Bitwarden: Generate a Username
bitwarden.com
bitwarden.com
https://github.com/topics/username-search
I use different usernames per-site, but I tend to take a couple seconds to think of something (hopefully) clever.
I do wish this was easy and automated.
Looks like we’re getting really close.
Good?: product1@sebastianmiller.ismyrealname product2@sebastianmiller.ismyrealname
Approaches for randomly generated usernames are probably the best way to go. DDG's @duck.com email service (and similar) is pretty fantastic if you're forced to use an email.
You can reply from all addresses described above. The FF extension makes pre-registration of random addresses a little easier by putting a button on e-mail form fields.
There isn't convenient integration with password managers, that I know of.
You could be de-anonymised. Particularly by correlating your sign-ups using your-own-subdomain.mozmail.com. Or if the service is hacked. There's some argument that makes this service harder to generate spam with, and therefore less likely to be blocked. That's yet to be seen, I suppose.
Fastmail also offers this service, so I think it's becoming a popular enough idea that password managers may start to see value in introducing it. Hopefully...
It is, on MacOS and iOS. HideMyEmail works for normals, and Sign-in w/ Apple defaults it on.
Do you also use a different email address on each site, or do all the unique usernames ultimately link back to one email?
I think an important distinction is that the email address is often private. My HN account and my reddit account may have the same email address, but Reddit and HN would need to coordinate to figure that out. If they both sell user data, or suffer database breaches, get subpoenas, then a third party could link the accounts. For sites that support username search by email address or treat email address as public data, yeah, that's exposed.
For usernames: a series of HTTP GETs can find likely examples of username reuse:
* news.ycombinator.com/user?id=$username
* reddit.com/u/$username
* twitter.com/$username
This is cheap, easy, scalable, has automated tooling, etc. So I worry enough to pick a new username, and let my password manager remember it.
Many services today use emails as their userid, and even often the login username (account display name being separate), so I think it's probably more common for attackers to match passwords with common emails rather than common usernames. But they can & will still do both, so the unique username certainly has some use.
(it also helps a lot with tracing who's sold your data to a spammer)
> Distinct emails is just defense in-depth. > (it also helps a lot with tracing who's sold your data to a spammer)
Not only that, if when you first sign up with BigCo you give them your email address as bigco@example.com then when one eventually stops dealing with BigCo one be certain that all email addressed to bigco@example.com can be rejected at your email server without a second thought, no need to scan for spam, just reject everything addressed to that alias.
A good friend of mine takes this a step further and does it through DNS (which of course he self-hosts as well as his mail server). He would give his email to BigCo as firstname@bigco.example.com. Once he's done with BigCo then he removes the records for bigco.example.com and there's no way to even look up a relevant mailserver to send email to firstname@bigco.example.com!
LastPass's username generator is much better: https://www.lastpass.com/username-generator. With "lowercase" only and "Easy to say" turned on, the suggestions are really good. This is my go-to when I need a username, and that's as a Bitwarden user!
I would think the purpose here would be that you would use unique aliases per service to limit your own risk in the event of a site breach. However, the vast majority of websites these days require a username and an email address. In which case, if I've got 50 unique usernames but they're all tied to a single email, how much am I really protecting myself if the email address gets included in the breach?
If my data were exposed, I guess someone who realized that could try any variation of the site's name to figure out the exact one in my address, but you could always do something more unique than that. Even something like generate a BitWarden password and use it as the user for the domain.
I think a good system would be a randomly generated handle like nick836742@example.com where my real email probably isn't nick@example.com, but the number is different for each service.
Large font, clear hierarchy, great use of color and font weight.
To access your account you need to type your master password, the same password that is used decrypt your vault. If a competent hacker gains access to the Bitwarden servers they could install a compromised login page that logs master passwords and with that gain access to password vaults.
Sounds far-fetched maybe, but your password security depends completely on the ability of Bitwarden to protect their servers. The encryption is just a minor hurdle once the servers are compromised.
Note that 2FA doesn’t help since it is not used for vault encryption.
First-party end-to-end encryption is broken by design, especially in the presence of auto-updating.
The caveat being: you have to manually copy over any credentials from Bitwarden to Keepass, which is time consuming but one day maybe worth it.
pass-import works pretty well; create an initial empty KeePass DBX file first and keep a copy to re-use, then one can re-run pass-import to import BW to a fresh KDBX on a recurring basis with a simple script.
There's no desktop autofill or autotype and no SSH key management.
