Live data from Hacker News

Bitwarden adds support for passkeys

bitwarden.com

161–170 of 172 posts

Re: Bitwarden adds support for passkeys

#161
post #148

Earlier quoted context omitted.

Can confirm this. Additionally, the Bitwarden app on mobiles also checks the app name (i.e. the 'com.company.appname' not the 'user friendly' name). It takes an extra step to 'force' Bitwarden to use a username/password if the name/domain does not match the name/domain(s) recorded against the username/password which adds a nice bit of friction.

There not even being an extra step is still much safer, no?

If I can't get my password thing to autofill on a mobile app (because the mobile app is on a different domain) then it's just annoying because I have to copy and paste over secrets.

That's the wrong thing twice over.

The password app should be as useful to me as a user as it can while still helping me be safe. "Hey, we can't confirm these creds are correct for this app. Do you still want to proceed?"

Re: Bitwarden adds support for passkeys

#162
post #21

Earlier quoted context omitted.

Having to manually type a folder path to create nested folders is horribly archaic. / Paying Bitwarden user

I think they fixed that. Can't verify at the moment.

Apparently there is two different things, Collections and Folders. Folders exist for personal vaults and collections for organizations. No idea why you can't use folders in organizations.

Re: Bitwarden adds support for passkeys

#163
post #120
post #87

Earlier quoted context omitted.

1Password is very trustworthy too. They get audited frequently, and their db file format is open source (meaning you can write a 3rd party tool to decrypt them). With UI/UX they are lightyears ahead of Bitwarden. I want to like Bitwarden, but when your application doesn’t even support extremely basic stuff like drag ‘n drop, I’m gone. In general they also support newer tech much faster. And their secret key system is…

> With UI/UX they are lightyears ahead of Bitwarden. 1Password is arguably moving backwards these days, UI-wise. I don't know if it's caused by the Electron update or just coincided with it, but I've been finding the keyboard autofill shortcut as well as keyboard navigation for selecting a given login on a page very unreliable lately. That said, 1Password's "auto-rotate password" feature is still ahead of the competi…

> > their secret key system is more secure than Bitwarden’s password-only method.

> I don't know, their security key mechanism seems to be getting weakened in the interest of convenience as well. I was recently very surprised to notice that the iOS client apparently synchronizes the security key for any logged-in vault to iCloud Keychain, with no way to opt out – even for enterprise vaults!

In their defense, they document that the point of the Secret Key is that it remains secret from them/AgileBits/1Password, and that it is expected to be present on-device. It used to be called the Account Key, but the reason the name was changed was because far too many people were referencing it in emails to support, which undermined the design.

In your defense, while they started syncing the Secret Key in iCloud Keychain all the way back at v7.0, they had then and have had sense gotten plenty of feedback saying this should be optional. They have just refused to make it optional.

Re: Bitwarden adds support for passkeys

#164
post #64

Earlier quoted context omitted.

I don’t even mind the UI honestly. It works. Some annoying UX here and there, but I can live with that. I happily pay for a subscription to support them.

My biggest peeve is that if you search for a password and you happen to be in the "Card" category for example, it will return 0 results. A good alternative would be to show No Results for the category you are in, but then provide results for other categories below.

My biggest issue is when having to copy multiple fields from an entry into the webpage and having to use the search (because the entry is for a different domain or just a note or a card) you have to search for the entry again and again because the search key doesn't persist

Re: Bitwarden adds support for passkeys

#165
post #156
post #145

Earlier quoted context omitted.

Can't we just put a 100px blinking red text that says "Do not share this with anyone or it's your own fault" and be done with it?

It would be great if that were actually 100% effective, but unfortunately phishing still happens despite such warnings. In a situation where a message on a screen tells a person to do x, and a person on the phone tells them to disregard it because it’s a computer error or whatever and do y, some percentage of people will do y. The only way to prevent that is for there to be only one option – the safe one. Sometimes t…

> In a situation where a message on a screen tells a person to do x, and a person on the phone tells them to disregard it because it’s a computer error or whatever and do y, some percentage of people will do y.

