Live data from Hacker News

Bitwarden adds support for passkeys

bitwarden.com

71–80 of 172 posts

Re: Bitwarden adds support for passkeys

#71
post #23
post #15

One of the benefits we saw moving from lastpass to bitwarden is it allow us to much more easily reduce duplicate entries for the same site/account. So it's pretty annoying to see in the docs for this passkey feature that they just expect you to make a duplicate bitwarden entry for every additional passkey you need to add to an account. Especially when it's standard to register a backup key for any service that uses p…

What would be the purpose of having multiple passkeys for the same account stored in the same BitWarden vault? You're going to have a backup key and store it in the exact same place as the primary key?

The idea of passkeys is that they can be synced so you don't lose them when you lose a device. So there's a lot less need to have two

Re: Bitwarden adds support for passkeys

#72
post #39

From the FAQ [1]: > Q: Are stored passkeys included in Bitwarden imports and exports? > A: Passkeys are not included in imports and exports. I think it's the same for iCloud [2]. That is why I don't love it. I prefer a very long password, and Bitwarden "Device login" that will prompt in my iPhone that will require FaceID (So essentially I have bio login). And 2FA to lower hacking chances. I'm aware I'm still vulnerab…

> But essentially it's a certificate... I'll put upfront that I'm no expert in any of this, but ... unlike passwords and certificates, attestation is a thing for passkeys. The thing being attested to is "the private key of this cert is being secured by X". X might be YubiKey in the case of a FIDO2 key, or Google or Apple in the case of passkeys. This aspect of passkeys made me uncomfortable with them. If Google is go…

I hate attestation with a passion. But luckily Apple has not implemented it and nobody wants to lock all Apple users out. So at least right now it's not a thing in practice.

Re: Bitwarden adds support for passkeys

#73
post #39

From the FAQ [1]: > Q: Are stored passkeys included in Bitwarden imports and exports? > A: Passkeys are not included in imports and exports. I think it's the same for iCloud [2]. That is why I don't love it. I prefer a very long password, and Bitwarden "Device login" that will prompt in my iPhone that will require FaceID (So essentially I have bio login). And 2FA to lower hacking chances. I'm aware I'm still vulnerab…

But. If you run your own vaultwarden there must be a way to export it.

Re: Bitwarden adds support for passkeys

#74
post #39

From the FAQ [1]: > Q: Are stored passkeys included in Bitwarden imports and exports? > A: Passkeys are not included in imports and exports. I think it's the same for iCloud [2]. That is why I don't love it. I prefer a very long password, and Bitwarden "Device login" that will prompt in my iPhone that will require FaceID (So essentially I have bio login). And 2FA to lower hacking chances. I'm aware I'm still vulnerab…

+1. Lastpass was the love child until they got sold and sold out. I switched over to bitwarden but after being burned, keeping it basic with no lock in for now.

In which way did you get burned while using Bitwarden?

Re: Bitwarden adds support for passkeys

#75
post #66

Earlier quoted context omitted.

It is special - it should be a reference to an asymmetric key stored in hardware. But it's not clear whether they are actually doing this.

Some snippets from the FAQ [1]. > The public key is stored on the website and the private key is stored on your device or in your passkey provider, e.g. your Bitwarden Vault. > Passkeys are often able to sync across your devices, however not all platforms support this yet. So it sounds like it's not stored in hardware. It'll be interesting to see how it works if solutions that use a TPM or similar start to emerge. I…

> What happens if I have 500 passkeys backed by keys in a TPM and I get a new computer?

In theory the same thing that happens today with a yubikey - you have multiple devices with valid keys.

Re: Bitwarden adds support for passkeys

#76
post #39

From the FAQ [1]: > Q: Are stored passkeys included in Bitwarden imports and exports? > A: Passkeys are not included in imports and exports. I think it's the same for iCloud [2]. That is why I don't love it. I prefer a very long password, and Bitwarden "Device login" that will prompt in my iPhone that will require FaceID (So essentially I have bio login). And 2FA to lower hacking chances. I'm aware I'm still vulnerab…

You're not really vulnerable to phishing if you use a password manager with a browser extension. Cross-platform import/export for passkeys is considered a "nice-to-have" because you can always just add a new device via other established factors (email/SMS). So, what's the point, then? Why can't passkeys just be strings that I can extract via biometric authentication? The answer: everyone pushing this has a significan…

https://matduggan.com/passkeys-as-a-tool-for-user-retention/

> It is also, as currently implemented, one of the most effective platform lock-ins I've ever seen.

Re: Bitwarden adds support for passkeys

#77

One of the nicest thing about bitwarden is the ability to selfhost it. I don't think there is anything like it. 1password seems to have the best UX in the field. But you always have to trust some company with the keys to your digital life. Self hosting password managers is not as big of a deal as it should be.

You’re not really “trusting a company with the keys to your digital life”. The vault is encrypted with a password that never gets transmitted, and even if your password and vault gets stolen, without the additional “secret key” that also never leaves your device (and you should probably print and store somewhere safe), an attacker won’t be able to do much with it. The inclusion of an additional secret key makes a hug…

You realize that trust is not just about privacy the day your vault disappears from all your devices with no option whatsoever for recovery[1].

[1] https://1password.community/discussion/120403/delete-family-...

Re: Bitwarden adds support for passkeys

#78
post #46
post #9

Looks like the new version isn't approved for the firefox addons repository just yet... So haven't been able to try it out, but very happy with bitwarden (self-hosting a server using vaultwarden)

Looks like it not really released yet. I still have 2023.9.x everywhere, and 2023.10 is the version with passkey support.

It's definitely out (https://github.com/bitwarden/clients/releases/tag/browser-v2... just looks like browsers haven't approved it yet.

Re: Bitwarden adds support for passkeys

#79

One of the nicest thing about bitwarden is the ability to selfhost it. I don't think there is anything like it. 1password seems to have the best UX in the field. But you always have to trust some company with the keys to your digital life. Self hosting password managers is not as big of a deal as it should be.

You’re not really “trusting a company with the keys to your digital life”. The vault is encrypted with a password that never gets transmitted, and even if your password and vault gets stolen, without the additional “secret key” that also never leaves your device (and you should probably print and store somewhere safe), an attacker won’t be able to do much with it. The inclusion of an additional secret key makes a hug…

But you have to trust them that the secret key never gets transmitted, unless you compiled it yourself.

Re: Bitwarden adds support for passkeys

#80
post #58

Earlier quoted context omitted.

Mobile apps, slightly tweaky domain names (which happens normally), much less fancy xss type attacks, plus general data exfil.

Mobile BW app also wouldn't fill a password for a different domain

Can confirm this. Additionally, the Bitwarden app on mobiles also checks the app name (i.e. the 'com.company.appname' not the 'user friendly' name). It takes an extra step to 'force' Bitwarden to use a username/password if the name/domain does not match the name/domain(s) recorded against the username/password which adds a nice bit of friction.
Post reply on HN