4 ms·
>I think people on HN overestimate the security literacy of the average computer user in a personal/corporate setting. Sure. Provide an escape hatch for the te
by msgodel 1y ago
>I think people on HN overestimate the security literacy of the average computer user in a personal/corporate setting.
Sure. Provide an escape hatch for the technically literate and let us use our ssh-agent then.
- ericpauley 1y agoHere's your escape hatch: https://bitwarden.com/help/export-your-data/ https://bitwarden.com/help/export-your-data/ Bitwarden even now supports passkeys on mobile browsers and apps. As a happy user for over 5 years it's been great being able to configure something less theatrical than push/codes without needing to plug in my YubiKey every time.
- secabeen 1y agoSadly, right now, bitwarden is the only provider that will dump your passkeys into a JSON. No one else offers it, and there is no functionality from any provider to import and adopt the JSON that bitwarden exports. Passwords have their faults, but they do have a zero-technology backup option that your heirs can execute. (A printed dump of the password vault in a locked fire safe.)
- hakfoo 1y agoI'm surprised that especially financial service providers don't have a very clear "in the event of death/emergency" flow. I know you can sometimes label an account payable-on-death/joint-ownership/trust/other weird tax-dodge shaped things, but that doesn't solve the technical problem of "how do I log in and initiate my claim when Grandpa kicks the bucket." I prepared the fire-safe paper, but I can imagine my family getting stuck at the institutions who demand 2FA and probably won't have access to my phone or email at the time.
- brewdad 1y agoThe whole point is that you aren't supposed to be able to login and continue business as usual. You need to call or write to the financial institution and provide proper legal documentation (death certificate) before you can assume control of the account. This is a GOOD thing.
- secabeen 1y agoThat's fine for financial accounts, but people have hundreds of accounts, and you don't know which ones are the ones that matter beforehand. Is it your family member's AO3 stories that you want? Or maybe the login to the web forum that was their primary social outlet in old age? This assumes that those non-financial sites even have a process to let you in.
- RandomGerm4n 1y agoKeepassXC also has the option to export passkeys
- pjjpo 1y agoHappy user of Bitwarden and use their passkey support when I can. But generally I've been underwhelmed with the passkey UX, likely no fault of Bitwarden or similar. With extensions installed, Android configured to use Bitwarden for passkeys, etc, it feels like a 10% chance or so Bitwarden will be checked for a passkey and otherwise it's randomly either the browser or phone. Without being able to reliably read a passkey, I always need to set up password + OTP as a backup. While there's some benefit to passkeys when available, having to set up multiple auths anyways just makes it feel like too much of a hassle...
- reginald78 1y agoAnd how long until the attestation feature is used to ban their implementation? The threats have already been made to keepass.