Live data from Hacker News

Bitwarden releases “emergency access” feature

bitwarden.com

101–110 of 154 posts

Re: Bitwarden releases “emergency access” feature

#101

Earlier quoted context omitted.

That's fine if you're single but incredibly selfish if you're not.

I think an accusation like that warrants some elaboration. Please describe why you think this is selfish.

It makes the whole thing the problem of whoever survives. By not leaving documentation, you pass the work of picking up the pieces to someone else. I think "selfish" might be a little strong, but it's not an indefensible position to take.

Re: Bitwarden releases “emergency access” feature

#102

Earlier quoted context omitted.

What's a good, safe place to store the key?

Either on your keyring or in your fire safe. As I mentioned, if you lose it, you can get the lock drilled at the bank with sufficient ID. All trust waterfalls to meatspace trust providers, just like if you lose your Yubikey AWS support will reset your hardware 2FA with sufficient evidence you are you.

Just a note about safes... our community had a wildfire sweep through, and I have not heard of any fireproof safes actually working. Some were cracked open, or were so compromised they could be snapped apart by hand; some survived, but there were only ashes and melted metal at the bottom. I'm sure I didn't hear about the successes, only the failures, but still...

I don't want people to proceed with the notion that those safes are actually fire-proof. Consider them 'fire-resistant' safes that conditionally offer some extra protection.

Re: Bitwarden releases “emergency access” feature

#103

Earlier quoted context omitted.

I don't buy the "don't use 2FA" argument. My partner knows how to unlock my phone. She can read the eventual SMS (I know, it's insecure, but still the only 2FA method in many US bansk), she will receive the email with the eventual password reset on the phone, she can use my authenticator apps. She also knows about my Yubikeys and where they are stored. She also has access to my laptop, where backups for the above are…

And what the manual unlock codes?

What manual unlock codes? You mean the TOTP backup? It's documented. But she won't need if she has the rest.

Re: Bitwarden releases “emergency access” feature

#104

Earlier quoted context omitted.

Keep a copy in there if you want for convenience, I argue you’ll still want a paper backup somewhere. Opsec is hard, people are fallible. “What was the password?”, “Where’s the Yubikey?”, etc. These are not the failure scenarios you want to encounter during a tragedy (speaking from experience).

I think giving a USB key or login details with access info to your password manager to a trusted friend or family member might be preferable to having a paper binder that could be lost in a disaster situation.

You'd have to account for bit rot though

Re: Bitwarden releases “emergency access” feature

#106
post #12

Earlier quoted context omitted.

I'm under the impression that the "encrypt master key with the receiver's public key" step is done on-client, so you could verify that the master key isn't being stored the same way you can very they're not sending the master key when logging into the web ui: looking at devtools and seeing everything that leaves the network.

> I'm under the impression that the "encrypt master key with the receiver's public key" step is done on-client However, what would prevent them sending two public keys, one for your contact, and one for someone else? Or sending the wrong public key? How is the key exchange itself verified other than "Bitwarden user"? Those questions aren't answered.

They are answered right in the help article: https://bitwarden.com/help/article/emergency-access/#confirm...

"To ensure the integrity of your encryption keys, verify the displayed fingerprint phrase with the grantee before completing confirmation."

Re: Bitwarden releases “emergency access” feature

#107

I use Lastpass, but I'm no longer a fan. So I am considering Bitwarden, but was wondering: What does this afford me that the built in Firefox password manager does not? Firefox now provides a method to generate passwords. Is there something else I am missing?

The built-in Firefox password manager does not work with other browsers (kind of obvious, no?). I use different browsers on different devices, and Bitwarden just works on all of them.

Re: Bitwarden releases “emergency access” feature

#108
post #16

The pandemic has made me (re)evaluate how my family can get to my finances and online services. Such solutions can solve issues related to bank/trading account access and key documents but what about subscription services? All my subscription services from Netflix/Plex (less important) to VPN/Blackblaze (more important) are tied to my credit cards, which upon my untimely demise will be deactivated. My family will sur…

Everything should be documented. We have a binder with checklists that walk you through gaining access to everything the other partner might need in the event of death (email accounts, domain registrar, bank and brokerage accounts, auto/home/life insurance, ongoing recurring bills of all sorts). Bitwarden databases are exported to paper, 3 hole punched, and put in the binder on a schedule. Both partners get setup wit…

Interesting. Did anyone make a similar checklist for passwords and what not? I have something in a binder which is meant to be used in case of emergency, but it's a bit out of date and I wanted to revamp it.

Re: Bitwarden releases “emergency access” feature

#109

Earlier quoted context omitted.

Everything should be documented. We have a binder with checklists that walk you through gaining access to everything the other partner might need in the event of death (email accounts, domain registrar, bank and brokerage accounts, auto/home/life insurance, ongoing recurring bills of all sorts). Bitwarden databases are exported to paper, 3 hole punched, and put in the binder on a schedule. Both partners get setup wit…

This is a good approach, but it requires having a partner in the first place...

Couldn't you have that binder laying around in your home anyways? I imagine my family would be able to gain access to my home if I die (even though not one of them has a key).

Re: Bitwarden releases “emergency access” feature

#110
post #12

Earlier quoted context omitted.

> I'm under the impression that the "encrypt master key with the receiver's public key" step is done on-client However, what would prevent them sending two public keys, one for your contact, and one for someone else? Or sending the wrong public key? How is the key exchange itself verified other than "Bitwarden user"? Those questions aren't answered.

They are answered right in the help article: https://bitwarden.com/help/article/emergency-access/#confirm... "To ensure the integrity of your encryption keys, verify the displayed fingerprint phrase with the grantee before completing confirmation."

So keys aren't verified at all. That seems like something that needs more than a single sentence that comes _after_ they explain the confirmation process.
Post reply on HN