10 ms·
I really dislike the idea of giving complete access to my digital life to any company, particularly one that needs to grow quickly. The tech for password vault
by obblekk 4y ago
I really dislike the idea of giving complete access to my digital life to any company, particularly one that needs to grow quickly.
The tech for password vaults is so simple, I use keepass + icloud syncing and get free end-to-end encrypted password syncing, without sharing any data with anyone.
Outlined in more detail here: https://magoop.substack.com/p/how-to-manage-500-passwords-securely https://magoop.substack.com/p/how-to-manage-500-passwords-se...
- Biganon 4y ago"I don't want my encrypted passwords on Bitwarden's servers. I'm OK with having my encrypted passwords on Apple's servers."
- hn92726819 4y agoDifference, of course, being that keepass kdbx is offline and not dependent on any particular online service. If apple gets too greedy with iCloud, you can sync your kdbx with 1000 other clients.
- d1lanka 4y agoSame here. KeepassXC to be specific: https://keepassxc.org/ https://keepassxc.org/
- sakopov 4y agoAgreed. I use keepass + dropbox secured with yubikey. You can even go a step further and configure yubikey with keepass as well.
- anonkogudhyfhhf 4y agoWhere about on mobile?
- velhartice 4y agoStrongbox for iOS.
- artificial 4y agoRight on, thank you!
- sakopov 4y agoI believe KeepPassDX on android supports yubikey via NFC.
- advisedwang 4y agoI do this, but have started using Syncthing [1] for sync instead of a cloud service. [1] https://syncthing.net/ https://syncthing.net/
- thefz 4y agoBitwarden is built as a zero knowledge platform and they can't access the contents of your Vault.
- RadiozRadioz 4y agoSo is LastPass, but we users changed our passwords in December anyway as a precaution. Bitwarden is still a central entity that needs to be trusted to manage the zero knowledge platform with competence, e.g. not storing unencrypted metadata in a backup.
- panarky 4y agoBecause LastPass is a bad actor that falsely claimed to have a "zero knowledge architecture" that couldn't be compromised if they were hacked, and kept their code secret so nobody could independently assess their implementation, and then proceeded to store critical user data unencrypted, which was promptly hacked and leaked, that means the risks must be identical with Bitwarden, which publishes client and server code in public, so anyone can inspect their implementation.
- LelouBil 4y agoThey cannot store unencrypted data because the whole vault is encrypted client side. And thats verifiable because their clients are open source.
- RadiozRadioz 4y agoThat specific fault applied to LastPass, I used it as an example of a flaw in a system advertised as zero knowledge, to demonstrate that not all systems are created equal. It is true that BitWarden's Open Source nature helps prevent silly things like that. You raise a good point that their open source clients are _verifiable_, but they're not often _verified_. I'm certain that you verify the checksums of all your updates or exclusively build from source, but the distribution channels on most platforms encourage users to trust updates from BitWarden inc. If those channels are compromised, most users are one unchecked automatic Play Store update away from a problem. Not disagreeing, just noting that Open Source is not a silver bullet given BitWarden's default architecture is centralised web service with centralised client distribution channels.
- TillE 4y agoBitWarden doesn't get "complete access to your digital life", they get an encrypted blob. It's not materially different than storing your KeePass vault in the cloud.
- mort96 4y agoThere's still trust there. You're writing the key to decrypt everything into their web interface if you ever use it (vault.bitwarden.com). If they wanted, they could really get access to everything in your bitwarden vault.
- dcow 4y agoThat's why open source is important. You can audit them and verify that they are behaving in a trustworthy manner.
- Kimcha 4y agoNot if you are using their cloud version instead of the open source self hosted server. The code they are running does have to be the code they are publishing. And if someone compromises their cloud servers, they could also modify it to log the passwords entered.
- tracker1 4y agoThen host your own.
- dcow 4y agoYes we can degenerate into inordinate amounts of rabbit holes. For 1, you can audit the JS that runs on your browser, it's not hiding (so it's not strictly fair to say that just because you loaded a webpage in your browser from their server it can't be trusted). And anyway, generally, your argument holds for any software interaction ever. GH doesn't have to ship you the repo that you browsed on the web client. A malicious actor could have compromised their infra and be serving fake code in the web UI but have added all sorts of malware to the stuff you download. Apple app store doesn't eve ship you the exact binary the developer uploaded. Scary. At some point you have to decide which threat vectors you actually care about. Give me a scenario and I can tell you how someone can theoretically attack it and why you're not safe. The only thing you can be 100% sure about is manually auditing every single release at the source level and building it yourself.
- waymon 4y agoI used to do this. Now I self host vaultwarden since it allows me to use that database with faceID. Can keepass do that?
- IronWolve 4y agoI like keypass, but merging my android and pc versions every so often is a task I'd like to automate. I dont do google/apple cloud so avoiding that.
- hoboris 4y agoI use the Strongbox iOS client. It reads .kdbx files, integrates with apple sign-in features, and supports faceID. https://apps.apple.com/us/app/strongbox-password-manager/id897283731 https://apps.apple.com/us/app/strongbox-password-manager/id8...
- dicknuckle 4y agoI use the Keepass2Android and it integrates with the OS fingerprint reader, so it's likely the same for faceunlock but I don't use that.
- manmal 4y agoServices like 1Password are often more secure than your solution because they need to harden vaults against full leaks. In the case of 1Password, a secret key in addition to the password ensures that brute forcing is (at the moment) not feasible, even if your password is really crappy.
- notesinthefield 4y agoKeepass has Key Files as a part of the spec https://keepass.info/help/base/keys.html https://keepass.info/help/base/keys.html On my devices, keyfiles and a KP client are stored locally. The DB rests in the cloud.
- manmal 4y agoIs that kind of file storage secure? I thought files stored on disk can be extracted quite easily?
- brandon272 4y agoLastPass would have also led their customers to believe that "brute forcing was not possible" and that they were taking extraordinary measures to keep vaults and data safe. I think one distinction between services like KeePass and 1Password is end user perception of how easy it is for an attacker to acquire an encrypted vault to begin with. For many, they consider a KDBX database sitting in their Dropbox account to be less likely to be stolen than an encrypted vault being held by a company like 1Password, a high value target to the most sophisticated attackers including state actors.
- hn_throwaway_99 4y agoDoesn't necessarily matter what LastPass "would have also led their customers to believe", the mathematical reality is still that LassPass vaults are crackable in a way that 1P vaults fundamentally are not.
- brandon272 4y ago
- stavros 4y agoI kind of want to point out the discrepancy in saying "I get syncing without sharing my data with anyone by sending my password database to Apple". If your argument is that the database is encrypted, how is Bitwarden different?
- dcow 4y agoWhat this highlights in my humble opinion is that many users seek security signals and are less concerned with the actual security implementation. In the password management space, the signals are "local vault", and "not VC backed", at least on HN. It's quite odd since you'd think people would be more concerned with the application architecture, key derivation, key transport backup and recovery, etc. But it seems security is more synonymous with "company doesn't store my vault on their servers" than it is with "company helps me securely encrypt my passwords".
- zmxz 4y agoBitwarden can be self-hosted, it's fully open source so you can be safe that way, never giving a single byte to the company. Do you have a browser extension that offers username/password autofill using keepass as datasource or do you alttab copypaste / rely on a program made by someone else to clear your clipboard?