27 ms·
Bitwarden Acquires Passwordless.dev
- srigi 4y agoThe idea of FIDO2 with HW tokens is great, but not practical if you don't own atleast 2 pieces: - one constantly inserted into main working machine - second somewhere with the keys, ready to be used on other devices You should be having third one - backup token stored securely in the safe or vault. That is $150 investment just to do it right. And then - not all webapps allow to register more that one FIDO2 device, which totally cancels the above best practises.
- jlundberg 4y agoAnd here is a link to the web site of this startup: https://www.passwordless.dev/ https://www.passwordless.dev/ Anders Åberg (@andersaberg) who is the founder behind this is a really enthusiastic and inspiring coder. I've always enjoyed his mashup hackathon ideas and meetup presentations. :-)
- jlundberg 4y agoFor those curious, here is another fun project Anders has built in which he mix ambient music with live radio broadcasts from airports :) https://listentothe.cloud/ https://listentothe.cloud/
- fantalamera 4y agoAnders is amazing!
- xwowsersx 4y agoCould someone clarify what the relationship between passkeys and WebAuthn is? Is it that Passkey is the Apple, Google, Microsoft implementation (commercialization?) of WebAuthn? If so, does it add anything on top of WebAuthn that makes it differ in some fundamental way? Also, are passkeys how WebAuthn is most commonly actually used in practice? Apologies for the noob questions.
- snagg 4y agoWe wrote a long post on Passkeys, in particular how they are implemented by Apple[0] that might be interesting. Technically a Passkey is just a multi-device FIDO credential that is compatible with WebAuthn (which is an official W3C and FIDO spec). However, vendors implementations of Passkeys/FIDO credentials differ quite widely. The Apple implementation of Passkeys, as an example, doesn't provide attestation information which reduces the ability to do device verification. Similarly, even though it's not technically part of Passkeys, Apple removed the possibility to create device-bound WebAuthn keys which significantly weakens the security guarantees you'd normally get with WebAuthn. [0]https://www.slashid.dev/blog/passkeys-deepdive/ https://www.slashid.dev/blog/passkeys-deepdive/
- xwowsersx 4y agoThis looks great, thanks for the link
- snagg 4y agoHappy to chat more about it if you'd like!
- PassageNick 4y agoThat's a great article, thanks. In fact, it's a fantastic article. I read it a couple of weeks ago, and learned a lot. Thanks. Apple's changes do degrade security, but I think it is important to note that even with those degradations, Apple passkeys are still many orders of magnitude more secure than passwords.
- snagg 4y agoThank you! 100% agree - realistically, given their scale, the tradeoff made sense. The UI would have been fairly un-intuitive for users had they left the option to do both device-bound keys and passkeys.
- jlundberg 4y ago
- AdmiralAsshat 4y agoAs a recent convert to Bitwarden from LastPass, I start to get a bit nervous when I see acquisitions happening. LastPass getting acquired was the beginning of the end for it, IMO, before stagnating into criminal negligence. Granted this is Bitwarden acquiring rather than being acquired, but I still worry it leads to a trend of building "portfolio value" rather than focusing on the product. I sincerely hope I'm wrong.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- allochthon 4y agoI had a similar reaction. Acquisitions can be a signal that there's a go-to-market strategy being pursued.
- gagabity 4y agoAlso Bitwarden recently raised 100M from VC so yeah, the clock is ticking now.
- afavour 4y agoThey did? Oh JFC I just switched from 1Password to avoid using a VC backed service. At least there's always Vaultwarden, now all I need is a service I can pay to host an instance for me. ...and to not take VC funding. https://github.com/dani-garcia/vaultwarden https://github.com/dani-garcia/vaultwarden Though I fear it’s only a matter of time before the VC gods demand the client apps remove compatibility and they have to be forked too.
