Earlier quoted context omitted.
> But essentially it's a certificate... I'll put upfront that I'm no expert in any of this, but ... unlike passwords and certificates, attestation is a thing for passkeys. The thing being attested to is "the private key of this cert is being secured by X". X might be YubiKey in the case of a FIDO2 key, or Google or Apple in the case of passkeys. This aspect of passkeys made me uncomfortable with them. If Google is go…
I hate attestation with a passion. But luckily Apple has not implemented it and nobody wants to lock all Apple users out. So at least right now it's not a thing in practice.
Bitwarden adds support for passkeys
121–130 of 172 posts
Re: Bitwarden adds support for passkeys
#122Earlier quoted context omitted.
I've experienced this on my phone IIRC...if I register a webauthn key on chrome on iphone, it shows up on safari; but the reverse is not true. Im assuming this is because apple uses a software based TPM that isn't tied to the device. This lets those private keys sync between devices. Is the future state for bitwarden to be able to perform the same trick somehow? Have you create keys in it and not your devices tpm?
The situation with Chrome and Apple devices is currently quite confusing. Apple has only recently introduced the necessary APIs to allow for third-party passkey providers (i.e. other apps acting as a passkey storage) and users (i.e. other apps using passkeys stored in iCloud and in other third-party provider apps). But it's not easy as passkeys being supported on the latest versions; at least Google used to support a…
As someone who's used 1Password, Apple's password/passkey manager, and Chrome's password/passkey manager while checking out the passkey user experience of these respective solutions, I didn't find it more confusing than the ability to choose your preferred password manager. That is, I didn't find it confusing.
Re: Bitwarden adds support for passkeys
#123Earlier quoted context omitted.
> But essentially it's a certificate... I'll put upfront that I'm no expert in any of this, but ... unlike passwords and certificates, attestation is a thing for passkeys. The thing being attested to is "the private key of this cert is being secured by X". X might be YubiKey in the case of a FIDO2 key, or Google or Apple in the case of passkeys. This aspect of passkeys made me uncomfortable with them. If Google is go…
Yep. The end game of this is that web applications will, either through laziness or a sense of 'better security', only accept passkeys attested by Google/Apple/MS and/or those backed by TPM with non-exportable keys. You have to register with the FIDO Alliance to obtain an attestation GUID, and unsurprisingly, only the big guys are on the list: https://github.com/passkeydeveloper/passkey-authenticator-aa... This move…
It used to not even accept Yubikeys, only a fairly unknown other brand; now they finally do support Yubikeys, but only the "FIDO L2" certified kind, i.e. the FIDO and "security key" models, but not the most common plain Yubikey ones...
Re: Bitwarden adds support for passkeys
#124From the FAQ [1]: > Q: Are stored passkeys included in Bitwarden imports and exports? > A: Passkeys are not included in imports and exports. I think it's the same for iCloud [2]. That is why I don't love it. I prefer a very long password, and Bitwarden "Device login" that will prompt in my iPhone that will require FaceID (So essentially I have bio login). And 2FA to lower hacking chances. I'm aware I'm still vulnerab…
You're not really vulnerable to phishing if you use a password manager with a browser extension. Cross-platform import/export for passkeys is considered a "nice-to-have" because you can always just add a new device via other established factors (email/SMS). So, what's the point, then? Why can't passkeys just be strings that I can extract via biometric authentication? The answer: everyone pushing this has a significan…
As much as that lock-in annoys me personally – I could absolutely see this become a tech support scam attack vector. "Please share your passkey with us for authentication by going to your device's settings and selecting the 'export passkey' option"...
> you can always just add a new device via other established factors (email/SMS)
That gives the relying party some agency about requiring additional authentication to add devices though, of treating devices added under dubious circumstances as less trusted, or simply of sending a security notification to the customer.
Exporting a passkey leaves no relying-party-side traces.
Re: Bitwarden adds support for passkeys
#125Earlier quoted context omitted.
Yep. Thing you have is a passkey that can't be copied at all, like a yuibikey, some physical manifestation that can't be easily cloned. Arguably TOTP is "have" due to being linked to a phone when doing push to a single device.
TOTP is just PAKE with a funny way of writing the password. We tricked people into using actually secure passwords and password managers by calling it 2FA and devising a scheme where the human does the challenge and the server necessarily must keep that part of the password in plaintext, but in exchange the user doesn't have to type out the long part of the password every time.
PAKEs do significantly more; in particular, they are MITM resistant (unlike TOTPs) and provide mutual authentication.
Re: Bitwarden adds support for passkeys
#126Earlier quoted context omitted.
The situation with Chrome and Apple devices is currently quite confusing. Apple has only recently introduced the necessary APIs to allow for third-party passkey providers (i.e. other apps acting as a passkey storage) and users (i.e. other apps using passkeys stored in iCloud and in other third-party provider apps). But it's not easy as passkeys being supported on the latest versions; at least Google used to support a…
> The situation with Chrome and Apple devices is currently quite confusing. As someone who's used 1Password, Apple's password/passkey manager, and Chrome's password/passkey manager while checking out the passkey user experience of these respective solutions, I didn't find it more confusing than the ability to choose your preferred password manager. That is, I didn't find it confusing.
Maybe the onboarding experience is better now, but when I last looked into this, 1Password and Chrome were fighting over who gets to store newly generated passkeys in my browser. At the same time, Chrome's ability to use Apple/iCloud passkeys is brand new; before macOS Sonoma, this wasn't possible at all.
Re: Bitwarden adds support for passkeys
#127Earlier quoted context omitted.
what's the phishing risk if bitwarden autofills only on the correct domains stored in the vault?
> what's the phishing risk if bitwarden autofills only on the correct domains stored in the vault? The whole point of passkeys is that they should be tied to a specific domain, and thus be nonphisable. If Bitwarden allows reuse for different domains, that would be (as I understand it) a violation of the spec and a bug in their implementation.
So even if Bitwarden would go blatantly out of spec and allow usage of a passkey created on and scoped to a.com on b.com, the assertion signature would effectively say "I want to login to b.com", which a.com would simply reject.
That's what makes it so much harder to phish than auto-filled passwords (which could still be MITMed e.g. through usage of attacker-installed TLS certificates).
Re: Bitwarden adds support for passkeys
#128Re: Bitwarden adds support for passkeys
#129From the FAQ [1]: > Q: Are stored passkeys included in Bitwarden imports and exports? > A: Passkeys are not included in imports and exports. I think it's the same for iCloud [2]. That is why I don't love it. I prefer a very long password, and Bitwarden "Device login" that will prompt in my iPhone that will require FaceID (So essentially I have bio login). And 2FA to lower hacking chances. I'm aware I'm still vulnerab…
But. If you run your own vaultwarden there must be a way to export it.
Re: Bitwarden adds support for passkeys
#130Earlier quoted context omitted.
Bitwarden's UI is far from perfect but I find it better than any competitors I've tried (LP & 1Pass). 1Password feels cleaner, more integrated & polished but in practice the UX is inferior to BW - most regular actions take more clicks & discoverability is lower. And the password generator is even worse than LP's. Lastpass UI is well known to be poor - Bitwarden's is far less worse by every metric. Bitwarden's not per…
Nothing beats www.enpass.io but they charge now. I still ran the free version (free version not available for download anymore).
So, how would you access that cloud account in the first place? Unless you remember the password and disable 2FA for that cloud account, unless of course you add another 2FA manager which is just an extra non-needed complexity.