Live data from Hacker News

Bitwarden Acquires Passwordless.dev

bitwarden.com

361–370 of 399 posts

Re: Bitwarden Acquires Passwordless.dev

#361

Earlier quoted context omitted.

1Password NEVER had lifetime licenses. We made this decision since day one because we had a product before that died because it was a "lifetime" purchase. The 1Password license is valid for the major version of the app. The license purchased would still work with that version today. If you look at the release history of 1Password apps — every version had a ton of updates made long after the app was no longer on sale.…

Pretty sure 1Password had "standalone" licenses. https://piunikaweb.com/2021/06/22/1password-ceases-all-licen... The article above talks about them being shutdown

They had "standalone" licenses but those weren't "lifetime licenses" I don't believe.

Re: Bitwarden Acquires Passwordless.dev

#362
post #47

Earlier quoted context omitted.

Bitwarden (for me) is still a little clunkier in how it does things compared to 1Password. I find 1Password a much smoother experience.

KeepassXC and/or strongbox have a very similar workflow to the older file based 1password one. I switched from 1password once they went to the centralized subscription model and I have been very happy with it for years now.

I am actually thinking of that app. They are going to implement templates (login, credit card, etc.) and when they do, I am in.

Re: Bitwarden Acquires Passwordless.dev

#363
post #5

Slightly offtopic, but I really find the Bitwarden Clients to be lacking in the feature department. I switched to Bitwarden a few month ago and the client has evolved (for me) ever since. There are a few basic features missing, such as that if I search for something I wrote in the notes of password, that the client shows the according password. I get that the open-source model implies that everyone can contribute and…

yeah, for me the Bitwarden iphone app doesnt support Touchid, which means I have to enter my password everytime. 1Password does, and is much easier to use (though I use both)

I don't know about Bitwarden supporting TouchID, but it does support FaceID.

Re: Bitwarden Acquires Passwordless.dev

#364

Could someone clarify what the relationship between passkeys and WebAuthn is? Is it that Passkey is the Apple, Google, Microsoft implementation (commercialization?) of WebAuthn? If so, does it add anything on top of WebAuthn that makes it differ in some fundamental way? Also, are passkeys how WebAuthn is most commonly actually used in practice? Apologies for the noob questions.

We wrote a long post on Passkeys, in particular how they are implemented by Apple[0] that might be interesting.

Technically a Passkey is just a multi-device FIDO credential that is compatible with WebAuthn (which is an official W3C and FIDO spec).

However, vendors implementations of Passkeys/FIDO credentials differ quite widely. The Apple implementation of Passkeys, as an example, doesn't provide attestation information which reduces the ability to do device verification. Similarly, even though it's not technically part of Passkeys, Apple removed the possibility to create device-bound WebAuthn keys which significantly weakens the security guarantees you'd normally get with WebAuthn.

[0]https://www.slashid.dev/blog/passkeys-deepdive/

Re: Bitwarden Acquires Passwordless.dev

#365
post #364

Could someone clarify what the relationship between passkeys and WebAuthn is? Is it that Passkey is the Apple, Google, Microsoft implementation (commercialization?) of WebAuthn? If so, does it add anything on top of WebAuthn that makes it differ in some fundamental way? Also, are passkeys how WebAuthn is most commonly actually used in practice? Apologies for the noob questions.

We wrote a long post on Passkeys, in particular how they are implemented by Apple[0] that might be interesting. Technically a Passkey is just a multi-device FIDO credential that is compatible with WebAuthn (which is an official W3C and FIDO spec). However, vendors implementations of Passkeys/FIDO credentials differ quite widely. The Apple implementation of Passkeys, as an example, doesn't provide attestation informat…

This looks great, thanks for the link

Re: Bitwarden Acquires Passwordless.dev

#366

Earlier quoted context omitted.

So is LastPass, but we users changed our passwords in December anyway as a precaution. Bitwarden is still a central entity that needs to be trusted to manage the zero knowledge platform with competence, e.g. not storing unencrypted metadata in a backup.