- Jack5500 4y agoSlightly offtopic, but I really find the Bitwarden Clients to be lacking in the feature department. I switched to Bitwarden a few month ago and the client has evolved (for me) ever since. There are a few basic features missing, such as that if I search for something I wrote in the notes of password, that the client shows the according password. I get that the open-source model implies that everyone can contribute and fix this issue, but if I look at the repo and see 108 open PRs, I don't even bother to check if that's a feature that would be easy to add.
- cryptos 4y agoI tested Bitwarden recently and found the UX really disappointing. Some basic operations are so counter intuitive that I felt completely lost. This is definitely not the application I would recommend to non tech-savvy people. 1Password has much smoother UX.
- temeritatis 4y ago> There are a few basic features missing, such as that if I search for something I wrote in the notes of password, that the client shows the according password It might be that your search term is a partial of a word. This is fine when searching some fields, but for finding entries with that word in the notes section, the search term needs wildcards. You can read more about it here: https://bitwarden.com/help/searching-vault/ https://bitwarden.com/help/searching-vault/ But to paraphrase: "notes: Item's notes. Only full-word matches will be listed unless you use wildcards." Hope it helps.
- shantnutiwari 4y agoyeah, for me the Bitwarden iphone app doesnt support Touchid, which means I have to enter my password everytime. 1Password does, and is much easier to use (though I use both)
- Corrado 4y agoI don't know about Bitwarden supporting TouchID, but it does support FaceID.
- 4y ago
- Jsharm 4y agoWow this is really cool. I just tried the example on the homepage, that's magic! No email, username or password. Can someone explain what is happening?
- rgrmrts 4y agoA new private-public key pair is generated, the public key is your user identifier (sort of), and the private key is stored on your device (browser or phone). You're logging in by proving you have the private key for the associated public key. I think the device may also be storing a mapping from key to service or something? Not sure. Please correct me if I'm wrong on any of this.
- medstrom 4y agoFrom my loose skim, this seems to be more for UX than anything else: no-clicks account creation and no-clicks login, but there's still account creation and login happening, presumably with a key provided by BitWarden. But websites can start removing the login prompt as an entity to be interacted with.
- antihero 4y agoOn iOS this seems to use the iCloud Keychain which is slick but how would I then login to sites using Firefox or any computer that doesn’t have access to my keychain? The reason I use a 3rd party manager is precisely this reason.
- WorldMaker 4y agoSites should likely let you enroll multiple such passkeys from different vendors (add a Microsoft Account passkey from your PC, a Google one from your Chromebook, etc). Apple already supports Keychain sync with Edge on Windows and I believe that already supports Passkey access. Also, I believe I heard rumor that "Sign in with Apple" (their existing OpenID Connect account system) will also eventually support helping you enroll non-Apple devices to Passkeys in apps that support both Passkeys and "Sign in with Apple", though I don't know if there is yet a timeframe on that sort of support.
- ohCh6zos 4y agoI’m highly skeptical of Passkeys/Webauthn as it would seem to not have the same legal protections that a password has in the US. Maybe this is me becoming a conspiracy theorist.
- qzx_pierri 4y agoI’m in the same boat. Using Passkeys gives the user less control. The last thing I need is another layer of complexity when dealing with credentials. This seems like a solution created for people too lazy to generate and track secure secrets (using a password manager). It also seems like a way companies like Google would lock people into their browser.
- 9dev 4y agoWell, passkeys come with another very interesting property: they make it entirely useless to obtain the database of user credentials from services. It only contains public keys specific to a single service, so you cannot use them anywhere else. Additionally, private keys are stored on secure storage in client devices (or need to be decrypted themselves using a second factor), so there’s pretty much 0% risk of mass credential leakage.
- secabeen 4y ago> they make it entirely useless to obtain the database of user credentials from services. It only contains public keys specific to a single service, so you cannot use them anywhere else. This is also the case for anyone using unique passwords per site, which is the standard for password vault users. Not much of a win there. > Additionally, private keys are stored on secure storage in client devices (or need to be decrypted themselves using a second factor) Also exactly the same as password vaults, but we still stress about Lastpass losing their encrypted vault DB. I agree that Passkeys appear to bring the benefits of Password Vaults to people not currently using them in a fairly easy way. However, I worry about access to those passkeys when access to the Passkey provider is lost/revoked.
