Passwordless Authentication – Access Your Bitwarden Web Vault Without a Password
bitwarden.com
bitwarden.com
I just envision a future where there is some near-circular dependency of passwords/phrases/notifications/authenticators/keys/email verifications etc across different devices and services - the end result is that it is absolute PiTA to log into anything or recover any account if anything is ever lost. Sort of an endless personal bureaucracy for authentication. It’s a future I am personally trying to avoid at all costs
Yubikeys etc seem like something I could potentially get behind, but it still doesn’t seem perfect persay… anyway, maybe I am just a geezer
MFA using an SMS is not secure.
If people reliably made good passwords and never reused them, we probably wouldn't need MFA as much.
Unfortunately, we live in a society. Bitwarden will remember your TOTP codes for you across any device you login from. It will even copy the code to you paste buffer during a login.
I enable MFA everywhere i can, even for stupid stuff. Its just not an inconvenience using bitwarden.
Why not? Is it that easy to intercept a SMS or is that just due to poor handling with some providers?
I don't know about other countries, but you can't even buy/activate SIM cards in Germany without "proper" identification through VideoIdent or another system where your passport is checked against. At least that's what I remember.
I'm not sure any type of "I've lost my SIM, please use this one" would work on German carriers without proper ID.
Moving numbers als requires some kind of paperwork, it's not that easy after all.
So... Is this a telco problem or a SMS problem?
So essentially they would have to breach the national 2factor authentication system first here.
And there is absolutely no way that you could "social engineer" the guy on the other end of the phone who works for the telecompany as there is no way you shouldn't be able to use their online tools.
SMS has weaknesses. Especially if you are a particularly high-interest target. But the benefit of "everybody already has a phone" is immense and the true recovery mechanism for "oh shit I dropped my phone in the toilet" is valuable. Something like a yubikey is the complete solution to login problems that don't involve malware or some security vuln, but they are an extra thing that people need to buy so the pathway to "everybody uses a yubikey" is a mess.
Both Android and iPhone are now offering similar functionality though phones, which mitigates the "you need to buy a new thing" problem, though it is harder to set up an effective backup here.
If you ever notice you lose connection to your carrier: begin to worry.
and it’s all developers will give you the tools to check every login session, including ip addresses used, and number of failed attempts
and off everybody uses full disk encryption and other measures so that your passwords cannot be stolen, such as only use signed applications and proper sandboxes
I know a lot of HN doesn't have much use for blockchain, but if there's one thing that blockchain has done for the world it's been to substantially spur the use and development of public-key auth systems, especially on the UX front. This is because it had no choice. If you try to use an inherently broken password auth system for completely decentralized digital currency, it will immediately descend into unusable chaos because of the vulnerability. Traditional finance (credit cards), government identification systems (social security), etc have so much existing infrastructure that innovating in this area is hugely costly and slow, but it's absolutely the direction we need to go.
Real cross-device passwordless is likely coming in the next year or so. WebAuthn/Passkey is in its 3rd public working draft[1] and once finalized, we'll likely start to see it across sites. Most devices, browsers and managers have added or are adding support for it: Apple, Microsoft, Google, Auth0, Duo, 1Password, etc. If you haven't seen it, Auth0's demo is helpful[2].
As a side note, if you want to try out passkeys now and don't want to tie it to your device, I would like to plug my solution, Bulwark Passkey (https://bulwark.id). It's open source, allows you to export your credentials if you want, and supports all browsers since it emulates a virtual USB device.
What downsides are there? E.g, will it work on rooted phones? Will apps start adding mandatory pin numbers on top (like they do for biometrics), or will Google/Apple's app stores disallow it? How do I "log out" to avoid tracking without being implicitly logged back in? What happens if I routinely wipe my browser settings? Can I use some other person's computer to login in a pinch? (Such as when my phone is off network?)
In principle, browser and os vendors could work through all these "niche" use cases, but I'll be pleasantly surprised if they actually did.
Personally, I think that the main blocker for adoption of passkeys is ease of use, as if you can't transfer your credentials either off of your device or away from your Apple/Google/etc account, then I think it will be a hard sell to users.
Any ideas? Thanks!
