27 ms·
Bitwarden releases “emergency access” feature
- fhoxh 6y agoThis represents a dramatic escalation of side-channel attack vectors and surface area. It’s an unfortunate inevitability that this will not end well. Secure platforms never provide affordances for backdoors, especially backdoors tightly coupled to externalities. Bitwarden is further attracting unnecessary attention to itself from actors who have an interest in the collection of the volunteered emergency-trust relationships. Bitwarden would be well-advised to reconsider this feature.
- Nightshaxx 6y agoI disagree. This is an extremely important feature. If something happens to me, I wouldn't want my family to have to jump through insane hoops to get access to my accounts for a bit of extra theoretical security. At this point something traumatic has already happened to them and this would just be another emotion burden. This could be for financial reasons, or say if I were missing, to communicate with my friends. Let people who don't need it and don't want it turn it off, but for me I'd definitely have it on.
- blakesterz 6y agoHere's the details on how it works: https://bitwarden.com/help/article/emergency-access/ https://bitwarden.com/help/article/emergency-access/
- joerickard 6y agoNice! I was already satisfied using Bitwarden, and now I will no longer have to manually manage my ICE backup. In the past I've kept an offline copy of my 'vault' on a few USB keys in a safe deposit, for my family in case of death or similar. I'm curious how others have solved this problem.
- NikolaeVarius 6y agoI have a similar and opposite problem. I would be fine with all my secrets dying with me, but what i want to protect against is me going into a coma/for some reason I forget how to access my accounts. How to securely manage it so that only I can open it if my biological self is there? I don't trust bank safe deposit boxes and I can't put a safe worth using inside my Apt. https://www.nytimes.com/2019/07/19/business/safe-deposit-box-theft.html https://www.nytimes.com/2019/07/19/business/safe-deposit-box...
- ibejoeb 6y agoPerhaps just an old ipnone or android with a fingerprint sensor and another installation of bitwarden. You can keep the phone's passcode written down because its only use is to start the device. Then configure biometric log-in for bitwarden as an alternative to a distinct passphrase. In the event of a total blank, you should still have access as long as you retain a finger.
- jbverschoor 6y agoRequires a passcode before allowing biometrics
- chris37879 6y agoNot the person you responded too, but I imagine you could likely get a custom firmware to allow biometrics whenever, if you can replace the kernel, you can generally make the device behave however you'd like.
- ibejoeb 6y agoThat's why I said write down the passcode and keep it with the device. The device itself isn't important because you're not keeping anything on it. Bitwarden encrypts everything itself. To my knowledge, once you enable biometrics in bitwarden, you will not need to use the master passphrase.
- ahnick 6y ago
- shakna 6y ago> On confirmation, the grantor’s Master Key is encrypted using the grantee’s public key and stored once encrypted. Grantee is notified of confirmation. > When the request is approved or the wait time lapses, the public-key-encrypted Master Key is delivered to grantee for decryption with grantee’s private key. I'm not quite sure how I feel about the way they're doing this. Whilst this is a feature a lot of people desire, the way that they're doing it makes it feel like it would be impossible to verify that they're not storing your Master Key, or transmitting it to someone else - i.e. backdoor. At least, not with the level of detail I can find. [0] [0] https://bitwarden.com/help/article/emergency-access/ https://bitwarden.com/help/article/emergency-access/
- judge2020 6y agoI'm under the impression that the "encrypt master key with the receiver's public key" step is done on-client, so you could verify that the master key isn't being stored the same way you can very they're not sending the master key when logging into the web ui: looking at devtools and seeing everything that leaves the network.
- shakna 6y ago> I'm under the impression that the "encrypt master key with the receiver's public key" step is done on-client However, what would prevent them sending two public keys, one for your contact, and one for someone else? Or sending the wrong public key? How is the key exchange itself verified other than "Bitwarden user"? Those questions aren't answered.
- warkdarrior 6y agoThey are answered right in the help article: https://bitwarden.com/help/article/emergency-access/#confirm-an-accepted-invitation https://bitwarden.com/help/article/emergency-access/#confirm... "To ensure the integrity of your encryption keys, verify the displayed fingerprint phrase with the grantee before completing confirmation."
- tptacek 6y agoAm I reading it right that this allows people to designate access to their password manager via email? I feel like I have to missing something, like a previous step that fingerprints the emergency contact's key or something. (I get that we rely on email for stuff like this all the time, but your password manager is part of what protects your email account, which is why we rely on email as much as we do for resets).
- WatchDog 6y agoWhile I make heavy use of a password manager, I still choose to memorize my email password, and not store it in a password manager, precisely because it is is relied on so much, and can be used to reset the majority of the passwords stored in the manager anyway.
- Vaslo 6y agoI’m with you. I’ve memorized an odd password for entry into my Bitwarden and my ProtonMail account.
- isatty 6y agoFor very important passwords that are stored in a password manager, salting it with a memorized phrase is a good idea. That way, if someone gets access to my password manager, they still won't be able to access everything in there.