- 4y ago
- judge2020 4y agoThis seems a bit odd to me - is setting up WebAuthn in your main backend so hard that an external service like this for validating credentials is required?
- cormacrelf 4y agoQuoting the docs: it’s “WebAuthn - without reading the w3c spec”. So apparently yes. It does seem very silly that this has to be a third party service instead of open source code you just plug in to Rails or whatever. I guess they had to find some way to get paid for all the expertise they accumulated. Stuff running on external servers is the way tech companies as a whole have decided to remunerate work like that, and now everything looks like a nail. I note that since logging in is such a crucial part of online business, running consulting around open source software would appear to be a a good model. That’s what the people behind the C# OAuth2/OpenID code known as IdentityServer do.
- 9dev 4y agoI recently implemented WebAuthn for a toy project, and while it took a bit to wrap my head around the details, it’s fairly straightforward if you know the problem domain a bit. I’d say we’re going to see polished libraries soon that will abstract all the details away, but services like this may help less experienced developers to quickly get secure auth working.
- boringg 4y agoIs this the password wars heating up? I.e. Bitwarden vs 1Password?
- wurstehans 4y agoSounds a bit worrisome to me… Maybe I'm just overly cautious, but i guess it's time to look around again. Has anybody checked out APass yet? https://github.com/balu-/a-pass https://github.com/balu-/a-pass
- coffeeri 4y agoWithout looking close at your suggestion, you might want to look at passage [0] by the creator of age. It's a fork of pass [1] using age as the backend. [0] https://github.com/FiloSottile/passage https://github.com/FiloSottile/passage [1] https://passwordstore.org https://passwordstore.org
- seanw444 4y agoFor my personal passwords and general secure info (it can store notes, files, and TOTP as well), KeePass(XC/DX) has been my password manager of choice. Nothing leaves your device. If you want it to, that's considered out-of-scope, and you have to handle syncing yourself. Whether that be something like Nextcloud, or my personal favorite: Syncthing.
- mtgx 4y ago[dead]
- zackify 4y agoI own passwordless.app. I wonder if they will want to buy it from me now.
- temptemptemp111 4y ago[dead]
- ubermonkey 4y agoYeah, this is not a good sign IMO.
- tr33house 4y agoI like where passwordless.dev is going. However, I don't think I'd like to build a business on top of that. Is there a similar implementation that's open-source that doesn't depend on a third party?
- jaywalk 4y agoYou can do all of it yourself, it's all based on open standards. Their value proposition is that by paying them, you don't have to DIY.
- jlundberg 4y agoThe core technology behind passwordless.dev is actually open source. https://github.com/passwordless-lib/fido2-net-lib https://github.com/passwordless-lib/fido2-net-lib
- jacooper 4y agoI still don't understand how it works. I went into the website under authenticated using my phones API, where is my account now? There is nothing in my Bitwarden vault.
- g_p 4y agoPasskeys are stored on your platform keychain. In time, Bitwarden will offer this interface up, so you can sync them through your Bitwarden vault. Currently, if you use an iPhone, you will have the passkey stored in iCloud keychain. Your "account" is a private key held within iCloud keychain, along with some metadata mapping that private key to the site you visited.
- jacooper 4y agoWell I use GrapheneOS without a Google Account. Its not listed under secure keys in the settings or in the browser. Anyway this really needs to be exportable, otherwise its in the ultimate platform lock.
- penciltwirler 4y agoOne can easily self host a bitwarden server on digitalocean. https://bitwarden.com/blog/digitalocean-marketplace/ https://bitwarden.com/blog/digitalocean-marketplace/ However, I'm curious what y'all think about the cost. A digitalocean droplet for the recommended specs (4 GiB memory) is $24/month. This is hard to stomach when you compare with Bitwarden Premium which is <$1/month. I guess it depends on how much you value your own data.
