Live data from Hacker News

Bitwarden adds support for passkeys

bitwarden.com

81–90 of 172 posts

Re: Bitwarden adds support for passkeys

#81
post #44

Earlier quoted context omitted.

what's the phishing risk if bitwarden autofills only on the correct domains stored in the vault?

> what's the phishing risk if bitwarden autofills only on the correct domains stored in the vault? The whole point of passkeys is that they should be tied to a specific domain, and thus be nonphisable. If Bitwarden allows reuse for different domains, that would be (as I understand it) a violation of the spec and a bug in their implementation.

Silly question perhaps, but what happens if a certain website changes to a different domain. E.g. a takeover of Company B by Company A who then decides to migrate all Company B passkeys to Company A and removes assets hosted under the Company B domain. This is easily sorted with existing tools but with passkeys... how?

Re: Bitwarden adds support for passkeys

#82
post #39

From the FAQ [1]: > Q: Are stored passkeys included in Bitwarden imports and exports? > A: Passkeys are not included in imports and exports. I think it's the same for iCloud [2]. That is why I don't love it. I prefer a very long password, and Bitwarden "Device login" that will prompt in my iPhone that will require FaceID (So essentially I have bio login). And 2FA to lower hacking chances. I'm aware I'm still vulnerab…

What stops anyone from forking their client and adding an "Export" button?

Re: Bitwarden adds support for passkeys

#84
post #39

From the FAQ [1]: > Q: Are stored passkeys included in Bitwarden imports and exports? > A: Passkeys are not included in imports and exports. I think it's the same for iCloud [2]. That is why I don't love it. I prefer a very long password, and Bitwarden "Device login" that will prompt in my iPhone that will require FaceID (So essentially I have bio login). And 2FA to lower hacking chances. I'm aware I'm still vulnerab…

What stops anyone from forking their client and adding an "Export" button?

export doesn't help if it's a TPM wrapped key

and websites can check the attestation on the registration to make sure it came from an apple/infineon/titan TPM

Re: Bitwarden adds support for passkeys

#85
post #2

Bitwarden is underrated. Passwords run everything in our digital life. I will gladly take a UI compromise here and there for more trustworthiness.

I am very happy to pay for a family plan. The price of one coffee per month. Thank you Bitwarden.

The coffee is really expensive where you live lol. Here is around €1. But it's a decent price for a password manager yes. And the personal one is even better.

Re: Bitwarden adds support for passkeys

#86
post #51
post #39

From the FAQ [1]: > Q: Are stored passkeys included in Bitwarden imports and exports? > A: Passkeys are not included in imports and exports. I think it's the same for iCloud [2]. That is why I don't love it. I prefer a very long password, and Bitwarden "Device login" that will prompt in my iPhone that will require FaceID (So essentially I have bio login). And 2FA to lower hacking chances. I'm aware I'm still vulnerab…

I hope they get over that. It's a blob of data. It's no more special than a TOTP secret or a conventional password, and I am completely uninterested in pretending otherwise because of a slick marketing campaign. It's a "thing I know" whether anybody likes it or not and you can't turn it into a "thing I have" just because you won't let me export it from this particular software. (Proof that it is a "thing I know": It…

I see this common refrain from people. How is writing something down so that you don't have to remember it a "thing you know"? You literally don't know it. A "thing you know" never leaves your brain, otherwise it becomes a "thing you have".

Re: Bitwarden adds support for passkeys

#87
post #8

Earlier quoted context omitted.

I moved over from Lastpass, I find the experience of filling in a password in Bitwarden more jarring/slow than in Lastpass. I'm not sure what it is, maybe Lastpass had longer timeouts to require FaceID when filling a password? Bitwarden requires it every time.

Can you compare to 1Password?

1Password is very trustworthy too. They get audited frequently, and their db file format is open source (meaning you can write a 3rd party tool to decrypt them).

With UI/UX they are lightyears ahead of Bitwarden. I want to like Bitwarden, but when your application doesn’t even support extremely basic stuff like drag ‘n drop, I’m gone.

In general they also support newer tech much faster. And their secret key system is more secure than Bitwarden’s password-only method.

Re: Bitwarden adds support for passkeys

#88
post #39

From the FAQ [1]: > Q: Are stored passkeys included in Bitwarden imports and exports? > A: Passkeys are not included in imports and exports. I think it's the same for iCloud [2]. That is why I don't love it. I prefer a very long password, and Bitwarden "Device login" that will prompt in my iPhone that will require FaceID (So essentially I have bio login). And 2FA to lower hacking chances. I'm aware I'm still vulnerab…

Maybe the authors saw this comment because the page you link to says, "A: Passkeys imports and exports will be included in a future release."

Re: Bitwarden adds support for passkeys

#90

One of the nicest thing about bitwarden is the ability to selfhost it. I don't think there is anything like it. 1password seems to have the best UX in the field. But you always have to trust some company with the keys to your digital life. Self hosting password managers is not as big of a deal as it should be.

I've been incredibly happy with https://www.passwordstore.org/ for years. The data store is a file hierarchy, with the files themselves encrypted with GPG. Sync is via git. TOTP support with a plugin.
Post reply on HN