Edit: I was able to reproduce the issue; it looks like WebView2 (which Bulwark Passkey relies on) is already installed on Windows 11 but not on Windows 10. I released a new version on https://bulwark.id that has that WebView now embedded in the app itself, would you mind downloading that and seeing if that works? Thank you for the report!
https://mjg59.dreamwidth.org/62175.html https://news.ycombinator.com/item?id=33810984
For a moment there I had hoped that maybe it would solve the problem in the opposite direction: I'm typing the master password so mechanically when I'm on my laptop, that I really struggle to remember it when I have to type it on a screen - to the point that I must go sit at a computer open a notepad, let muscle memory take over and then look at the screen to see what I typed /facepalm
Anyway, in all seriousness, while this is a scenario that happens very rarely, it still makes me wonder if it would be possible to do the pasdwordless login the other way, i.e. authenticate the phone using a trusted laptop (maybe a fingerprint enabled one)?
I've had times where I've needed to get into my account in a hurry and had to find a POS terminal with a keyboard so I could activate the muscle memory.
My work machines (government) check for "commonly used words" and will generally reject natural language even if squashed between punctuation marks. "P@ssword" would probably slip through, but "GodIHateRememberingAllTheseStupidPasswords!@#!@" doesn't.
Note: Logging in with a device is currently only available on the Bitwarden cloud server (https://vault.bitwarden.com).
And even there, I followed all the directions and don't have the 'Log in with device' button. Waste of time.The only hesitation for me is as other folks mentioned - never typing the master password again might make remembering the pass phrase challenging..
Those minimums are taken from Docker. The person above asked why they were what they were, I answered. You're just further reinforcing what I explained.
If you were running the Bitwarden server on bare metal (which you can definitely do), the requirements would still be the same.
- https://docs.docker.com/desktop/install/linux-install/
HN has reached the point, that it will heavily downvote an objective fact because it goes against the pointed narrative. They took a dependency, copied its system requirements, and someone asks "why?" and that is the actual answer.
A lot of the other answers (multiple Dockers, slimmer image) really address how Docker themselves have these exact system requirements listed, but why do they need to when the point isn't to answer the actual request asked by get lost into a predisposed critique.
Side note: WTF is Docker Desktop on Linux using a VM? I can't even.
With the requirements on here: https://docs.docker.com/engine/install/binaries/
It doesn't even mention space because it's negligible. dockerd uses a few megabytes of ram and around 100MB of drive.
Having facts doesn't always mean you're right. Sometimes it's the wrong facts.
It is written in Rust and is much lighter on resource requirements.
CONTAINER ID NAME CPU % MEM USAGE / LIMIT MEM % NET I/O BLOCK I/O PIDS
ecce485b8b3a bitwarden 0.06% 46.58MiB / 1.937GiB 2.35% 1.63MB / 28.1MB 17.5MB / 81.9kB 11I assume bitwarden's implementation has been more thoroughly reviewed.
Assuming there is a critical bug in vaultwarden, what is the severity/what information is exposed? Is it relatively safe even then because of the E2E?
But... that seems reasonably unlikely.
> if you don't have a fixed IP can bounce through even the cheapest VPS instance and still store nothing in the cloud
I've been meaning to look into this with wireguard, but I'm having trouble searching for/finding how to do this. Is "bastion host" what I'd want? Also is there a way to ensure the VPS cannot access the network as well, and just tunnels it essentially?
First, yes a search phrase like that should get you the right terms, though there isn't anything inherently special about it. If multiple systems are connected to one system with wireguard giving them all access to a given subnet is straight forward. As far as the VPS, it can indeed access that subnet too, since it's acting as part of the subnet, but you can use normal firewall rules on the far side internally to control what can talk to what and how. And in this kind of specific instance the WG is more about controller public facing surface area, the Bitwarden/Vaultwarden traffic in flight is itself encrypted.
Second though, having said all that I think if you worried about the VPS bit (or even if not) you should take a look at the Nebula SDN [0, 1] instead. It's built on the Noise encryption framework as well. There, the fixed IP node (the "Lighthouse") primarily acts to let other nodes know their mutual addresses, and they then attempt to form a direct link with no bouncing through a bastion, it's a real mesh. This generally works even if both are NAT'd, and if not it's transparent fallback and still encrypted between them. Depending on distance between nodes this can be a lot lower latency as well. With Nebula you establish an internal CA (super easy built-in tool for it) and that doesn't (and absolutely shouldn't) live on the lighthouse.