- attentive 4y ago1. oci has free ARM instances. 2. you don't need much server hw for vaultwarden 3. you don't need a server for keepassxc
- jeroenhd 4y agoYou can run the open source VaultWarden server (https://github.com/dani-garcia/vaultwarden https://github.com/dani-garcia/vaultwarden) on way slower hardware. It takes a while for the project to catch up in terms of API support compared to the official server, but it's great for self hosting.
- sodality2 4y agoHighly recommend using Vaultwarden, API compatible OSS server. It even provides premium features like TOTP for saved sites. I could host it on a small $12/yr VPS but currently host it on a home server. Minimum specs are very low for it as it’s written in Rust. DO inflates prices for their systems, sometimes I guess it’s worth it but you can get a great dedi with FAR better performance from Hetzner auctions for $32/mo. 64GB RAM, proper CPU, large HDD, could probably host a thousand Vaultwarden instances. Definitely don’t use that for just Vaultwarden, it’s just an example, but yeah.
- wallmountedtv 4y agoYou can use vaultwarden, which is a re-implementation in Rust that is much more lightweight than the official .NET version.
- metaltyphoon 4y ago
- obblekk 4y agoI really dislike the idea of giving complete access to my digital life to any company, particularly one that needs to grow quickly. The tech for password vaults is so simple, I use keepass + icloud syncing and get free end-to-end encrypted password syncing, without sharing any data with anyone. Outlined in more detail here: https://magoop.substack.com/p/how-to-manage-500-passwords-securely https://magoop.substack.com/p/how-to-manage-500-passwords-se...
- Biganon 4y ago"I don't want my encrypted passwords on Bitwarden's servers. I'm OK with having my encrypted passwords on Apple's servers."
- hn92726819 4y agoDifference, of course, being that keepass kdbx is offline and not dependent on any particular online service. If apple gets too greedy with iCloud, you can sync your kdbx with 1000 other clients.
- d1lanka 4y agoSame here. KeepassXC to be specific: https://keepassxc.org/ https://keepassxc.org/
- sakopov 4y agoAgreed. I use keepass + dropbox secured with yubikey. You can even go a step further and configure yubikey with keepass as well.
- anonkogudhyfhhf 4y agoWhere about on mobile?
- velhartice 4y agoStrongbox for iOS.
- StreamBright 4y agoI am not sure how much is this better than magic link logins.
- 8organicbits 4y agoMagic links via email? Email isn't a secure transport, or storage. I think that's only viable for low risk systems. Even software like Slack, which supports magic links via email, will also support username/password/MFA as an option for folks who need better security.
- StreamBright 4y agoDepends on the implementation. Most email servers use TLS and strong authentication, but I understand there are email providers without those.
- 9dev 4y agoIt’s about a bazillion times less annoying?
- ithkuil 4y agoThe demo on the homepage is available only on chrome. I tried both safari and firefox on macos and I can't see the " Experience Passwordless.dev in action" link there.
- jlundberg 4y agoWorked for me in Safari on macOS if you have iCloud keychain activated. Or more correctly: I got so far but stopped because I prefer to have my keychain locally :)
- Jerrrry 4y agoYour passwords shouldn't leave your device. Chrome's password manager is pushing it. Everything else should be considered malware. I don't understand how such a 'techy' crowd here on HN can be so belligerent with this security vs convenience trade off. KeePass locally, gmail yourself an encrypted backup. That's it. FFS.
- eli 4y agoHow is "gmail yourself an encrypted backup" fine but "store a copy of the encrypted vault in a cloud service designed for this purpose" not?
- Jerrrry 4y ago>"designed for this purpose" I know my blob is encrypted, because I did it. Did you audit your password manager's source control? No? That is the difference.