It's the human version of prompt injection attack.

Re: Bitwarden adds support for passkeys

#166
post #148

Earlier quoted context omitted.

There not even being an extra step is still much safer, no?

If I can't get my password thing to autofill on a mobile app (because the mobile app is on a different domain) then it's just annoying because I have to copy and paste over secrets. That's the wrong thing twice over. The password app should be as useful to me as a user as it can while still helping me be safe. "Hey, we can't confirm these creds are correct for this app. Do you still want to proceed?"

Or you can add another domain, saving users from easy buttons "yes, phish me anyway" is also useful

Re: Bitwarden adds support for passkeys

#167
post #143

Earlier quoted context omitted.

I agree with the general sentiment but every non-quantum "thing you have" can be duplicated. PS: I suspect that you could make a 2FA protocol capable of detecting duplication of the thing you have by having the app generate signed codes like "this is the n-th code I have generated" and have the server remember the n as a logical clock to detect duplicates and "time travel". AFAIK only bank-type apps would use somethi…

>but every non-quantum "thing you have" can be duplicated. Not easily. Extracting keys from hardware keys is very hard to do.

I agree, what I was trying to say is that not offering a key export is an attempt to gain some of the type of security provided by hardware keys: Difficulty to access the secret

Re: Bitwarden adds support for passkeys

#168
post #90

Earlier quoted context omitted.

I've been incredibly happy with https://www.passwordstore.org/ for years. The data store is a file hierarchy, with the files themselves encrypted with GPG. Sync is via git. TOTP support with a plugin.

The one major feature `pass` lacks is sharing. I used it for years, but moving to (self-hosted) bitwarden has made life a lot easier in that respect.

I share my vault with my partner. You can specify multiple gpg IDs in the `.gpg-id` file at the root of the store and passwords will be encrypted for both. You can do this on a per-directory basis too.

Re: Bitwarden adds support for passkeys

#169
post #51
post #39

From the FAQ [1]: > Q: Are stored passkeys included in Bitwarden imports and exports? > A: Passkeys are not included in imports and exports. I think it's the same for iCloud [2]. That is why I don't love it. I prefer a very long password, and Bitwarden "Device login" that will prompt in my iPhone that will require FaceID (So essentially I have bio login). And 2FA to lower hacking chances. I'm aware I'm still vulnerab…

I hope they get over that. It's a blob of data. It's no more special than a TOTP secret or a conventional password, and I am completely uninterested in pretending otherwise because of a slick marketing campaign. It's a "thing I know" whether anybody likes it or not and you can't turn it into a "thing I have" just because you won't let me export it from this particular software. (Proof that it is a "thing I know": It…

From: https://bitwarden.com/help/storing-passkeys/

> Saving and using passkeys are a feature of the Bitwarden browser extension. Other Bitwarden clients can be used to view the saved passkey.

So sadly, like TOTP I can't trust bitwarden to only keep my keys in an HSM on the server.

I really wish exporting would be impossible. Today, I need to add my primary and backup passkey devices whenever I signup for a service.

If keys were only stored on the server, then I could use it as a level of indirection.

Re: Bitwarden adds support for passkeys

#170
post #162

Earlier quoted context omitted.

I think they fixed that. Can't verify at the moment.

Apparently there is two different things, Collections and Folders. Folders exist for personal vaults and collections for organizations. No idea why you can't use folders in organizations.

Yeah you're right. I think folders are more like a "tag" in that it's not actually a container (I think you can even put stuff from an Organization's collections in your personal folders).

Anyway, with Collections, you used to have to create a collection and enter the name as Some/Thing, to get a hierarchy going. But I think they improved that so that you can just create that hierarchy of collections int he web gui as if they were folders in folders.

Post reply on HN