Live data from Hacker News

Bitwarden adds support for passkeys

bitwarden.com

101–110 of 172 posts

Re: Bitwarden adds support for passkeys

#101
post #94

I'm missing something. Webauthn puts a private key into a firewalled section of hardware onto your device - which is extremely prickly to work with in my experience - for your security. For passkeys to be transferable the private key cannot be locked to your device. Is bitwarden somehow able to "spoof" this hardware and have your browser generate private keys in it instead?

> Webauthn puts a private key into a firewalled section of hardware This is not true. In general, Webauthn doesn’t care where and how the keys are stored. There is attestation feature, but AFAIK e.g. Apple intentionally doesn’t implement it for unmanaged devices.

I've experienced this on my phone IIRC...if I register a webauthn key on chrome on iphone, it shows up on safari; but the reverse is not true.

Im assuming this is because apple uses a software based TPM that isn't tied to the device. This lets those private keys sync between devices.

Is the future state for bitwarden to be able to perform the same trick somehow? Have you create keys in it and not your devices tpm?

Re: Bitwarden adds support for passkeys

#102
post #91

Earlier quoted context omitted.

I see this common refrain from people. How is writing something down so that you don't have to remember it a "thing you know"? You literally don't know it. A "thing you know" never leaves your brain, otherwise it becomes a "thing you have".

It comes from the fact there are three fundamental ways to authenticate: a thing you know, a thing you have, a thing you are. You may not "know" a passkey or a TOTP token, but you are using computers in their most fundamental role as bicycles for the mind to "know" them for you. This means they still fit into "thing you know". Clearly a TOTP token is not a thing you are. Less clearly, it is not a thing you have. Pass…

Yep. Thing you have is a passkey that can't be copied at all, like a yuibikey, some physical manifestation that can't be easily cloned. Arguably TOTP is "have" due to being linked to a phone when doing push to a single device.

Re: Bitwarden adds support for passkeys

#103
post #90

One of the nicest thing about bitwarden is the ability to selfhost it. I don't think there is anything like it. 1password seems to have the best UX in the field. But you always have to trust some company with the keys to your digital life. Self hosting password managers is not as big of a deal as it should be.

I've been incredibly happy with https://www.passwordstore.org/ for years. The data store is a file hierarchy, with the files themselves encrypted with GPG. Sync is via git. TOTP support with a plugin.

The one major feature `pass` lacks is sharing. I used it for years, but moving to (self-hosted) bitwarden has made life a lot easier in that respect.

Re: Bitwarden adds support for passkeys

#104
post #49

Earlier quoted context omitted.

In theory the Bitwarden server (and Vaultwarden) shouldn't have any access to the passwords, so a data breach of the server should never disclose any contents of the vault. Vaultwarden "feels" safe to me, but I would also be interested if there is some possibility it could introduce some degraded security compared to the official Bitwarden server. My Vaultwarden instance is "hidden" on a subdomain that probably nobod…

How do you hide subdomain ?

You don’t, and they’re not really hiding anything from anybody who has any knowledge in the security space.

Re: Bitwarden adds support for passkeys

#105
post #91

Earlier quoted context omitted.

It comes from the fact there are three fundamental ways to authenticate: a thing you know, a thing you have, a thing you are. You may not "know" a passkey or a TOTP token, but you are using computers in their most fundamental role as bicycles for the mind to "know" them for you. This means they still fit into "thing you know". Clearly a TOTP token is not a thing you are. Less clearly, it is not a thing you have. Pass…

Yep. Thing you have is a passkey that can't be copied at all, like a yuibikey, some physical manifestation that can't be easily cloned. Arguably TOTP is "have" due to being linked to a phone when doing push to a single device.

Nit: TOTP doesn't include push methods of 2FA, it specifically refers to the algorithm for producing one-time passcodes from the current time and a secret key.

Re: Bitwarden adds support for passkeys

#106
post #51

Earlier quoted context omitted.

I hope they get over that. It's a blob of data. It's no more special than a TOTP secret or a conventional password, and I am completely uninterested in pretending otherwise because of a slick marketing campaign. It's a "thing I know" whether anybody likes it or not and you can't turn it into a "thing I have" just because you won't let me export it from this particular software. (Proof that it is a "thing I know": It…

I see this common refrain from people. How is writing something down so that you don't have to remember it a "thing you know"? You literally don't know it. A "thing you know" never leaves your brain, otherwise it becomes a "thing you have".

Any half decent sophisticated user on the internet has not remembered passwords for half a decade at least.

Nearly everyone is storing it in password managers.

So has that changed passwords into not being “thing you know”?

Re: Bitwarden adds support for passkeys

#107

Earlier quoted context omitted.

I see this common refrain from people. How is writing something down so that you don't have to remember it a "thing you know"? You literally don't know it. A "thing you know" never leaves your brain, otherwise it becomes a "thing you have".

Any half decent sophisticated user on the internet has not remembered passwords for half a decade at least. Nearly everyone is storing it in password managers. So has that changed passwords into not being “thing you know”?

  So has that changed passwords into not being “thing you know”? 
Yes? If you write your password down on a piece of paper it becomes something you have, no?

Re: Bitwarden adds support for passkeys

#108
post #98

Earlier quoted context omitted.

Silly question perhaps, but what happens if a certain website changes to a different domain. E.g. a takeover of Company B by Company A who then decides to migrate all Company B passkeys to Company A and removes assets hosted under the Company B domain. This is easily sorted with existing tools but with passkeys... how?

If they had time to prepare I'm sure they could develop a flow to get you a passkey on the new domain first. Similar to how YouTube used to do a bunch of cross-domain redirects (to plant cookies) to get Google+ login support back in the day.

You might not get a head up when you're forced to change your domain though. For example, recently a huge number of .ml domains are dead and people that used them must scramble to migrate to another domain. The problem is some apps like mastodon (and now passkey) don't support changing domains unless the old domain is still accessible.

Re: Bitwarden adds support for passkeys

#109

Earlier quoted context omitted.

+1. Lastpass was the love child until they got sold and sold out. I switched over to bitwarden but after being burned, keeping it basic with no lock in for now.

In which way did you get burned while using Bitwarden?

I think they meant they were burned by Lastpass and are now less trustful of password manager services.

Re: Bitwarden adds support for passkeys

#110
post #23

Earlier quoted context omitted.

What would be the purpose of having multiple passkeys for the same account stored in the same BitWarden vault? You're going to have a backup key and store it in the exact same place as the primary key?

The idea of passkeys is that they can be synced so you don't lose them when you lose a device. So there's a lot less need to have two

Multiple passkeys backed by different sources (password manager, iCloud, Yubikey, etc.) can serve as a backup in the case you lost access to your password manager, for example.

If a service provides the option for more than one passkey, I always configure several.

Post reply on HN