- Accacin 4y agoI'm surprised someone as techy as the parent even uses Google if I'm honest.
- Jerrrry 4y agoBecause the amount of effort required in avoiding them is a signal stronger than the noise of appearing normal. Google is just as powerful as state actors, the same rules apply. Don't stick out.
- ffstroll 4y agoOne is an encrypted blob in the cloud, the other is an encrypted file in your email in the cloud. That’s it. FFS.
- thesh4d0w 4y agoIf the key to decrypt the vault never leaves your device, then the security implications are minimal. Well worth the convenience in my eyes, and many others apparently.
- heresjohnny 4y agoInteresting demo. What happens though if the device holding the private key is lost? Or Apple decides to shut down your iCloud? Is there a backup option, similar to backup codes for OTP?
- smileybarry 4y agoI wonder how iCloud shutdown would affect this route, but: your Passkeys are synced to your devices locally, and the whole "scan QR code on another device with your phone to authenticate" flow is fully local, utilizing key authentication over BLE. Theoretically, your Passkeys should still be on your iPhone/iPad/Mac/iThing, and QR authentication will work. (And then you provision another key on another device, since Passkeys' intention is like SSH keys, allowing multiple on a single account)
- echeese 4y agoProbably the same thing that happens when you forget your password. Hit the "forgot your password" link, get a confirmation email, create a new passkey
- WorldMaker 4y agoJust like TOTP (used for most 2FA) the best practice for websites accepting passkeys will be to support as many passkeys as you wish to enroll. So you could enroll into your account some device associated with your Apple ID and some device associated with your Microsoft Account and some device associated with your Google Account and some browser associated with your Firefox Account and use any of those for recovery. Unlike TOTP, the base case for passkeys is multiple key enrollment so websites are more likely to support it well whereas with TOTP so many implement it as having one-and-only-one TOTP configured. Even when enrolling just a single device that device generally enrolls a small key-chain, not just a single key, because that's how recovery systems work even for using just a single "owner" account. Plus most people use 2 or more devices regularly and Passkey has to work with that. So much more websites in practice should actually support N passkeys where N > 1 (versus half-baked single-option-only TOTP implementations). At least in theory, in practice we'll see how well Passkey gets implemented at large, there's always lots of ways for companies to get practice wrong.
- DangitBobby 4y agoAnyone know how Bitwarden fits into the "passwordless" equation here? I tried to log in to Dogwarden (shown in the video demo on passwordless.dev), but the Bitwarden extension/app doesn't seem to do anything during sign-up. Also wondering if anyone knows why this device [1] doesn't work during the "passwordless" sign-up/sign-in process on dogwarden1.passwordless.dev. Am I going to have to buy yet another hardware key if I want passwordless logins? 1. https://www.amazon.com/gp/product/B0773YLSY5/ https://www.amazon.com/gp/product/B0773YLSY5/
- jeroenhd 4y agoMy current setup uses Krypt.co (deprecated) to forward most U2F/FIDO2 requests to an app on my phone. The app has some keys stored in my phone's secure secret storage and verifies/signs the request (after unlocking my phone with biometrics or my phone's PIN). This signed response is then used to log into the website. I believe the goal for Bitwarden would be the same, to allow for seamless login through a secondary device using WebAuthn and friends. Apple and Google are already working on cross-device FIDO2 login support, but for Firefox I haven't seen much announced as of yet. Bitwarden filling in for Apple's/Google's proprietary services would be a way to log in securely without giving up even more security features to browser companies.
- _8j50 4y agoPasswordless as a concept needs to die along with biometric auth. You have really good newer methods of auth. Instead of selling them as good MFA alternatives security vendors decided to replace passwords because that differentiates them more. But in reality, the layer of defense "what you know" should be complemented not replaced. A reduction in security being sold as a feature is dishonest and harmful.
- jaywalk 4y agoPlease explain how this is a reduction in security.
