HNHacker News
TopNewBestAskShowJobs

xxkylexx

918 karma · joined October 10, 2016

submissionscomments
xxkylexx··on Bitwarden introduces mandatory 2FA for new devices
Settings < Autofill < Click items to autofill from Vault
xxkylexx··on Bitwarden is turning 2FA on by default for new devices
It's not mandatory, it's a default. I asked the help docs team to update the FAQ to include that there is an opt-out option under account settings.
xxkylexx··on Bitwarden is turning 2FA on by default for new devices
It's not mandatory, it's a default. I asked the help docs team to update the FAQ to include that there is an opt-out option under account settings.
xxkylexx··on Apple unveils 'Passwords' manager app at WWDC 2024
You can turn this feature off under settings.
xxkylexx··on Bitwarden: Free, open-source password manager
Bitwarden has had VC investors for years, long before the mentioned 2022 funding. I think our track record to date shows how we operate in this relationship. We specifically choose partners that align with our vision, not just anyone that comes off the street wanting to throw money at us (though there are many). Our health as a company afford us this luxury.

Bitwarden is and has been monetized since the beginning. There are no plans to change how we monetize our products. It's working well for us.

xxkylexx··on Bitwarden: Free, open-source password manager
The "new" CEO has been at the helm since 2019. Long before the mentioned funding in 2022.

We don't really have a HQ since we are a 100% remote company.

Source: I am the Bitwarden founder.

xxkylexx··on Hacker mods an M1 Mac mini to receive power over Ethernet instead of AC
AC, or alternating current, is a type of power. Usually available as a wall plug in your house.

DC, or direct current, is another type. For example a battery. Or in this case, PoE.

xxkylexx··on Bitwarden PINs can be brute-forced
Criticisms from this article:

>Bitwarden does not warn about this risk…… Bitwarden takes little effort in communicating the risks of choosing a short low-entropy PIN. Currently there is very little information to be found about the PIN in Bitwarden documentation

Bitwarden's help docs on using PINs: https://bitwarden.com/help/unlock-with-pin/.

>Warning: Using a PIN can weaken the level of encryption that protects your application's local vault database. If you are worried about attack vectors that involve your device's local data being compromised, you may want to reconsider the convenience of using a PIN.

xxkylexx··on Bitwarden PINs can be brute-forced
The Bitwarden docs warn users about the exact risk this article talks about. https://bitwarden.com/help/unlock-with-pin/
xxkylexx··on Bitwarden Send - A trusted way to securely share information with anyone
Browser extension updates are still rolling out
xxkylexx··on Bitwarden Send - A trusted way to securely share information with anyone
Re point #2 - You can set a max access count to 1.
xxkylexx··on Apple neutered ad blockers in Safari, and users didn't say a thing
It’s actually released now on the website.
xxkylexx··on How I Made $200k When I Was 16 Years Old Through Coding (2018)
Hey Rodney. Nice to see you on HN. - You know who :)
xxkylexx··on Firefox Lockbox – Take your passwords everywhere
> Resolution

> An option to rotate the encryption key and mac key has been added to the change password operation. Rotating the keys will generate new, random key values and re-encrypt all vault data with these new keys.

xxkylexx··on Firefox 65.0 released
The requirement is 2GB. Where do you see 4GB?
xxkylexx··on Bitwarden Completes Third-Party Security Audit
@Aquakor I am the lead developer of Bitwarden and was intimately involved in the security audit mentioned. I can understand that those two paragraphs may seem a bit concerning out of context. To provide more context, there were several points discussed between the Bitwarden developers and the auditing team about how we could redesign specific features (ex. organization user confirmations) so that the crypto implementations would be stronger and more resilient against certain attack vectors. A consensus was reached and that is what is being referenced here about re-designing things.

The purpose of an audit like this is to find issues. When issues are found, that is a good thing. We want to find problems so that they can be fixed. What would be bad is if we found issues that could not be properly fixed, or an abnormally large number of issues, neither of which was the case with Bitwarden. What I can tell you is that all issues referenced in this audit have already been resolved in very short order (the audit was only completed just last week), with relatively simple fixes, and that Bitwarden is even safer to use today than it was before.

xxkylexx··on Bitwarden Completes Third-Party Security Audit
Yes, new account keys are identified (presence of a mac key) and block the downgrade (see code link above).
xxkylexx··on Bitwarden Completes Third-Party Security Audit
It does do this [1], however, it is a little more complex since Bitwarden has to backwards-compat support old data that was AES-CBC encrypted from long ago before auth checks were implemented, while also combating against downgrade attacks. This same discussion was had back in January when you (I assume this is PIE Scott) reported the problem in issue 306171 on HackerOne which was closed out.

[1]: https://github.com/bitwarden/jslib/blob/master/src/services/...

xxkylexx··on Bitwarden Completes Third-Party Security Audit
FYI: There is also a full history of generated passwords available in each Bitwarden client app. So if you manage to lose one during the onboarding process, it should still be available in the history log.
xxkylexx··on Bitwarden Completes Third-Party Security Audit
> it doesn't have a minimum character account so it contains 'words' such as 'aa' and 'aaa'.

The PR discusses how the original word list that was referenced was changed out to the better long word list from https://www.eff.org/dice .

xxkylexx··on Bitwarden Completes Third-Party Security Audit
The report doesn't close the issue. It just provides an explanation for the current state of the issue (along with a current workaround) and details the impact of how it affects users.
xxkylexx··on Bitwarden Completes Third-Party Security Audit
The audit was literally completed last week. Immediately pressing vulnerabilities were patched and shipped while plans were established for other long term fixes for the others. This report just provides disclosure of the issues.
xxkylexx··on Bitwarden Completes Third-Party Security Audit
All AES-CBC data is authenticated with HMAC SHA-256. This was highlighted in the BWN-01-011 issue (which was determined to be a false positive since it was deemed that authentication was properly done).
xxkylexx··on Bitwarden Completes Third-Party Security Audit
> Sometimes when launching bitwarden from an app, it will only show you the logins associated with the URI for your current page. But if you're launching it from an app you can't search for the right login.

This changed with the recent release of iOS 12 autofill in Bitwarden. If there is no credential found based on the app/website address you have the ability to search the vault for it.

xxkylexx··on Bitwarden – Open Source Password Manager
There has been a standalone Windows desktop app since February. https://bitwarden.com/#download

> Especially with 1Password's ability to generate 2 factor tokens and put them in your pasteboard automatically so you don't ever have to pull up an Authenticator app!

Bitwarden also does this.

xxkylexx··on Getting 1Password 7 ready for the Mac App Store
.NET Core is just as native as Java on Linux...
xxkylexx··on Getting 1Password 7 ready for the Mac App Store
This is not correct. All of Bitwarden source code is 100% open source. Even the few features that are paid. https://github.com/bitwarden
xxkylexx··on Getting 1Password 7 ready for the Mac App Store
- https://github.com/bitwarden/browser - https://github.com/bitwarden/cli
xxkylexx··on Many packages suddenly disappeared
I had "NPM Registry:" in the title originally, but someone edited it.
xxkylexx··on Many packages suddenly disappeared
> Update - Most of the deleted packages have been restored and installation of those packages should succeed. Nine packages are still in the process of restoration. > Jan 6, 20:12 UTC

https://status.npmjs.org/incidents/41zfb8qpvrdj

Page 1 of 3Next →