Live data from Hacker News

Bitwarden adds support for passkeys

bitwarden.com

61–70 of 172 posts

Re: Bitwarden adds support for passkeys

#61
post #15

One of the benefits we saw moving from lastpass to bitwarden is it allow us to much more easily reduce duplicate entries for the same site/account. So it's pretty annoying to see in the docs for this passkey feature that they just expect you to make a duplicate bitwarden entry for every additional passkey you need to add to an account. Especially when it's standard to register a backup key for any service that uses p…

> Especially when it's standard to register a backup key for any service that uses passkeys.

I’ve never heard of this for Passkeys, only for hardware keys.

Passkeys are meant to be something “that you have”, similar to one hardware key, why would you want to store 2 within the same password manager? What would that give you?

Re: Bitwarden adds support for passkeys

#62

One of the nicest thing about bitwarden is the ability to selfhost it. I don't think there is anything like it. 1password seems to have the best UX in the field. But you always have to trust some company with the keys to your digital life. Self hosting password managers is not as big of a deal as it should be.

You’re not really “trusting a company with the keys to your digital life”.

The vault is encrypted with a password that never gets transmitted, and even if your password and vault gets stolen, without the additional “secret key” that also never leaves your device (and you should probably print and store somewhere safe), an attacker won’t be able to do much with it.

The inclusion of an additional secret key makes a huge difference in this setup. but yes, it would be much nicer if I could use my own sync store like in the past… (looking at EnPass currently which also has a secret key setup and own sync store)

Re: Bitwarden adds support for passkeys

#63
post #13

Earlier quoted context omitted.

KeepassXC will have passkey support soon: https://github.com/keepassxreboot/keepassxc/issues/1870 Don't get FOMO; both seem to support export and import, and they seem to be compatible formats, but you may need to lightly modify the CSV from Bitwarden.

Very cool, thanks for the tip. I use KeePassXC together with Syncthing, so now I just need a compatible android client.

I recommend KeepassDX.

https://f-droid.org/en/packages/com.kunzisoft.keepass.libre/

Re: Bitwarden adds support for passkeys

#64
post #2

Bitwarden is underrated. Passwords run everything in our digital life. I will gladly take a UI compromise here and there for more trustworthiness.

I don’t even mind the UI honestly. It works. Some annoying UX here and there, but I can live with that. I happily pay for a subscription to support them.

My biggest peeve is that if you search for a password and you happen to be in the "Card" category for example, it will return 0 results. A good alternative would be to show No Results for the category you are in, but then provide results for other categories below.

Re: Bitwarden adds support for passkeys

#65
post #51

Earlier quoted context omitted.

I hope they get over that. It's a blob of data. It's no more special than a TOTP secret or a conventional password, and I am completely uninterested in pretending otherwise because of a slick marketing campaign. It's a "thing I know" whether anybody likes it or not and you can't turn it into a "thing I have" just because you won't let me export it from this particular software. (Proof that it is a "thing I know": It…

It is special - it should be a reference to an asymmetric key stored in hardware. But it's not clear whether they are actually doing this.

If it is just a pointer a hardware, even more reason to let you export it.

Re: Bitwarden adds support for passkeys

#66
post #51

Earlier quoted context omitted.

I hope they get over that. It's a blob of data. It's no more special than a TOTP secret or a conventional password, and I am completely uninterested in pretending otherwise because of a slick marketing campaign. It's a "thing I know" whether anybody likes it or not and you can't turn it into a "thing I have" just because you won't let me export it from this particular software. (Proof that it is a "thing I know": It…

It is special - it should be a reference to an asymmetric key stored in hardware. But it's not clear whether they are actually doing this.

Some snippets from the FAQ [1].

> The public key is stored on the website and the private key is stored on your device or in your passkey provider, e.g. your Bitwarden Vault.

> Passkeys are often able to sync across your devices, however not all platforms support this yet.

So it sounds like it's not stored in hardware. It'll be interesting to see how it works if solutions that use a TPM or similar start to emerge. I have nearly 1000 passwords and many of them are shared with colleagues, parents, siblings, etc.. I can't even imagine a way you could make that work if the private key is owned by a TPM (aka a hardware bound key) and needs to be enrolled somehow prior to becoming usable.

