12 ms·
Bitwarden adds support for passkeys
- traviswt 3y agoBitwarden is underrated. Passwords run everything in our digital life. I will gladly take a UI compromise here and there for more trustworthiness.
- corytheboyd 3y agoI don’t even mind the UI honestly. It works. Some annoying UX here and there, but I can live with that. I happily pay for a subscription to support them.
- ramenmeal 3y agoI moved over from Lastpass, I find the experience of filling in a password in Bitwarden more jarring/slow than in Lastpass. I'm not sure what it is, maybe Lastpass had longer timeouts to require FaceID when filling a password? Bitwarden requires it every time.
- barbazoo 3y agoCan you compare to 1Password?
- ramenmeal 3y agosorry, no experience with 1password
- jorvi 3y ago1Password is very trustworthy too. They get audited frequently, and their db file format is open source (meaning you can write a 3rd party tool to decrypt them). With UI/UX they are lightyears ahead of Bitwarden. I want to like Bitwarden, but when your application doesn’t even support extremely basic stuff like drag ‘n drop, I’m gone. In general they also support newer tech much faster. And their secret key system is more secure than Bitwarden’s password-only method.
- lxgr 3y ago> With UI/UX they are lightyears ahead of Bitwarden. 1Password is arguably moving backwards these days, UI-wise. I don't know if it's caused by the Electron update or just coincided with it, but I've been finding the keyboard autofill shortcut as well as keyboard navigation for selecting a given login on a page very unreliable lately. That said, 1Password's "auto-rotate password" feature is still ahead of the competition, though. Bitwarden doesn't even seem to try, but that's still better than LastPass, which reliably used to lock me out by irrevocably overwriting the old stored password before the website confirms the new one as having been accepted. > their secret key system is more secure than Bitwarden’s password-only method. I don't know, their security key mechanism seems to be getting weakened in the interest of convenience as well. I was recently very surprised to notice that the iOS client apparently synchronizes the security key for any logged-in vault to iCloud Keychain, with no way to opt out – even for enterprise vaults! Bitwarden will also soon support the WebAuthN/CTAP2 "PRF" extension, which is even better than a static security key since it rotates with every vault unlock.
- TheNewsIsHere 3y ago> > their secret key system is more secure than Bitwarden’s password-only method. > I don't know, their security key mechanism seems to be getting weakened in the interest of convenience as well. I was recently very surprised to notice that the iOS client apparently synchronizes the security key for any logged-in vault to iCloud Keychain, with no way to opt out – even for enterprise vaults! In their defense, they document that the point of the Secret Key is that it remains secret from them/AgileBits/1Password, and that it is expected to be present on-device. It used to be called the Account Key, but the reason the name was changed was because far too many people were referencing it in emails to support, which undermined the design. In your defense, while they started syncing the Secret Key in iCloud Keychain all the way back at v7.0, they had then and have had sense gotten plenty of feedback saying this should be optional. They have just refused to make it optional.
- lucideer 3y ago> Bitwarden requires it every time. This is configurable - not sure what the default is but every time does sound annoying.
- gregschlom 3y agoThis is configurable in the settings. The default timeout is indeed too low and very annoying, but you can set it up to 4h I believe.
- giarc 3y agoMy biggest peeve is that if you search for a password and you happen to be in the "Card" category for example, it will return 0 results. A good alternative would be to show No Results for the category you are in, but then provide results for other categories below.
- corytheboyd 3y agoYeah that gets me somewhat frequently too, and second the request you have. Another silly one is adding custom fields, you can’t change the type between visible/hidden once it’s created, so if you mess up, you have to delete the custom field and add it with the desired visibility. Ughhh
- PH95VuimJjqBqy 3y agoanother is that if you do a search then click on an entry and do another search, the entry details displayed and what's in the search box don't match and it's not clear unless you're paying attention.