- hsdropout 4y agoThey are pointing out that while the "something you have" factor may be stronger than "something you know", multi factor is still better. I agree. Also, passwords are decentralized, whereas passwordless puts the power into fewer hands, so this too reduces complexity for attackers. 2FA>1FA
- PassageNick 4y agoThe threat surface of a password based system is like Lake Superior. The threat surface of a passkey based solution is like a small puddle after a rain. How is there a "reduction" in security here?
- _8j50 4y agoDoesn't work that way. Passwords are inferior but still a strong layer of defense. You are putting all your eggs in one basket again. The lesson from passwords is that a single factor of authentication is inherently inferior to multiple factors of authentication. From a threat actor's perspective, even a yubikey is a matter of one well planned attack (physical, compromised host,etc) and by nature newer factors of auth don't get treated with hostility like with passwords. They are better than passwords but what I see is people moving away from MFA to only a yubikey for example. Like you are now one lost yubikey away from your whole company getting owned lol.
- moneywoes 4y agoAny idea on the multiple?
- velhartice 4y agoI’ve been using the keepass ecosystem for years after switching from 1password. It’s open source, highly portable, and you don’t need a degree to set it up.
- cryptos 4y agoYes, but password sharing in a team is no fun. You could use a completely separated password file, but then you might end up with a lot of password files with different passwords that need to be managed in another Keepass file. In theory there are child databases in Keepass, but using them with different clients and cloud sync never worked for me.
- attentive 4y agoNot everybody needs password sharing in a team. It's bad security practice anyway.
- Reptur 4y agoI'd like to see a video on how losing your device and recovery of the account works with Passwordless.
- Ajedi32 4y agoNot sure if this is new information or not, but this post mentions that Bitwarden is planning to support passkeys starting in 2023. That's great, since AFAIK all existing passkey implementations are tied to a specific browser or OS, and have no way to export the keys, which isn't great for a program designed to own the keys to your digital life. I'm hopeful Bitwarden will solve that problem, and that their example will encourage other popular password managers to do the same. (...or at least, I think "passkey support" means they plan to support storing passkeys in Bitwarden itself. I hope it doesn't just mean they want to let you use a passkey to log in to Bitwarden. That'd be really disappointing, and probably a poor choice strategically given that passkeys aim to eventually render traditional password managers obsolete.)
- noahtallen 4y ago1Password is also working on it: https://www.future.1password.com/passkeys/ https://www.future.1password.com/passkeys/ It’s shaping up to be a cool year for password management!
- cmdli 4y agoShameless plug to my own passkey manager, which is 100% open source: https://bulwark.id https://bulwark.id One of the big challenges to passkeys right now is that they aren’t as versatile as passwords, but this doesn’t have to be the case. Passkeys should be able to be exported and stored anywhere you want (ideally in an open source solution). Bulwark Passkey supports that right now, but I’m glad that other products are also providing solutions to users for the same problem.
- wkat4242 4y agoThe problem is that big companies don't want them to be as versatile. They don't trust us to manage our credentials. Hence FIDO2 and Passkeys feature 'attestation' that allows them to only accept 'trusted' implementations. This accreditation is a crypto process so it can't be faked. So, you can't just put your keys in any app you wish, like you can with TOTP. There will be strong pressure to just 'go with the flow' eg mainstream OS implementations and us with niche OS or cross platform requirements will be ever more marginalized. Any complaints will be simply rebuked with "For security reasons" or "We only certify implementation X, Y and Z". My work is already doing this, they only support Yubikey and one other brand through their Identity Provider, if you have one of the open source tokens you're straight out of luck. Passkeys don't work yet either but I'm sure they will only 'certify' Apple and Microsoft and leave the rest hanging. They love quoting the pareto principle / 80/20 rule as an excuse.
- ajcoll5 4y agoWould have preferred to see the cash used for this to be used for things like app QoL improvements, an actual code audit (not just the basic network security assessments they list), or offer actual bounties for their bug 'bounty' program.