Live data from Hacker News

Bitwarden Acquires Passwordless.dev

bitwarden.com

341–350 of 399 posts

Re: Bitwarden Acquires Passwordless.dev

#341

I’ve been using the keepass ecosystem for years after switching from 1password. It’s open source, highly portable, and you don’t need a degree to set it up.

Yes, but password sharing in a team is no fun. You could use a completely separated password file, but then you might end up with a lot of password files with different passwords that need to be managed in another Keepass file. In theory there are child databases in Keepass, but using them with different clients and cloud sync never worked for me.

Re: Bitwarden Acquires Passwordless.dev

#342

Earlier quoted context omitted.

Millions, even tens of millions, for founders isn't unheard of at all for small "lifestyle" businesses. Not VC billions, but fuck you money is certainly doable.

I don't know if a couple million is "fuck you" money in 2023 (enough to never work again and eventually retire while living a fairly luxurious lifestyle?), but point taken.

If you can't say "fuck you" with a couple million in the bank, tax paid, in 2023 then you're living WAY outside your means.

Re: Bitwarden Acquires Passwordless.dev

#343

Earlier quoted context omitted.

Bingo, me too. I like that keepass is file based so I can use any storage medium to make multiple layers of security to access the vault. Even if cloud providers have access to the file or my cloud storage account gets hacked they still have to crack the file to get the passowrds. Also I have been using strongbox pro for a few years now and been very happy, in fact I like it better than what 1password used to be. Wor…

I've been considering a switch from 1Password to KeepassXC myself, but the last time I tried it, I couldn't find if KeepassXC has some equivalent to the "quick access" feature of 1Password.[0] In short, a way to open a small window, search for a service name or URL, and then quickly copy username, password, or a TOTP code. As far as I could tell, I had to open the entire KeepassXC app every time to find something. Ha…

That's a useful feature. Maybe you want to create a ticket for it in the KeepassXC issue tracker.

Re: Bitwarden Acquires Passwordless.dev

#344

Earlier quoted context omitted.

I don't know if a couple million is "fuck you" money in 2023 (enough to never work again and eventually retire while living a fairly luxurious lifestyle?), but point taken.

If you can't say "fuck you" with a couple million in the bank, tax paid, in 2023 then you're living WAY outside your means.

I can say "fuck you" with no money at all, since I can still talk for free!

How much do you need to take a, say, $130K income for the rest of your life? (Which is still not really enough to live at a wealthy luxury standard). Depends on how old you are and how long you'll live, as well as anticipated rates of investment return. But it's almost definitely more than 2 million.

https://www.thekickassentrepreneur.com/never-have-to-work-ag...

Re: Bitwarden Acquires Passwordless.dev

#345

Earlier quoted context omitted.

I've been considering a switch from 1Password to KeepassXC myself, but the last time I tried it, I couldn't find if KeepassXC has some equivalent to the "quick access" feature of 1Password.[0] In short, a way to open a small window, search for a service name or URL, and then quickly copy username, password, or a TOTP code. As far as I could tell, I had to open the entire KeepassXC app every time to find something. Ha…

That's a useful feature. Maybe you want to create a ticket for it in the KeepassXC issue tracker.

Looks like there's already a similar issue.[0] Lots of discussion but no solution yet.

[0] https://github.com/keepassxreboot/keepassxc/issues/99

Re: Bitwarden Acquires Passwordless.dev

#346
post #97

Earlier quoted context omitted.

How is "gmail yourself an encrypted backup" fine but "store a copy of the encrypted vault in a cloud service designed for this purpose" not?

I'm surprised someone as techy as the parent even uses Google if I'm honest.

Because the amount of effort required in avoiding them is a signal stronger than the noise of appearing normal.

Google is just as powerful as state actors, the same rules apply.

Don't stick out.

Re: Bitwarden Acquires Passwordless.dev

#347
post #97
post #87

Your passwords shouldn't leave your device. Chrome's password manager is pushing it. Everything else should be considered malware. I don't understand how such a 'techy' crowd here on HN can be so belligerent with this security vs convenience trade off. KeePass locally, gmail yourself an encrypted backup. That's it. FFS.

How is "gmail yourself an encrypted backup" fine but "store a copy of the encrypted vault in a cloud service designed for this purpose" not?

>"designed for this purpose"

I know my blob is encrypted, because I did it. Did you audit your password manager's source control? No?

That is the difference.

Re: Bitwarden Acquires Passwordless.dev

#348
post #87

Your passwords shouldn't leave your device. Chrome's password manager is pushing it. Everything else should be considered malware. I don't understand how such a 'techy' crowd here on HN can be so belligerent with this security vs convenience trade off. KeePass locally, gmail yourself an encrypted backup. That's it. FFS.

This push is because there's a lot of people using weak, reused passwords out there, who are not willing (or capable in cases) of a self-managing a password manager. For the people in my life in this position, I would much rather them use lastpass or bitwarden or anything over continuing their current practice. The risk of a lost password from one of those services is much lower than of them getting hit by password s…

I understand and agree on the normie point; my point was geared towards the 'techies'

Re: Bitwarden Acquires Passwordless.dev

#349
post #87

Your passwords shouldn't leave your device. Chrome's password manager is pushing it. Everything else should be considered malware. I don't understand how such a 'techy' crowd here on HN can be so belligerent with this security vs convenience trade off. KeePass locally, gmail yourself an encrypted backup. That's it. FFS.

If the key to decrypt the vault never leaves your device, then the security implications are minimal. Well worth the convenience in my eyes, and many others apparently.

>If the key to decrypt the vault never leaves your device,

>If

And, if you get infected, it is all moot anyway.

Re: Bitwarden Acquires Passwordless.dev

#350
post #87

Your passwords shouldn't leave your device. Chrome's password manager is pushing it. Everything else should be considered malware. I don't understand how such a 'techy' crowd here on HN can be so belligerent with this security vs convenience trade off. KeePass locally, gmail yourself an encrypted backup. That's it. FFS.

You don't know what you're talking about.

please elaborate, all-knowing-one
Post reply on HN