
Re: Bitwarden releases “emergency access” feature
#102Earlier quoted context omitted.
What's a good, safe place to store the key?
Either on your keyring or in your fire safe. As I mentioned, if you lose it, you can get the lock drilled at the bank with sufficient ID. All trust waterfalls to meatspace trust providers, just like if you lose your Yubikey AWS support will reset your hardware 2FA with sufficient evidence you are you.
I don't want people to proceed with the notion that those safes are actually fire-proof. Consider them 'fire-resistant' safes that conditionally offer some extra protection.
Re: Bitwarden releases “emergency access” feature
#103Earlier quoted context omitted.
I don't buy the "don't use 2FA" argument. My partner knows how to unlock my phone. She can read the eventual SMS (I know, it's insecure, but still the only 2FA method in many US bansk), she will receive the email with the eventual password reset on the phone, she can use my authenticator apps. She also knows about my Yubikeys and where they are stored. She also has access to my laptop, where backups for the above are…
And what the manual unlock codes?
Re: Bitwarden releases “emergency access” feature
#104Earlier quoted context omitted.
Keep a copy in there if you want for convenience, I argue you’ll still want a paper backup somewhere. Opsec is hard, people are fallible. “What was the password?”, “Where’s the Yubikey?”, etc. These are not the failure scenarios you want to encounter during a tragedy (speaking from experience).
I think giving a USB key or login details with access info to your password manager to a trusted friend or family member might be preferable to having a paper binder that could be lost in a disaster situation.
Re: Bitwarden releases “emergency access” feature
#105https://francoisbest.com/posts/2020/password-reset-for-e2ee-...
Re: Bitwarden releases “emergency access” feature
#106Earlier quoted context omitted.
I'm under the impression that the "encrypt master key with the receiver's public key" step is done on-client, so you could verify that the master key isn't being stored the same way you can very they're not sending the master key when logging into the web ui: looking at devtools and seeing everything that leaves the network.
> I'm under the impression that the "encrypt master key with the receiver's public key" step is done on-client However, what would prevent them sending two public keys, one for your contact, and one for someone else? Or sending the wrong public key? How is the key exchange itself verified other than "Bitwarden user"? Those questions aren't answered.
"To ensure the integrity of your encryption keys, verify the displayed fingerprint phrase with the grantee before completing confirmation."
Re: Bitwarden releases “emergency access” feature
#107I use Lastpass, but I'm no longer a fan. So I am considering Bitwarden, but was wondering: What does this afford me that the built in Firefox password manager does not? Firefox now provides a method to generate passwords. Is there something else I am missing?
Re: Bitwarden releases “emergency access” feature
#108The pandemic has made me (re)evaluate how my family can get to my finances and online services. Such solutions can solve issues related to bank/trading account access and key documents but what about subscription services? All my subscription services from Netflix/Plex (less important) to VPN/Blackblaze (more important) are tied to my credit cards, which upon my untimely demise will be deactivated. My family will sur…
Everything should be documented. We have a binder with checklists that walk you through gaining access to everything the other partner might need in the event of death (email accounts, domain registrar, bank and brokerage accounts, auto/home/life insurance, ongoing recurring bills of all sorts). Bitwarden databases are exported to paper, 3 hole punched, and put in the binder on a schedule. Both partners get setup wit…
Re: Bitwarden releases “emergency access” feature
#109Earlier quoted context omitted.
Everything should be documented. We have a binder with checklists that walk you through gaining access to everything the other partner might need in the event of death (email accounts, domain registrar, bank and brokerage accounts, auto/home/life insurance, ongoing recurring bills of all sorts). Bitwarden databases are exported to paper, 3 hole punched, and put in the binder on a schedule. Both partners get setup wit…
This is a good approach, but it requires having a partner in the first place...
Re: Bitwarden releases “emergency access” feature
#110Earlier quoted context omitted.
> I'm under the impression that the "encrypt master key with the receiver's public key" step is done on-client However, what would prevent them sending two public keys, one for your contact, and one for someone else? Or sending the wrong public key? How is the key exchange itself verified other than "Bitwarden user"? Those questions aren't answered.
They are answered right in the help article: https://bitwarden.com/help/article/emergency-access/#confirm... "To ensure the integrity of your encryption keys, verify the displayed fingerprint phrase with the grantee before completing confirmation."