Live data from Hacker News

Bitwarden releases “emergency access” feature

bitwarden.com

61–70 of 154 posts

Re: Bitwarden releases “emergency access” feature

#61
post #39
post #16

The pandemic has made me (re)evaluate how my family can get to my finances and online services. Such solutions can solve issues related to bank/trading account access and key documents but what about subscription services? All my subscription services from Netflix/Plex (less important) to VPN/Blackblaze (more important) are tied to my credit cards, which upon my untimely demise will be deactivated. My family will sur…

Having gone through an unexpected, young death where nothing was recorded, I’ve come to the opposite conclusion: anything significant enough to care about already has next-of-kin processes established such that the Right Person will be able to sort it out. Indeed, when it comes to stuff like finances, at least where I live, touching them post-death creates issues when the legal channels confirming there’s no contest…

That's fine if you're single but incredibly selfish if you're not.

Re: Bitwarden releases “emergency access” feature

#62
post #33

Earlier quoted context omitted.

Have one email account on your domain (example.com) and use that for everything important. Use a long random password for the account and don't 2FA it. Share that with your family. That's probably all they need to gain access and reset your other accounts. If you 2FA the email account, you risk locking you and them out permanently for many services. I've written some about this. If you care to read it: https://www.go…

I don't buy the "don't use 2FA" argument. My partner knows how to unlock my phone. She can read the eventual SMS (I know, it's insecure, but still the only 2FA method in many US bansk), she will receive the email with the eventual password reset on the phone, she can use my authenticator apps. She also knows about my Yubikeys and where they are stored. She also has access to my laptop, where backups for the above are…

And what the manual unlock codes?

Re: Bitwarden releases “emergency access” feature

#63
post #16

The pandemic has made me (re)evaluate how my family can get to my finances and online services. Such solutions can solve issues related to bank/trading account access and key documents but what about subscription services? All my subscription services from Netflix/Plex (less important) to VPN/Blackblaze (more important) are tied to my credit cards, which upon my untimely demise will be deactivated. My family will sur…

I don't do anything with my online accounts; for assets I rely on beneficiary information and my will, and I expect that the online accounts will just die off (as CCs close, etc). I've always wondered if I should do more. What are the downsides of relying only on wills and beneficiaries? What might I be missing with this super basic estate planning?

I know of two off the top of my head, probate and people fighting over your stuff

Re: Bitwarden releases “emergency access” feature

#64
post #39

Earlier quoted context omitted.

Having gone through an unexpected, young death where nothing was recorded, I’ve come to the opposite conclusion: anything significant enough to care about already has next-of-kin processes established such that the Right Person will be able to sort it out. Indeed, when it comes to stuff like finances, at least where I live, touching them post-death creates issues when the legal channels confirming there’s no contest…

That's fine if you're single but incredibly selfish if you're not.

I think an accusation like that warrants some elaboration. Please describe why you think this is selfish.

Re: Bitwarden releases “emergency access” feature

#65
post #31

And you still can't use Bitwarden in Firefox's private mode.

Not sure why I'm getting down-voted. It doesn't work in Firefox's private mode. Nearly 4 years after the issue was raised. It was completely dismissed as "something Mozilla needs to fix" on multiple occasions.

Re: Bitwarden releases “emergency access” feature

#66
post #13

Earlier quoted context omitted.

I have a similar and opposite problem. I would be fine with all my secrets dying with me, but what i want to protect against is me going into a coma/for some reason I forget how to access my accounts. How to securely manage it so that only I can open it if my biological self is there? I don't trust bank safe deposit boxes and I can't put a safe worth using inside my Apt. https://www.nytimes.com/2019/07/19/business/sa…

I think you are going to have to rely on another human being (or perhaps a group of trusted individuals) even in that case. Depending upon what caused your incapacitation, you may or may not be able to actually retain and manage your secrets going forward. Put another way, if your wetware is damaged you may need a backup (aka trusted human) to handle your secrets on your behalf.

I think you are going to have to rely on another human being (or perhaps a group of trusted individuals) even in that case.

Not necessarily. Bank safe-deposit boxes are a secure place to keep secrets. To guard against rogue bank employees, encrypt the stored secrets and keep the key at home on a sticky note. If you ever hit your head and forget all your secrets, just present your ID to the bank teller, pull the secrets out of the vault, and decrypt them with the key on the sticky note.

Re: Bitwarden releases “emergency access” feature

#67
post #47

Earlier quoted context omitted.

Keep a copy in there if you want for convenience, I argue you’ll still want a paper backup somewhere. Opsec is hard, people are fallible. “What was the password?”, “Where’s the Yubikey?”, etc. These are not the failure scenarios you want to encounter during a tragedy (speaking from experience).

Bank safety deposit box is probably a good option for backup, it's very unlikely that both your home and the bank will burn down at the same time.

Safety Deposit boxes are not trustworthy

https://www.nytimes.com/2019/07/19/business/safe-deposit-box...

Re: Bitwarden releases “emergency access” feature

#68

Earlier quoted context omitted.

Everything should be documented. We have a binder with checklists that walk you through gaining access to everything the other partner might need in the event of death (email accounts, domain registrar, bank and brokerage accounts, auto/home/life insurance, ongoing recurring bills of all sorts). Bitwarden databases are exported to paper, 3 hole punched, and put in the binder on a schedule. Both partners get setup wit…

This is a good approach, but it requires having a partner in the first place...

I downvoted this at first, but I've undone that and am going to respond.

If you have family, extremely close friends (as adults, life-long friends), these can be options. Consider keeping your 'binder' in a safe deposit box and setting up access via your bank.

If not, an attorney or even CPA may be able to keep this information for you.

Re: Bitwarden releases “emergency access” feature

#69
post #26

Bitwarden is just fantastic. It's open source, the interface is clean, works fine on all platforms for me and pretty much everything is free. If the devs browse here, thanks for making it.

I have been using Bitwarden for over a year now and there are still tons of UX bugs that annoy me. In Firefox extension: 1. There is no memory. If you close the window, to copy the password, you have to re-search for the account to find the username. 2. If you open up bitwarden before the page is loaded, it says it can't find the password box to fill in. This is probably an extension limitation, but still annoying. i…

> 1. You should be able to set a default username or email to automatically use when creating a new account.

It's not a bad idea but you could also set up an identity, perhaps call it "New sign up", and it'll fill out the email address for you with two clicks - one to open Bitwarden, one to auto-fill.

Re: Bitwarden releases “emergency access” feature

#70
post #10

Earlier quoted context omitted.

Perhaps just an old ipnone or android with a fingerprint sensor and another installation of bitwarden. You can keep the phone's passcode written down because its only use is to start the device. Then configure biometric log-in for bitwarden as an alternative to a distinct passphrase. In the event of a total blank, you should still have access as long as you retain a finger.

Requires a passcode before allowing biometrics

That's why I said write down the passcode and keep it with the device. The device itself isn't important because you're not keeping anything on it. Bitwarden encrypts everything itself. To my knowledge, once you enable biometrics in bitwarden, you will not need to use the master passphrase.
Post reply on HN