- mderazon 3y agoMy biggest issue is when having to copy multiple fields from an entry into the webpage and having to use the search (because the entry is for a different domain or just a note or a card) you have to search for the entry again and again because the search key doesn't persist
- troyvit 3y agoSame here. We use 1Password at work and the braindead UI choices continuously surprise me compared to Bitwarden's simplicity.
- kwanbix 3y agoI pay for family, and I like it. The only thing I don't like is that 50% of the time it would not recognize that I created a new user/pass combination.
- lucideer 3y agoBitwarden's UI is far from perfect but I find it better than any competitors I've tried (LP & 1Pass). 1Password feels cleaner, more integrated & polished but in practice the UX is inferior to BW - most regular actions take more clicks & discoverability is lower. And the password generator is even worse than LP's. Lastpass UI is well known to be poor - Bitwarden's is far less worse by every metric. Bitwarden's not perfect but what's significantly better UI-wise?
- throwaway447 3y agoNothing beats www.enpass.io but they charge now. I still ran the free version (free version not available for download anymore).
- tssva 3y agoI find Enpass to be great for personal use at least. I've never tried it for business use. Luckily I paid for it when the Android app was $6.95 and got you lifetime usage on all platforms. They recently added passkey support.
- throwaway447 3y agoI never installed it on Android. I use it only on my computer. But I use it also a lot as an organizer since it is so flexible. Has also my ID scans, Degree scans etc.
- tamimio 3y ago> store and sync passwords wherever is best for you So, how would you access that cloud account in the first place? Unless you remember the password and disable 2FA for that cloud account, unless of course you add another 2FA manager which is just an extra non-needed complexity.
- bmurphy1976 3y agoI can't speak for the other password managers, but I find Bitwarden's organization management to be pretty terrible. As a personal password manager it's pretty good, but as an organization password manager, not so much.
- sph 3y agoAnd with the Premium upgrade at only $10 a year, it's outstanding. I wouldn't mind paying 10x that. I introduced it at work to manage all our company credentials, and loved the fact that all users also get free premium for their personal account.
- razemio 3y agoWhy is it underrated? In my personal bubble everyone is using it. Most of them self-hosted. My hole family and some friends use my instance. Besides pass (low non tech approval factor) there is nothing that comes close.
- breakfastduck 3y agoTends to be used by a tech audience, it's nowhere near as widely adopted as e.g. last pass for normal consumers.
- carstenhag 3y agoI have to use bitwarden at my company laptop and don't enjoy it at all. Weird UX with unlocking the vault via touch id on a Mac (this is literally the most common UI interaction, please make it nice). On top of that, weird rare syncs/bugs, but this could also be coming from my employer.
- scubadude 3y agoI am very happy to pay for a family plan. The price of one coffee per month. Thank you Bitwarden.
- wkat4242 3y agoThe coffee is really expensive where you live lol. Here is around €1. But it's a decent price for a password manager yes. And the personal one is even better.
- nedt 3y agoFor hackers there is a CLI and with that also JS libs etc. to get it into anything you might want. For anyone else the UI is already miles ahead of Lastpass so there is no big compromise.
- treve 3y agoI feel I may have made a mistake going all in on keepasscx. Been looking for something without a subscription and ideally open source. Keepassxc looks like it has a much nicer UI.
- mksybr 3y agoKeepassXC will have passkey support soon: https://github.com/keepassxreboot/keepassxc/issues/1870 https://github.com/keepassxreboot/keepassxc/issues/1870 Don't get FOMO; both seem to support export and import, and they seem to be compatible formats, but you may need to lightly modify the CSV from Bitwarden.
- TheChaplain 3y agoVery cool, thanks for the tip. I use KeePassXC together with Syncthing, so now I just need a compatible android client.
- mksybr 3y agoI recommend KeepassDX. https://f-droid.org/en/packages/com.kunzisoft.keepass.libre/ https://f-droid.org/en/packages/com.kunzisoft.keepass.libre/
- renewiltord 3y agoGreat news. This is my favourite (and now only) password manager.