I'm fortunate enough to have fixed IPs available to me at home and office and have tended to use WG a lot just because it's had more advanced support and performance in constrained environments for me (kernel support in Linux and now BSDs). Nebula has been super slick though and I've been using it more and more. It makes all this really easy.
Anyway, hope this helps a bit. It's really exciting to me how much open source networking power is now available to everyone. It's a bit of a counter decentralization force IMO to the last few decades push towards central service providers.
----
0: https://github.com/slackhq/nebula
1: https://arstechnica.com/gadgets/2019/12/how-to-set-up-your-o... (note 3 years old, there are now Android/iOS clients as well and things are further refined)
However, it's not WireGuard. WireGuard operates on L3, there's no L2 headers, you can't run MPLS over it, you can't add VLAN tags to it, you route all the traffic.
As long as you're not bridging yourself into the ZeroTier network there shouldn't be any issues though, but fragmenting always kills performance.
TL;DR: ZeroTier is not based on WireGuard.
I’m in the process of moving towards putting stuff behind new vpn solutions (Tailscale/ Wireguard in my case). It does feel good to drop https though. Or does it really not matter? What do HNers think?
The easy alternative is to purchase a domain, and use let's encrypt to create a wildcard certificate for you. I use the integration with my reverse proxy and it's pretty easy. You want a wildcard certificate because of the Certificate Transparency Logs, if you do it by subdomain then the list of registered subdomains will be public.
Certs on multiple devices - you can most likely still use let's encrypt as most things nowadays have native integration. Otherwise you'll likely have to do it manually
I recommend a domain you don't use for other things online
Hosting your own is a twenty minute setup, more or less, and $5/mo on Hetzner. Uptime, in my experience, is 5 nines.
With SaaS, I am losing the main reason that I am using Bitwarden - that I don't want the X agency to force Bitwarden to give them my passwords.
And I know that if said agency (it varies by country and target) could definitely hack the VPS if I was important enough, that is not part of my threat profile. Self hosted is far less likely to get auto vacuumed than SaaS data.
There's a very big gap between a warrant and a torture kidnapping. Self-hosting protects a lot of that gap.
Then you do not understand how bitwarden works,
Bit Warden has the same access to your passwords that Hetzner does, i.e they have only encrypted access to the binary storage.
The only thing agency X could get from bitwarden is an encrypted vault that is useless with out your master key, all encryption and decryption is done client side. THis by the way is the same access Hetzner would have to turn over if Agency X asks for a copy of your VM running vualtwarden
You’re probably not worth individually attacking, but a brief look at the failed ssh login logs of any insignificant server shows that you probably are worth automated attacks… so I suppose the question is “Are you more vulnerable due to a) the risk of getting pwnt by an automated attack (due to a misconfiguration or being even a little slow to install a critical patch) or b) due to the risk of bitwarden getting pwnt by a sophisticated targeted actor?”
Further complicating this math is the E2EE nature of it, so it’s not just enough to pwn a server, you’d need to also compromise the client application.
Actually, now that I think about it, if you can compromise the client you don’t even need to compromise the server. I’m not really sure under what scenarios running your own server would protect you in in that case.
The webvault is both a server and a client, and you can't not use it. As soon as you sign into it once (which you must, with the official apps) you have allowed unsigned ephemeral javascript code to run against your decrypted vault.
So yeah even if you aren't a big target then you are still a target for automated attacks as they just pick whatever IPs they can find and try to breach.
Any purchase I do online is done with a virtual card that links to a bank account that only ever has the amount I need to pay for whatever it is I am currently purchasing. That way it doesn't matter if the information is stolen etc. because there is no more money to use and I can cancel the card as easily as I can create a new.
For banking I also only use my banks official app, I don't know how exactly it works and I assume it does use some form of http and whatnot, but I wouldn't trust using a bank through the browser as you never know what kind of thing an extension or something have in there.
I have a hard-to-guess master password, but it wouldn't surprise me if they could crack it with a 2026 vintage GPU farm.
Also, after your device synced with the server at least once, you can still access and export all your passwords, even if the server is down. This is the main selling point for me : even in a disaster scenario, your passwords are "naturally" replicated.
Mine is exposed behind a reverse proxy, with a subdomain != Bitwarden, and a wildcard certificate. Never seen anything weird in the logs since (before, I had a named certificate including subdomain, and I was seeing regular pokes from unknown IPs, so better be on the safe side)
Again, the main bitwarden instance is a huge target. Mine is just a small instance with less than 10 users, which will probably never encounter a targeted attack.