But honestly with all the updates I'm putting off I'm probably actually more at risk, and a good password manager implementation will encrypt all passwords client-side so you're not actually uploading your passwords to anyone's computer.
There's a self-hosted alternative, but even so, I'd trust them to handle server security better since, since it's their speciality.
I'd suggest adding Yubikey as 2-factor, then anyone would need that physical key to login.
That said, I use KeePass on Windows and Android, sync my safes once a month/as needed, and call it a day.
Personally, I've used it since lastpass made people pay for multi-device access. You can treat it like a git repo that's encrypted at rest. Client implementations are pretty quality in my window of experience (on linux+ff, mac osx+ff, iOS+safari).
The security problem reduces to "how do I securely store a private key that I use every day", which is a well-understood problem with a well-documented set of solutions.
if name == "boring_wozniak" /* Steve Wozniak is not boring */ { goto begin }
EDIT: See note below - this is for the Add Login dialog where it detects the domain you're signup for. (My initial tests were in the generic Generator function, which don't have the full functionality.)
> Website Name is limited to the Add/Edit screen on browser and desktop as it requires knowledge of the login's URI, in other locations the username generator will default to Random.
Very cool, glad to see more people doing so!
Anyone knows which providers do this?
>e.g. alice+gsd4aqqe@bitwarden.com)
If this pattern becomes popular enough, it won't take long until services strip out the + part entirely.
Sneakemail, which lets you do it with hyphens, works pretty well, though.
Why would they do that? Specifically to spam more discreetly? But it's trivial to auto-filter all non-plus addresses to the trash.
I've switched to a custom domain and from.<sitename>.<random>@
NOTE: Because the encoding of detailed addresses are site and/or
implementation specific
`+` or any other encoding is not part of an RFC, and I don't think the existence of subaddressing is either.[1] https://www.reddit.com/r/Bitwarden/comments/ucd9d2/new_exten...
In addition, in the extension I can't use pass-phrase like generated responses for my username but I can for the password?
I just use a random cheap domain, registered through Gandi. This includes a couple of 3 GB mailboxes each with unlimited aliases, which is quite adequate if you don't use your email as a file store (much).
I suppose the "right" way would be through something like Fastmail instead, but the simple arrangement above has worked fine thus far.
They use something called Jellyfish for spam detection and it's been pretty impressive. A few false negatives but overall catches most of it. And you can use their webmail or any IMAP/POP3/SMTP client.
A bit slow but I don't think it's unreliable. If it is, that's scary because how would I know :)
Just moved a folder with 1037 emails and it has 1037 on NameCheap now. Seems like it moved them all! (And it didn't take too long. It's moving a bunch of subfolders now.)
Random addresses are also somewhat problematic too when they ask me to “confirm my email”. But they just think I have a very strange username.
Downside is you have to use 1password AND fastmail obv.
2) You typically want your user name to be recognizable by the community you're registering at.
Or email address is required? The email address username generation is useful for those cases (assuming you use unique email addresses for each signup.)
Also, the password generator isn't configured to work for the use cases here (adding your email or a catchall, using less characters, no special characters, etc.). That way you can still sign up for accounts that require email verifications.
1password integration is nice, because you don't have to open up Fastmail to generate a new masked email.
I just use catch-all with custom domain, though. That way, I'm not tied to a particular provider, and I can make new "masked emails" on the fly however I want (usually, just using the name of the app/website I'm signing up for). The downside is that you loose the previously mentioned anonymity since a hacker could link your various addresses by domain name. But it's still way better than using the same email address everywhere!
It wont forward to your inbox though and is only suited for temporary usage.
Answer: Don't worry, they'll tell you about it.
Why use Plus Addressed Email?
Plus addressed emails allow you to filter your email for all the junk mail you get when signing up for a new service. Signing up for a service with the username alice+rnok6xsh@bitwarden.com will still send emails to alice@bitwarden.com, but you can easily filter emails that include +rnok6xsh to prevent them from clogging up your inbox.
In this example, just make rnok6xsh your username and let spam filters do their job. Please stop embedding email addresses in usernames. It rubs GDPR and privacy in a bad way.Edit: Based on the other reply to my comment-- are you using the Bitwarden self-hosted solution? I was primarily interested in Vaultwarden, the OSS alternative
Whether it's as secure as using a separate TOTP generation app is slightly beside the point, because it's so much more usable. And I don't need to re-bootstrap access to all my accounts when my phone gets run over by a car.