- sigio 3y agoLooks like the new version isn't approved for the firefox addons repository just yet... So haven't been able to try it out, but very happy with bitwarden (self-hosting a server using vaultwarden)
- dhd415 3y agoDoesn't appear to be available yet for Chrome in the Chrome Web Store or for Android in the Google Play Store, either. :(
- andix 3y agoLooks like it not really released yet. I still have 2023.9.x everywhere, and 2023.10 is the version with passkey support.
- minedwiz 3y agoIt's definitely out (https://github.com/bitwarden/clients/releases/tag/browser-v2023.10.0); https://github.com/bitwarden/clients/releases/tag/browser-v2... just looks like browsers haven't approved it yet.
- andix 3y agoI don't want to start a philosphical discussion. But I still can't install the browser extension to use it, so I wouldn't consider it being "out".
- Andrew018 3y ago[dead]
- gingerlime 3y agoperhaps a better link? https://bitwarden.com/help/storing-passkeys/ https://bitwarden.com/help/storing-passkeys/ Not sure if passkeys are supported on iOS or Android (only the browser extension is explicitly mentioned) and also they cannot be imported or exported according to the page.
- josteink 3y agoI may be stupid, but I just cant get this to work. Ive tried in both Safari and Chrome. Anyone have any luck so far?
- andix 3y agoNo, I didn't get the update yet (Firefox, Chrome, iOS). Everything is still at 2023.9 and 2023.10 is the version with passkey support.
- sotix 3y agoGiven the title of this post being about Bitwarden adding passkeys; I would think linking directly to the specific release note would be the best link. https://bitwarden.com/help/releasenotes/#2023-10-0 https://bitwarden.com/help/releasenotes/#2023-10-0
- Spunkie 3y agoOne of the benefits we saw moving from lastpass to bitwarden is it allow us to much more easily reduce duplicate entries for the same site/account. So it's pretty annoying to see in the docs for this passkey feature that they just expect you to make a duplicate bitwarden entry for every additional passkey you need to add to an account. Especially when it's standard to register a backup key for any service that uses passkeys.
- wetpaws 3y ago[dead]
- Ajedi32 3y agoWhat would be the purpose of having multiple passkeys for the same account stored in the same BitWarden vault? You're going to have a backup key and store it in the exact same place as the primary key?
- wkat4242 3y agoThe idea of passkeys is that they can be synced so you don't lose them when you lose a device. So there's a lot less need to have two
- barkerja 3y agoMultiple passkeys backed by different sources (password manager, iCloud, Yubikey, etc.) can serve as a backup in the case you lost access to your password manager, for example. If a service provides the option for more than one passkey, I always configure several.
- lolinder 3y agoBut that doesn't explain why you'd want multiple keys all in the same password manager. That seems to miss the point of the redundancy, like keeping an "offsite" backup onsite.
- 3y ago
- deutschepost 3y agoOne of the nicest thing about bitwarden is the ability to selfhost it. I don't think there is anything like it. 1password seems to have the best UX in the field. But you always have to trust some company with the keys to your digital life. Self hosting password managers is not as big of a deal as it should be.
- Axsuul 3y agoDo you get the same features self-hosting as you do paying for their cloud offering?
- deleted 3y ago[deleted]
- robertjglick 3y agoSome features require paying. For example: TOTP. But if you want just for passwords it is free.
- ghosty141 3y agoYou can use vaultwarden and get everything for free
- sneak 3y agoYes.
- artdigital 3y agoYou’re not really “trusting a company with the keys to your digital life”. The vault is encrypted with a password that never gets transmitted, and even if your password and vault gets stolen, without the additional “secret key” that also never leaves your device (and you should probably print and store somewhere safe), an attacker won’t be able to do much with it. The inclusion of an additional secret key makes a huge difference in this setup. but yes, it would be much nicer if I could use my own sync store like in the past… (looking at EnPass currently which also has a secret key setup and own sync store)
- quaffapint 3y agoSo it's browser extension only? I can't use the android app to login with a passkey I stored from my desktop browser? Hopefully they'll add that support soon enough, because password access on my mobile is a big pain point.