- dsissitka 6y agoThey encourage you to verify the grantee’s fingerprint phrase: > To ensure the integrity of your encryption keys, verify the displayed fingerprint phrase with the grantee before completing confirmation. https://bitwarden.com/help/article/emergency-access/#confirm-an-accepted-invitation https://bitwarden.com/help/article/emergency-access/#confirm... > The fingerprint phrase is an important security feature that assists in uniquely and securely identifying a Bitwarden user account when important encryption-related operations are performed (such as sharing). https://bitwarden.com/help/article/fingerprint-phrase/ https://bitwarden.com/help/article/fingerprint-phrase/
- aunlead 6y agoThe pandemic has made me (re)evaluate how my family can get to my finances and online services. Such solutions can solve issues related to bank/trading account access and key documents but what about subscription services? All my subscription services from Netflix/Plex (less important) to VPN/Blackblaze (more important) are tied to my credit cards, which upon my untimely demise will be deactivated. My family will surely get locked out if I don't leave clear instructions on each of the services and how they can access them, etc. Then there is a technical aspect of taking over these service. I'm curious on how others have planned around this? edit: typo
- gpanders 6y agoAfter my wife watched the show “Dead To Me” on Netflix, we had this exact same discussion. I ended up writing a “death document” on Google Docs and sharing it with her. It just outlines “here’s where everything is and this is what you do with it”. It was done kind of jokingly, but now that it’s written it actually makes me feel much better. For passwords and such, she has a Bitwarden account too and we share all important passwords (finances, medical, etc) in a shared organization between the two of us.
- bronco21016 6y agoFun story about shared passwords in Bitwarden... I recently had to undo that process because I’m going through divorce. We aren’t at the point of severing everything yet but my ex took the liberty of using the shared Bitwarden passwords to sign into each of the utility (gas, electric, etc) accounts and change the passwords. Thus locking me out. I had resisted doing anything with the shared passwords prior to this because the process to unshare an account is to delete it from the organization and make a new entry on your personal vault. Ultimately the blame is on me but the process for unsharing is broken. I guess the moral is to just be careful about sharing accounts in a BW org if you ever expect you might have to undo all of them. It was about 15 accounts in all because we had also shared everything related to financial institutions and health care. I did take the time to change each of them as well since there was no way of knowing what may have been copied.
- Barrin92 6y agoBitwarden is just fantastic. It's open source, the interface is clean, works fine on all platforms for me and pretty much everything is free. If the devs browse here, thanks for making it.
- opheliate 6y agoJust want to echo this. I've been using Bitwarden for about a year now, and a few months ago, my mum (not technologically literate) had her email hacked. Getting her set up with Bitwarden & teaching her how to use it was one of the easiest experiences I've had when introducing her to new software. Really well designed.
- ajh13 6y agoI recently set this up with my mom and dad too, and they have been enjoying the relief of only having to memorize one password. It is also much more secure since then their previous methods of reusing passwords.
- alexanderh 6y agoHow dependent is it on them as a service? If their website/service disappeared off the face of the earth tomorrow, would I still have access to my passwords locally? I'm still hesitant to use any form of password management that relies on cloud services. I still like Keepass (with auto-updates disabled for security because their updater uses HTTP, of course), for my purposes. I can Sync my keepass file any number of secure ways that don't rely on a single provider.
- bilange 6y ago> If their website/service disappeared off the face of the earth tomorrow, would I still have access to my passwords locally? They provide a selfhosted alternative to their cloud service. Not only that, there is a rust based birwarden server reimplementation that doesn't phone home (IIRC I believe the official self-hosted server needs an API key?), is compatible with all platform clients (at least for my needs). https://github.com/dani-garcia/bitwarden_rs https://github.com/dani-garcia/bitwarden_rs
- pndy 6y agoIt's a good application and service that offers much on free accounts "but": * there's still no way to keep fetching icons disabled across all devices and instances of bitwarden - each time I have to disable it; I just simply don't like such feature anywhere it's present * there's no emptying the trash on desktop client and neither in browser addon * logging in generates email on which your account is registered, which is a good security feature but sometimes it's just... annoying * import exist only in the web vault interface, while export is present on desktop application and web vault * despite of having vault unlocking to set with pin, I have to provide password Still, it's my secondary choice for less important passwords for sites and apps since it works nicely on mobile and isn't limiting features like Enpass which is my main password manager.
- croon 6y ago> * despite of having vault unlocking to set with pin, I have to provide password You can configure how it locks upon close.
- hehehaha 6y agoI am not so sure about this. I think they should certainly allow emergency access to shut down all access but not necessarily give access to a trusted party. Life can change quite unexpectedly.
- dastx 6y agoAnd you still can't use Bitwarden in Firefox's private mode.
- dastx 6y agoNot sure why I'm getting down-voted. It doesn't work in Firefox's private mode. Nearly 4 years after the issue was raised. It was completely dismissed as "something Mozilla needs to fix" on multiple occasions.