They cannot store unencrypted data because the whole vault is encrypted client side. And thats verifiable because their clients are open source.

That specific fault applied to LastPass, I used it as an example of a flaw in a system advertised as zero knowledge, to demonstrate that not all systems are created equal. It is true that BitWarden's Open Source nature helps prevent silly things like that.

You raise a good point that their open source clients are _verifiable_, but they're not often _verified_. I'm certain that you verify the checksums of all your updates or exclusively build from source, but the distribution channels on most platforms encourage users to trust updates from BitWarden inc. If those channels are compromised, most users are one unchecked automatic Play Store update away from a problem.

Not disagreeing, just noting that Open Source is not a silver bullet given BitWarden's default architecture is centralised web service with centralised client distribution channels.

Re: Bitwarden Acquires Passwordless.dev

#367
post #200
post #125

Earlier quoted context omitted.

In 1Password there's at least a half dozen ways that drag and drop could be used: - Drag a password into a password field - Drag an attachment from Finder/Explorer into an item - Drag an item from vault to vault (or collection in Bitwarden parlance) - Drag an item into a tag or folder to add that item to the folder, or add that tag to the item - Drag an app to the 1Password icon to create a software license item with…

You must be on mac, because my 1pw experience is horrible on Linux. Edit a password in the browserextention opens an new tab in n which i have to login all again. Ugh. Bitwarden at least doesn't do that. Drag and drop? Nope.

With 1Password 8, AgileBits made 1Password an universal Electron app. Experience is virtually the same whether you are on Mac, Windows or Linux.

The 1Password browser extension and application should sync, but it’s experimental on Linux AFAIK.

Re: Bitwarden Acquires Passwordless.dev

#368
post #364

Earlier quoted context omitted.

We wrote a long post on Passkeys, in particular how they are implemented by Apple[0] that might be interesting. Technically a Passkey is just a multi-device FIDO credential that is compatible with WebAuthn (which is an official W3C and FIDO spec). However, vendors implementations of Passkeys/FIDO credentials differ quite widely. The Apple implementation of Passkeys, as an example, doesn't provide attestation informat…

This looks great, thanks for the link

Happy to chat more about it if you'd like!

Re: Bitwarden Acquires Passwordless.dev

#369
The idea of FIDO2 with HW tokens is great, but not practical if you don't own atleast 2 pieces: - one constantly inserted into main working machine - second somewhere with the keys, ready to be used on other devices

You should be having third one - backup token stored securely in the safe or vault. That is $150 investment just to do it right.

And then - not all webapps allow to register more that one FIDO2 device, which totally cancels the above best practises.

Re: Bitwarden Acquires Passwordless.dev

#370

Earlier quoted context omitted.

Doesn't necessarily matter what LastPass "would have also led their customers to believe", the mathematical reality is still that LassPass vaults are crackable in a way that 1P vaults fundamentally are not.

Yes, according to what 1Password is telling us. But as we've seen, what these companies say and what they actually do in practice are not always aligned. And oftentimes customers are inserting a lot of their own assumptions into the mix, not only with respect to vault encryption but vault storage and operational security.

> Yes, according to what 1Password is telling us

With their very comprehensive whitepaper and Charles Proxy you can verify all their claims. Their whitepaper is one of the best resources I have found on E2EE in general. With that, you should be able to write your own 1P vault parser. Then you can verify that traffic to their server is exactly what they claim it to be.

In another comment you are criticizing that their product is proprietary - that's IMO not quite true. Yes, 1P is closed source, but their crypto strategy is documented extensively - they list the exact cipher algos and settings.

> not only with respect to vault encryption but vault storage and operational security

That's a valid argument, BUT, if you read their whitepaper, you'll likely arrive at the conclusion that even a full leak of the encrypted vault is currently not that problematic. I wouldn't post it online, but I'm not worried if they announce a leak tomorrow.

Post reply on HN