- lxgr 3y agoFrom the website: > Passkeys support for mobile applications is planned for a future release.
- aborsy 3y agoDoes the code in Vaultwarden mimic the code in the self hosted version of Bitwarden? Or a code audit in Bitwarden has no bearing on vaultwarden?
- figmert 3y agoVaultwarden is unaffiliated with Bitwarden. Vaultwarden is a hobbyist re-implementation of the Bitwarden server API. Anything the frontends (extensions, web ui, apps, etc) need to function properly, must would need to be re-implemented in Vaultwarden.
- andix 3y agoIn theory the Bitwarden server (and Vaultwarden) shouldn't have any access to the passwords, so a data breach of the server should never disclose any contents of the vault. Vaultwarden "feels" safe to me, but I would also be interested if there is some possibility it could introduce some degraded security compared to the official Bitwarden server. My Vaultwarden instance is "hidden" on a subdomain that probably nobody would ever guess (or scan for), so at least there is some added security by obscurity. If someone would know my credentials and master password, they probably won't find where to use them. In this case the reverse proxy in front of it also serves other content, just be hitting the IP nobody would ever know there is a Vaultwarden running on this server. Edit: the subdomain is behind a wildcard DNS, so it's also not listed in the zone file. Although it will show in DNS logs of the ISP when I'm using it.
- aborsy 3y agoGood point actually, the passwords are encrypted with official Bitwarden client apps (unless using web app).
- andix 3y agoI think even the web app does the encryption in the browser. The bitwarden windows app and the browser extension are more or less just the web app inside a webview.
- 3y ago
- mnahkies 3y agoWhat's the story with passkeys and broken/lost devices? I'm a bit out of touch here, and I assume adding support to password managers like bitwardon mitigates this risk similar to using them to store MFA seeds, or apps like authy over Google authenticator
- Mandatum 3y agoYou can still have a password, but think of it as a backup. Or you rely solely on the lost password process to reaccess your account.
- yonixw 3y agoFrom the FAQ [1]: > Q: Are stored passkeys included in Bitwarden imports and exports? > A: Passkeys are not included in imports and exports. I think it's the same for iCloud [2]. That is why I don't love it. I prefer a very long password, and Bitwarden "Device login" that will prompt in my iPhone that will require FaceID (So essentially I have bio login). And 2FA to lower hacking chances. I'm aware I'm still vulnerable to phishing but because there is no export, this is a marriage to Bitwarden. And as much as I love them... I'm not ready yet. But essentially it's a certificate... so I wonder why no private key export? Maybe because current implementation uses some CA that binds you to the issuer? [1] https://bitwarden.com/help/storing-passkeys/ https://bitwarden.com/help/storing-passkeys/ [2] https://redd.it/143acl5 https://redd.it/143acl5
- emptysongglass 3y agoIs this true for all of the incumbent password managers? If so, it seems like the worst of software lock-in.
- camkego 3y agoIt does seem like a real "lock-in" move.
- eviks 3y agowhat's the phishing risk if bitwarden autofills only on the correct domains stored in the vault?
- FloatArtifact 3y agoLooks like they're planning for export of passkeys. Q: Are stored passkeys included in Bitwarden imports and exports? A: Passkeys imports and exports will be included in a future release.
- seemaze 3y agoI've been waiting for this ever since Apple locked passkey support behind their existing (and infuriating) password autofill implementation. It irritates me so much that I refuse to use passkeys on iClould anymore, which is a shame becuase I really enjoyed the UI (for passkeys) and biometric auth built in to their products.
- jwally 3y agoI'm missing something. Webauthn puts a private key into a firewalled section of hardware onto your device - which is extremely prickly to work with in my experience - for your security. For passkeys to be transferable the private key cannot be locked to your device. Is bitwarden somehow able to "spoof" this hardware and have your browser generate private keys in it instead?
