Live data from Hacker News

Bitwarden adds support for passkeys

bitwarden.com

171–172 of 172 posts

Re: Bitwarden adds support for passkeys

#171
post #60
post #49

Earlier quoted context omitted.

In theory the Bitwarden server (and Vaultwarden) shouldn't have any access to the passwords, so a data breach of the server should never disclose any contents of the vault. Vaultwarden "feels" safe to me, but I would also be interested if there is some possibility it could introduce some degraded security compared to the official Bitwarden server. My Vaultwarden instance is "hidden" on a subdomain that probably nobod…

Good point actually, the passwords are encrypted with official Bitwarden client apps (unless using web app).

I think even the web app does the encryption in the browser.

The bitwarden windows app and the browser extension are more or less just the web app inside a webview.

Re: Bitwarden adds support for passkeys

#172
post #90

One of the nicest thing about bitwarden is the ability to selfhost it. I don't think there is anything like it. 1password seems to have the best UX in the field. But you always have to trust some company with the keys to your digital life. Self hosting password managers is not as big of a deal as it should be.

I've been incredibly happy with https://www.passwordstore.org/ for years. The data store is a file hierarchy, with the files themselves encrypted with GPG. Sync is via git. TOTP support with a plugin.

I'd use pass if there was an easy way to use it on mobile.
Post reply on HN