- ssklash 6y agoIt works, but you need to right click the field you want to fill and mouse over to Bitwarden.
- jrib 6y agoIt's working fine for me here (Firefox private window on OSX). I did have to go to the extension's settings and enable "Run in Private Windows".
- latchkey 6y agoJust a friendly reminder that DMS is an excellent service as well. Just PGP encrypt a message and it'll get emailed out if you don't click a link on a set period. It is a painfully simple and inexpensive service. https://www.deadmansswitch.net/help/ https://www.deadmansswitch.net/help/
- michaelmior 6y agoLastPass has had a similar feature for some time now. https://support.logmeininc.com/lastpass/help/set-up-and-manage-emergency-access-lp030013 https://support.logmeininc.com/lastpass/help/set-up-and-mana...
- dalrympm 6y agoI'm really happy to see this come to BitWarden. I switched from LastPass to BitWarden and this Dead Man's switch was the only thing I found missing. I actually kept my LastPass active just to provide instructions on how to get into my BitWarden in case of an emergency. I'm still not clear if both the granter and grantee need to be premium/paid subscribers or not. Hopefully I can grant emergency access to someone without a paid subscription... I guess I'll find out when I dig into it over the weekend.
- WhiteListed 6y agoI (premium user) have just tried this with my girlfriend (free user). I can add her as a emergency contact and she can accept that. But she cannot add me as an emergency contact since it is a premium-only feature.
- brigandish 6y agoJust a thought after having read through the comments, not all emergencies are the result of death, and, since pretty much any textual information can be stored in a Bitwarden vault, the kinds of emergencies could vary widely. A well-thought out use of the share/collection features might mitigate a lot of "emergency" situations though. I do, however, look forward to the clichéd "you had her change the will just days before her death" in murder mysteries being replaced with "you signed her up for Bitwarden's emergency access just days before her death"…
- olah_1 6y agoThis is timely considering Vitalik’s vocal support for Social Account Recovery: https://vitalik.ca/general/2021/01/11/recovery.html https://vitalik.ca/general/2021/01/11/recovery.html It’s personally something I love to see.
- vaidik 6y agoSo useful. I have been wanting this feature.
- SubiculumCode 6y agoI use Lastpass, but I'm no longer a fan. So I am considering Bitwarden, but was wondering: What does this afford me that the built in Firefox password manager does not? Firefox now provides a method to generate passwords. Is there something else I am missing?
- njsubedi 6y agoI’m also looking to move away from LastPass. Dropping this comment to get notified of replies.
- nichos 6y agoI switched from the Firefox password manager to bw a while ago, but at the time, Firefox didn't allow multiple users to share passwords (organizations). I share some passwords with my wife, that was enough to switch.
- warkdarrior 6y agoThe built-in Firefox password manager does not work with other browsers (kind of obvious, no?). I use different browsers on different devices, and Bitwarden just works on all of them.
- croon 6y agoPassword fill for every other app on your phone, and just generally decoupled from your choice of browser.
- franky47 6y agoAn alternative way to restore access to an E2EE app account could involve Shamir's Secret Sharing, I wrote some ideas about it would work: https://francoisbest.com/posts/2020/password-reset-for-e2ee-apps https://francoisbest.com/posts/2020/password-reset-for-e2ee-...
- starfox64_ 6y agoUnless I'm reading this wrong, this lacks a lot of granularity. I'd like to be able to only give access to a subset of my vault, not all of it. I'm of the opinion that my accounts should just disappear with me, apart for some things related to real life like utilities and the likes. Come to think of it, my GitHub account could be worth preserving too but right now I can't think of much else being worth it.
- Terretta 6y agoHere’s a list of password managers: https://en.wikipedia.org/wiki/List_of_password_managers https://en.wikipedia.org/wiki/List_of_password_managers It has a column for Secure Sharing, but not one to show granularity. Ones that make organization easy seem to choose to offer persistent sharing at the vault level (multiple vaults shared to nobody or to different sets of people), easy ways to move items between vaults, and flagging if you have multiple or OOS copies of items. Careful, most seem to offer per-item share-as-a-copy that the recipient should store, which I wouldn’t consider as counting as the kind of sharing needed for this thread.
- tweetle_beetle 6y agoMy dad set me up with the equivalent feature to this on Dashlane. But it involved downloading their desktop app, which has all the usual anti-user behaviour - automatically adding to startup list, minimising to taskbar on quit, self updating without request, etc. So I ended up uninstalling it. I hope that I get an email notification, or I find out through other offline means, if the feature ever gets activated. I hate that something which could have a significant impact on my life, potentially at a difficult time, appears to require running crapware on my own computer.
- dspillett 6y ago> Dashlane ... their desktop app, which has all the usual anti-user behaviour They are going "web first" and eventually deprecating the desktop app, so you are going to need to reengineer that solution at oe point soon.
- tweetle_beetle 6y agoAppreciate the tip-off