- drdaeman 3y ago> Webauthn puts a private key into a firewalled section of hardware This is not true. In general, Webauthn doesn’t care where and how the keys are stored. There is attestation feature, but AFAIK e.g. Apple intentionally doesn’t implement it for unmanaged devices.
- jwally 3y agoI've experienced this on my phone IIRC...if I register a webauthn key on chrome on iphone, it shows up on safari; but the reverse is not true. Im assuming this is because apple uses a software based TPM that isn't tied to the device. This lets those private keys sync between devices. Is the future state for bitwarden to be able to perform the same trick somehow? Have you create keys in it and not your devices tpm?
- lxgr 3y agoThe situation with Chrome and Apple devices is currently quite confusing. Apple has only recently introduced the necessary APIs to allow for third-party passkey providers (i.e. other apps acting as a passkey storage) and users (i.e. other apps using passkeys stored in iCloud and in other third-party provider apps). But it's not easy as passkeys being supported on the latest versions; at least Google used to support a non-synchronizing platform authenticator implementation of WebAuthN using the system keychain and Touch ID (or the login password as a fallback) as well. So there is also a chance you were using that, at least on macOS. > Is the future state for bitwarden to be able to perform the same trick somehow? For web browsers, I believe the current approach of 1Password and presumably also Bitwarden is to inject a custom implementation of WebAuthN into every page's context. This doesn't require any WebAuthN/passkey support on the browser's side. On macOS, they could also act as a system-level passkey provider though; this should then allow all passkey consumers (such as Safari and other browsers) to use these passkeys natively, i.e. without a JavaScript shim. And on iOS, given how web extensions are notoriously tricky there and all browsers are kind of Safari under the hood anyway, that might even be the only option.
- cmurf 3y agoiOS inhibits solving the cross platform problem, due to lack of browser extensions for all browsers. I get to use iOS built-in password manager, sync only on Apple devices and then no where else; or I get to use Bitwarden everywhere but on iOS no browser integration, I have to copy and paste (separately) user and password. Or even more lovely, maintain separate managers.
- snailmailman 3y agoThird party apps can integrate with iOS’s native password autofill, just like how keychain works. Bitwarden supports this as well. I’ve been using Bitwarden seamlessly on all my devices, iOS included, for a while now. It works in apps other than safari too. Anywhere where the native iOS password manager would appear, my Bitwarden passwords appear as well. I don’t think apps can turn on autofill automatically, you might have to manually turn it on in Settings->Passwords->Password Options
- gregorvand 3y agoPair it with mailpass.io and you have PassKeys all round, and real phishing protection than using gmail/ms/icloud emails as the communication method. Using a pw manager works well with it since the manager quickly stores the unique alias assigned to the service (ie instead of the same persistent email each time)
- AnonHP 3y agoThere's no pricing information for mailpass.io. There isn't even a contact email address or form. I'm hesitant to trust services that do not list the pricing (or future plans for pricing) transparently. Same for not having a support contact either. The help page here shows Slack as the only way to connect, but that's not convenient for people who don't use it or don't want to use it.
- gregorvand 3y agoThanks for your points - the product is in early beta and it is fully appreciated we are asking to be trusted with inbound messages which is a higher bar than a lot of products. Pricing will be transparent and detailed soon - however the service is currently free for up to 10 services/aliases (noted on the landing page) as we determine the user cohort that gets the most value from the product in general. We thought a Slack community was a more authentic way for users to contact / chat to those actually building the product, but please reach out to gregor@mailpass.io if you need support or just would like to ask some questions.
- scottydelta 3y agoI have been self hosting bitwarden/vaultwarden for 4 years now and my setup is hosted behind two self hosted vpns(openvpn and wireguard where one acts as backup vpn). This ability to self host in itself is worth so much.