Live data from Hacker News

Bitwarden integrates with OneCLI agent vault

onecli.sh

31–40 of 48 posts

Re: Bitwarden integrates with OneCLI agent vault

#31

These tools are useful, but I can't help to feel like they're solving the wrong part of the problem. I really don't have much concern that an agent has access to one of my credentials. Outside of production, most of these credentials are going to be limited in privilege and self-rotatable. What remains terrifying is the ability to exfil important data or run commands that are malicious.

exfiltrating a credential provides persistent access (until detected and rotated) tho! probably one of the more leveraged things to prevent

Re: Bitwarden integrates with OneCLI agent vault

#33

[flagged]

How so? From what I understand, all requests have to be proxied through OneCLI so that agent can't see your keys.

OneCLI assumes that the proxy is fully trusted by the agent and it still has authorized access to your accounts.

What happens when the agent environment is breached? All you need is the fake key + URL of the proxy and that maps to your real keys and you can make authorized requests outside of the agent.

The real keys don't have to be leaked, just the fake ones have to map to the real one; so unless they are rotated, then this is a problem.

Re: Bitwarden integrates with OneCLI agent vault

#34
post #22

Reading the article, it sounds like this is the other way around? Bitwarden is offering a new API, and OneCLI Agent Vault is integrating with the new API.

integration is a two-way street. it doesn't matter which is stated first

I disagree that integration is commutative.

Often, we see a feature which is important to free use of a computer as a general-purpose tool locked behind an ever-changing and/or poorly documented API in a closed-source, centralized, de-facto-government-subsidized project.

The power dynamics of that situation are not symmetrical, so it does matter which project(s) are using which API(s) of the other(s).

Re: Bitwarden integrates with OneCLI agent vault

#35
post #20

Earlier quoted context omitted.

Who cares? Did you get the point of the message or not? People trying to detect AI and seeing red the moment their AI-sniff test fails are killing discourse.

lmao... people using AI are killing discourse. and then come along bootlickers like you

You're right, it's actually the people throwing around inflammatory statements like "bootlickers" to virtue signal and score fake internet points that are doing the most harm.

Re: Bitwarden integrates with OneCLI agent vault

#36

I really don't understand the HN comments here. Lots of assumptions that the article is AI-authored (it could be but I'm not seeing overtly obvious signs - it's quite readable) & a lot of ungrounded assumptions that this is somehow related to Bitwarden integrating AI into their product. I really thought reading comprehension among HN users was better than this.

Yeah, it seems like this is at minimum an "ok" thing. Honestly having a good way to do secrets management with agents seems like a good idea.

Re: Bitwarden integrates with OneCLI agent vault

#37
post #7

[flagged]

Who cares? Did you get the point of the message or not? People trying to detect AI and seeing red the moment their AI-sniff test fails are killing discourse.

The authors want me to trust them to handle all my passwords. I'm not going to do that if they don't respect me enough to tell me I'm reading AI-generated content.

Re: Bitwarden integrates with OneCLI agent vault

#38
post #33

Earlier quoted context omitted.

How so? From what I understand, all requests have to be proxied through OneCLI so that agent can't see your keys.

OneCLI assumes that the proxy is fully trusted by the agent and it still has authorized access to your accounts. What happens when the agent environment is breached? All you need is the fake key + URL of the proxy and that maps to your real keys and you can make authorized requests outside of the agent. The real keys don't have to be leaked, just the fake ones have to map to the real one; so unless they are rotated,…

Exactly. I appreciate the considerations they have already taken, this is definitely a problem that needs to be addressed as agentic AI continues its warpath.

However, this feels to me like widening the attack surface rather than tightening security. I'm going to dig in to this over the next few weeks. Hopefully I prove myself wrong

Re: Bitwarden integrates with OneCLI agent vault

#39
post #22

Reading the article, it sounds like this is the other way around? Bitwarden is offering a new API, and OneCLI Agent Vault is integrating with the new API.

integration is a two-way street. it doesn't matter which is stated first

I added "login with google" to my website. Should I go to the news media to brag about how google is launching an integration with me?

Re: Bitwarden integrates with OneCLI agent vault

#40
post #39

Earlier quoted context omitted.

integration is a two-way street. it doesn't matter which is stated first

I added "login with google" to my website. Should I go to the news media to brag about how google is launching an integration with me?

But in this case they both made posts that point to each other.

https://bitwarden.com/blog/introducing-agent-access-sdk/#int...

Post reply on HN