What happens if I have 500 passkeys backed by keys in a TPM and I get a new computer?

1. https://bitwarden.com/resources/passkeys-faq/

Re: Bitwarden adds support for passkeys

#68
post #39

From the FAQ [1]: > Q: Are stored passkeys included in Bitwarden imports and exports? > A: Passkeys are not included in imports and exports. I think it's the same for iCloud [2]. That is why I don't love it. I prefer a very long password, and Bitwarden "Device login" that will prompt in my iPhone that will require FaceID (So essentially I have bio login). And 2FA to lower hacking chances. I'm aware I'm still vulnerab…

> But essentially it's a certificate...

I'll put upfront that I'm no expert in any of this, but ... unlike passwords and certificates, attestation is a thing for passkeys. The thing being attested to is "the private key of this cert is being secured by X". X might be YubiKey in the case of a FIDO2 key, or Google or Apple in the case of passkeys.

This aspect of passkeys made me uncomfortable with them. If Google is going to attest they manage your passkey, then it follows the aren't giving a copy to anybody, including you. That means if you lose your Google account you've lost control of your ID. But note: that's control, not the keys themselves. You probably will have a copy of them on a phone, so you can still use them until that phone dies. But when it does you've in a world of pain because you can't backup / transfer / copy them - only Google can do that. In effect you don't own your Google passkey - Google does.

I don't know if Bitwarden does attestation now, or if the are planning to implement it in the future. But if either of those things are true they can't give you a copy of the key, ever.

This still makes me uncomfortable. But I can see why it is so. You and I may be capable of protecting a private key, but my mother and 99% of the rest of the planet aren't. Your bank or whoever trusting me on my say so isn't going to work, so the end result of us never being able to manage our own keys is inevitable. We have to put them in the hands of a 3rd party the bank or whoever can trust.

And it is ameliorated by another aspect of FIDO2 / passkeys: unlike passwords where you can only have one per site, sites are expected to support many FIDO2 keys for the same person. And, you are expected to keep several of them and authenticate each of them at every site you use. So you might have a Google one, and a Bitwarden one, and maybe even a Keypass one. If you did you solve the "Google owns my ID" problem, but it's such a pain in the arse to do I don't see it happening.

We've seen several iterations of this concept: FIDO, WebAuthn/FIDO2, and now passkeys. I'd like to see one more: some way of bundling up a whole pile of passkeys from different providers, so when I establish a new account on a web site, I register all of them. That would make maintaining a bunch of PassKeys trackable. Right now, the reality is bugger all people are going to do it. And as a consequence, a good chunk of the planet is going to end up with Apple / Google / whoever owning their identities. And of course some of them are going to lose their relationship they had with there ID manager, and wake up one day to discover themselves wiped from the digital planet.

Re: Bitwarden adds support for passkeys

#69
post #64

Earlier quoted context omitted.

I don’t even mind the UI honestly. It works. Some annoying UX here and there, but I can live with that. I happily pay for a subscription to support them.

My biggest peeve is that if you search for a password and you happen to be in the "Card" category for example, it will return 0 results. A good alternative would be to show No Results for the category you are in, but then provide results for other categories below.

Yeah that gets me somewhat frequently too, and second the request you have.

Another silly one is adding custom fields, you can’t change the type between visible/hidden once it’s created, so if you mess up, you have to delete the custom field and add it with the desired visibility. Ughhh

Re: Bitwarden adds support for passkeys

#70
post #49
post #28

Does the code in Vaultwarden mimic the code in the self hosted version of Bitwarden? Or a code audit in Bitwarden has no bearing on vaultwarden?

In theory the Bitwarden server (and Vaultwarden) shouldn't have any access to the passwords, so a data breach of the server should never disclose any contents of the vault. Vaultwarden "feels" safe to me, but I would also be interested if there is some possibility it could introduce some degraded security compared to the official Bitwarden server. My Vaultwarden instance is "hidden" on a subdomain that probably nobod…

How do you hide subdomain ?
Post reply on HN