Live data from Hacker News

Bitwarden Acquires Passwordless.dev

bitwarden.com

111–120 of 399 posts

Re: Bitwarden Acquires Passwordless.dev

#111
Passwordless as a concept needs to die along with biometric auth.

You have really good newer methods of auth. Instead of selling them as good MFA alternatives security vendors decided to replace passwords because that differentiates them more. But in reality, the layer of defense "what you know" should be complemented not replaced. A reduction in security being sold as a feature is dishonest and harmful.

Re: Bitwarden Acquires Passwordless.dev

#113
post #97
post #87

Your passwords shouldn't leave your device. Chrome's password manager is pushing it. Everything else should be considered malware. I don't understand how such a 'techy' crowd here on HN can be so belligerent with this security vs convenience trade off. KeePass locally, gmail yourself an encrypted backup. That's it. FFS.

How is "gmail yourself an encrypted backup" fine but "store a copy of the encrypted vault in a cloud service designed for this purpose" not?

I'm surprised someone as techy as the parent even uses Google if I'm honest.

Re: Bitwarden Acquires Passwordless.dev

#114
post #97
post #87

Your passwords shouldn't leave your device. Chrome's password manager is pushing it. Everything else should be considered malware. I don't understand how such a 'techy' crowd here on HN can be so belligerent with this security vs convenience trade off. KeePass locally, gmail yourself an encrypted backup. That's it. FFS.

How is "gmail yourself an encrypted backup" fine but "store a copy of the encrypted vault in a cloud service designed for this purpose" not?

One is an encrypted blob in the cloud, the other is an encrypted file in your email in the cloud. That’s it. FFS.

Re: Bitwarden Acquires Passwordless.dev

#115
post #78

I still don't understand how it works. I went into the website under authenticated using my phones API, where is my account now? There is nothing in my Bitwarden vault.

Passkeys are stored on your platform keychain. In time, Bitwarden will offer this interface up, so you can sync them through your Bitwarden vault. Currently, if you use an iPhone, you will have the passkey stored in iCloud keychain. Your "account" is a private key held within iCloud keychain, along with some metadata mapping that private key to the site you visited.

Well I use GrapheneOS without a Google Account. Its not listed under secure keys in the settings or in the browser.

Anyway this really needs to be exportable, otherwise its in the ultimate platform lock.

Re: Bitwarden Acquires Passwordless.dev

#116
post #5

Slightly offtopic, but I really find the Bitwarden Clients to be lacking in the feature department. I switched to Bitwarden a few month ago and the client has evolved (for me) ever since. There are a few basic features missing, such as that if I search for something I wrote in the notes of password, that the client shows the according password. I get that the open-source model implies that everyone can contribute and…

I agree, it's a little weird that some very basic quality of life features are missing from such a popular and relatively mature product.

Folder management in particular seems to have been an afterthought. You create a subfolder by setting its name to its full path in the hierarchy, including all its parents. And thus, in order to rename a folder you have to manually go through every single subfolder and rename the particular parent in its name.

Other annoyances off the top of my head are things like the inability to change the type of a custom field from e.g. text to hidden without deleting it and creating a new field. Or the browser extension forgetting everything you just typed into the new item form (unless you remember to pop out the window) when pasting a generated password on the site you're trying to register to.

After switching from KeepassXC to Bitwarden for its better auto-fill detection and convenient synchronization, I can't help but feel that it's also been a downgrade in more ways than expected.

Re: Bitwarden Acquires Passwordless.dev

#117
post #85

Earlier quoted context omitted.

I’d bet on KeePass 2 longer term. KeepPassCX has been around 10 years (forked from a project started 8 years before that). Actively developed, cross platform. There are decent apps for android and iOS (eg Strongbox) I’m going to migrate off 1Password to it soon

I did this some time ago when 1Password announced switching from having native apps to being containerized web apps. Have not regretted it one bit.

Bingo, me too. I like that keepass is file based so I can use any storage medium to make multiple layers of security to access the vault. Even if cloud providers have access to the file or my cloud storage account gets hacked they still have to crack the file to get the passowrds. Also I have been using strongbox pro for a few years now and been very happy, in fact I like it better than what 1password used to be. Worth every penny. KeepassXC has also been great.

Re: Bitwarden Acquires Passwordless.dev

#119

I like where passwordless.dev is going. However, I don't think I'd like to build a business on top of that. Is there a similar implementation that's open-source that doesn't depend on a third party?

You can do all of it yourself, it's all based on open standards. Their value proposition is that by paying them, you don't have to DIY.

Re: Bitwarden Acquires Passwordless.dev

#120
post #111

Passwordless as a concept needs to die along with biometric auth. You have really good newer methods of auth. Instead of selling them as good MFA alternatives security vendors decided to replace passwords because that differentiates them more. But in reality, the layer of defense "what you know" should be complemented not replaced. A reduction in security being sold as a feature is dishonest and harmful.

Please explain how this is a reduction in security.
Post reply on HN