You have really good newer methods of auth. Instead of selling them as good MFA alternatives security vendors decided to replace passwords because that differentiates them more. But in reality, the layer of defense "what you know" should be complemented not replaced. A reduction in security being sold as a feature is dishonest and harmful.
Bitwarden Acquires Passwordless.dev
111–120 of 399 posts
Re: Bitwarden Acquires Passwordless.dev
#112Re: Bitwarden Acquires Passwordless.dev
#113Your passwords shouldn't leave your device. Chrome's password manager is pushing it. Everything else should be considered malware. I don't understand how such a 'techy' crowd here on HN can be so belligerent with this security vs convenience trade off. KeePass locally, gmail yourself an encrypted backup. That's it. FFS.
How is "gmail yourself an encrypted backup" fine but "store a copy of the encrypted vault in a cloud service designed for this purpose" not?
Re: Bitwarden Acquires Passwordless.dev
#114Your passwords shouldn't leave your device. Chrome's password manager is pushing it. Everything else should be considered malware. I don't understand how such a 'techy' crowd here on HN can be so belligerent with this security vs convenience trade off. KeePass locally, gmail yourself an encrypted backup. That's it. FFS.
How is "gmail yourself an encrypted backup" fine but "store a copy of the encrypted vault in a cloud service designed for this purpose" not?
Re: Bitwarden Acquires Passwordless.dev
#115I still don't understand how it works. I went into the website under authenticated using my phones API, where is my account now? There is nothing in my Bitwarden vault.
Passkeys are stored on your platform keychain. In time, Bitwarden will offer this interface up, so you can sync them through your Bitwarden vault. Currently, if you use an iPhone, you will have the passkey stored in iCloud keychain. Your "account" is a private key held within iCloud keychain, along with some metadata mapping that private key to the site you visited.
Anyway this really needs to be exportable, otherwise its in the ultimate platform lock.
Re: Bitwarden Acquires Passwordless.dev
#116Slightly offtopic, but I really find the Bitwarden Clients to be lacking in the feature department. I switched to Bitwarden a few month ago and the client has evolved (for me) ever since. There are a few basic features missing, such as that if I search for something I wrote in the notes of password, that the client shows the according password. I get that the open-source model implies that everyone can contribute and…
Folder management in particular seems to have been an afterthought. You create a subfolder by setting its name to its full path in the hierarchy, including all its parents. And thus, in order to rename a folder you have to manually go through every single subfolder and rename the particular parent in its name.
Other annoyances off the top of my head are things like the inability to change the type of a custom field from e.g. text to hidden without deleting it and creating a new field. Or the browser extension forgetting everything you just typed into the new item form (unless you remember to pop out the window) when pasting a generated password on the site you're trying to register to.
After switching from KeepassXC to Bitwarden for its better auto-fill detection and convenient synchronization, I can't help but feel that it's also been a downgrade in more ways than expected.
Re: Bitwarden Acquires Passwordless.dev
#117Earlier quoted context omitted.
I’d bet on KeePass 2 longer term. KeepPassCX has been around 10 years (forked from a project started 8 years before that). Actively developed, cross platform. There are decent apps for android and iOS (eg Strongbox) I’m going to migrate off 1Password to it soon
I did this some time ago when 1Password announced switching from having native apps to being containerized web apps. Have not regretted it one bit.
Re: Bitwarden Acquires Passwordless.dev
#118Re: Bitwarden Acquires Passwordless.dev
#119I like where passwordless.dev is going. However, I don't think I'd like to build a business on top of that. Is there a similar implementation that's open-source that doesn't depend on a third party?
Re: Bitwarden Acquires Passwordless.dev
#120Passwordless as a concept needs to die along with biometric auth. You have really good newer methods of auth. Instead of selling them as good MFA alternatives security vendors decided to replace passwords because that differentiates them more. But in reality, the layer of defense "what you know" should be complemented not replaced. A reduction in security being sold as a feature is dishonest and harmful.