6 ms·
I can understand adding some friction to discourage using Bitwarden without 2FA, but requiring it seems very wrongheaded to make it mandatory. I've been using 2
by TheFreim 2y ago
I can understand adding some friction to discourage using Bitwarden without 2FA, but requiring it seems very wrongheaded to make it mandatory. I've been using 2FA on Bitwarden for a while and it adds a lot of friction and made me very nervous that if I lost my phone that I'd be locked out of literally every account I have. I mentioned elsewhere (link below) that I have solved this issue for myself, but people shouldn't be required to jump through these hoops and introduce a greater opportunity to lose access to their accounts if they should lose their phone.
https://news.ycombinator.com/item?id=42853696 https://news.ycombinator.com/item?id=42853696
- mplewis 2y agoYou don't need your phone. You need access to your email account. This is described in the article.
- TheFreim 2y agoLike numerous others, my email account password and 2FA codes are in Bitwarden.
- notesinthefield 2y agoI dont understand why people do this - those “bedrock” accounts like bank accounts shouldnt be in your password manager in my opinion. At the very least split your providers - no one manager has all my passwords and 2FA codes.
- Wowfunhappy 2y agoBecause for security (!), I use a very strong and difficult to memorize password, with no backstop if I forget it. I only want to memorize one of those.
- bgnn 2y agowhy is this safer than requiring 2 master passwords. at the end an email account is accessible via a password.
- Too 2y agoHopefully your email also requires 2FA :) Even without, accidentally getting one password leaked is a lot more likely than two. For whatever reason, shoulder peeking, keylogger, wrong input field, brute forced, and so on.
- bgnn 2y agoyeah so 2 passwords would do the same trick then? In my mind the email is the second worst 2FA since it's used for registering everywhere on the web and more prone to be compromised. Phone number is the worst.
- the_snooze 2y agoIt seems like the alternative is to allow anyone with just the master password to get access to your vault. That doesn't seem so great. I'm on 1Password and it's basically a 2FA setup there too: to register a device, you need to have the master password (what you know) and the secret key (what you have, randomly generated at vault creation). Losing my phone isn't a big deal because I have 1Password on multiple devices, each with a copy of the secret key, so there's pretty good hedging there. I also carry a physical Yubikey, which grants me passwordless access to my email account (assuming I know the PIN to unlock the hardware, which I do). That's probably overkill for most people, but that's another layer of hedging too.
- mvdtnz 2y ago> It seems like the alternative is to allow anyone with just the master password to get access to your vault. That doesn't seem so great. Given that only I have my master password I don't see what's wrong with it.
- hypeatei 2y agoWhat if, for example, a piece of software is logging your key presses without your knowledge? You could have the best, most secure password but you're typing it into a complex machine which could be doing any number of things. Don't forget that you're human and make mistakes too so it doesn't necessarily have to be malicious; a bad copy paste into a public forum post could hose you. A second factor makes it extremely unlikely that one slip up results in a complete compromise of your vault.
- the_snooze 2y agoYou don't even need a keylogger for password leakage. You could accidentally type in your password into a logged field because you forgot to press tab or alt-tab to move cursor focus. 2FA for setup doesn't strike me as too onerous. It only happens once per device, after which you're free to rely on just your master password or even biometrics.
- fwn 2y ago
- bachmeier 2y ago> very nervous that if I lost my phone that I'd be locked out of literally every account I have I use Bitwarden 2FA with my phone, but I have backup codes stored in a fireproof safe with my other important documents.
- makeitdouble 2y agoAren't you screwed if you can't get access to your home for whatever reason ? That hopefully would only happen in extremely rare conditions, but that's not a risk everyone would take. Especially in area where losing your home is a very real risk, and you'd be hanging to your data by a string while facing an otherwise already challenging situation.
- JasserInicide 2y agoI'm so fucking sick of places enforcing that shit. Not all of us have shit passwords.
- gear54rus 2y agoAt least they are not 100% head-in-ass sesoority yet and still allow to at least self-host to disable that crap.
- rcxdude 2y agoThere is still a ceiling to how secure a password can be which 2FA solutions will generally beat (mainly by the secret not being spread as far when used, such as keyloggers, window focus mishaps, or simply being sent to the server verifying it).
- thomastjeffery 2y agoFriction is bad security. Simple as that. Removing the friction of many passwords is the whole reason a password manager is good in the first place! It seems like every IT person needs this lesson reiterated to them, at least once a year...
- TheFreim 2y agoI am not suggesting friction as security, I am suggesting it so that the average user is funneled towards the most secure option, i.e. using 2FA, while allowing experienced users to put in a small amount of effort to disable it.
- thomastjeffery 2y agoThat's not a meaningfully different context, unfortunately.
- akvadrako 2y agoYou certainly shouldn't rely on just your phone. If you store your 2FA token in Bitwarden, you can use any of your other devices that you have used Bitwarden with recently. The 2nd factor is only needed when it's new or occasionally in other cases. I don't know why you say it adds lots of friction, unless you are frequently signing into new devices. And as a failsafe a printed backup code is pretty important.
- demosthanos 2y agoI understand that in theory storing the 2FA for Bitwarden in Bitwarden itself can work, but I don't know if I can ever bring myself to store the key to the car in the car, even if I pinky promise myself that I'll never lock all the car doors at once. This is doubly true because Bitwarden has not been consistent at only asking for 2FA on brand new devices, so it's not even just me that I have to worry about locking the car doors.
- krick 2y agoAnd even if F2A wouldn't have ANY downsides, it's still not their fucking business if users want to use it or not. There is a million ways to leak your credentials to a service anyway, and I don't know anything more annoying than when a service tries to protect you from yourself (sometime locking you out of your account while doing so). If a user wants to have no F2A, no backup email, to use qwerty as a password and to write it on a sticky-note attached to a display, it's their right to do so. It's not Bitwarden's (or anyone else's) responsibility.
- Wowfunhappy 2y agoI agree, and when I first read the headline, my reaction was "Well, I guess it's time to start researching different password managers, because I obviously can't use Bitwarden anymore." However, despite what the headline says, this 2FA does not appear to be mandatory. Under the heading: "Who is excluded from this account email-based new device verification?" > Users who opt-out from their account settings, to which an option will be added, are excluded.
- krick 2y agoThank you. The title should be changed, really. Following an ancient HN custom I've chosen to get annoyed before reading the article, and the title simply isn't true. In fact, it's exactly what GP suggested, which is a perfectly nice way to implement that. (Unless, of course, one day they get rid of that option as well...)
- TheFreim 2y agoThe title was changed, but it's worth pointing out that they updated the article AFTER criticisms in this thread were already made (the original policy did not say you could opt-out): https://news.ycombinator.com/item?id=42859698 https://news.ycombinator.com/item?id=42859698
- sesky 2y agoTo clarify, this was new information added to the release within the past hour or so, which seems like the company responding to criticism. The original article gave no indication 2FA was anything but mandatory.