Watch out for the browser extension clients though - they're prone to session expiry and insisting you relogin which is a problem if the remote server is down or gone.
Who would trust their passwords to a service with such a clause?
Well, yes, after adding photo gallery, I now want a faster device.
'Passwordless' badly needs 'password manager' support, or other cross-platform implementation, IMO.
Overall, I think what passkeys need right now is more flexibility. Nobody is going to switch to passkeys if they are locked to their Apple account, for example.
Can someone ELI5 how this works? I went to fidoalliance.org and honestly, I didn't understand a thing. I still don't understand Yubikey and its MFA, it feels so cumbersome and huge PITA to do it every-time. Am I missing something? My workflow now is: CMD+SHIFT+L, enter master-password once and that's it for the current OSX login session. Will Passkey or FIDO or Yubikey improve this speed of interaction?
At least with Bulwark Passkey, its a separate app that you only have to log into once when you open it. Then, when logging into a website, you hit Approve on the app and it should just work. Speedwise, it should be about similar to an optimized password flow, but security-wise it will be much better since you can't phish passwords from it.
Partly to force memory reinforcement, I set the password cache time of gpg-agent on my machine to 24 hours maximum. Thus I have to enter my password once a day, which helps me to remember it; but it isn't overly burdensome.
Although maybe if one always has
If someone was to obtain a copy of your vault, decrypting it would be trivial with a weak or compromised master password in that case.
CTAP supports an extension called hmac-secret that would allow you encrypt your vault, which would mitigate this issue (While introducing others potentially -- for instance, hmac-secret does not require user verification so anyone with your yubikey could decrypt it). Of course there are other mechanisms to encrypt a vault other than a key derived from a password that you can use with a Yubikey, like PGP, but I don't know of any commercial password manager that does it that way.
The thing I worry about is that the security of the passphrase is only as secure as the mechanism guarding it. If it's written on a piece of paper, then how is the paper secured? It could be put in a vault, but then the vault itself is a conspicuous target for thieves. Hiding the paper somewhere is probably pretty reasonable, but if it's too well hidden, it could get forgotten or accidentally thrown out over time.
I use a YubiKey as well as an ultimate backup, and it has a PIN code mechanism that will lock after a few incorrect attempts, so that is a reasonable tradeoff for security and usability I feel.
I wonder if the best solution is to have a distributed copy of a recovery passphrase to friends and family. Then separately have a distributed copy of the vault itself (in my case, it's GPG-protected Password Store). This must have been an area of study already, I need to do some research!
Like the other commenter I don't want or need MFA. It's more complicated and a pain to use. Just seems like a convenient opportunity for online companies to gather more data points about you. Keepassxc with a key file is still going strong for me. You've no need for my phone number! And I don't want my device linked to any account.
If you think your computer security is weak, it will continue to be the weak link even with with a hardware key.
Hardware keys are made not to give out secret keys without physical touch.
Firmware in Yubikey is not updated, unlike over the air phone update.
it say: [1198] [SecureNote] "username id rsa ssh": The field Notes exceeds the maximum encrypted value length of 10000 characters. But this id_rsa has only 1415 symbols
1password has imported csv as well without any issue or alert.
So login from device is not a big deal.
Does anyone have any insights to how enterprises will be managing passkeys for corporate accounts with the potential of creds being leaked to potential compromised devices.
Although how could any product protect against that kind of attack? If the supply chain is compromised, it's pretty much a wrap.
This is not specific to Bitwarden though, it's the same for all apps. Now because Bitwarden is open source, you can actually compile and install it yourself (if you're confident that the sources you are compiling are the legitimate ones, and not a fork that will steal your passwords ;-)).
Same applies for e.g. Signal Messenger: since it's difficult to check what version of the code is coming from your store, you can always compile it from source and install it yourself.
Edit: thanks, sounds like 2fa is now free.
Happily paid my $10 after using it around the office for a few months (paid Teams account).
We came from KeePass, so the whole cloud thing was new. But it's "just worked" remarkably well.
The multiple-profiles feature was a game changer, allowing me to access both my work credentials and personal credentials from the same app, while keeping them entirely separate is really nice.
Upgrading to the Premium Account ($10/yr) gets you additional options: "YubiKey, FIDO2, Duo, Email, Authentication app"
Source: https://bitwarden.com/pricing/