TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Bitwarden Acquires Passwordless.dev

479 pointsby xxkylexxover 2 years ago

27 comments

Ajedi32over 2 years ago
Not sure if this is new information or not, but this post mentions that Bitwarden is planning to support passkeys starting in 2023.<p>That&#x27;s great, since AFAIK all existing passkey implementations are tied to a specific browser or OS, and have no way to export the keys, which isn&#x27;t great for a program designed to own the keys to your digital life. I&#x27;m hopeful Bitwarden will solve that problem, and that their example will encourage other popular password managers to do the same.<p>(...or at least, I <i>think</i> &quot;passkey support&quot; means they plan to support storing passkeys in Bitwarden itself. I hope it doesn&#x27;t just mean they want to let you use a passkey to log in to Bitwarden. That&#x27;d be really disappointing, and probably a poor choice strategically given that passkeys aim to eventually render traditional password managers obsolete.)
评论 #34436767 未加载
评论 #34432088 未加载
评论 #34431873 未加载
评论 #34436934 未加载
评论 #34435336 未加载
obblekkover 2 years ago
I really dislike the idea of giving complete access to my digital life to any company, particularly one that needs to grow quickly.<p>The tech for password vaults is so simple, I use keepass + icloud syncing and get free end-to-end encrypted password syncing, without sharing any data with anyone.<p>Outlined in more detail here: <a href="https:&#x2F;&#x2F;magoop.substack.com&#x2F;p&#x2F;how-to-manage-500-passwords-securely" rel="nofollow">https:&#x2F;&#x2F;magoop.substack.com&#x2F;p&#x2F;how-to-manage-500-passwords-se...</a>
评论 #34429833 未加载
评论 #34430908 未加载
评论 #34429497 未加载
评论 #34430443 未加载
评论 #34433212 未加载
评论 #34441647 未加载
评论 #34431843 未加载
评论 #34429294 未加载
评论 #34428881 未加载
评论 #34428863 未加载
Jack5500over 2 years ago
Slightly offtopic, but I really find the Bitwarden Clients to be lacking in the feature department. I switched to Bitwarden a few month ago and the client has evolved (for me) ever since.<p>There are a few basic features missing, such as that if I search for something I wrote in the notes of password, that the client shows the according password. I get that the open-source model implies that everyone can contribute and fix this issue, but if I look at the repo and see 108 open PRs, I don&#x27;t even bother to check if that&#x27;s a feature that would be easy to add.
评论 #34429638 未加载
评论 #34428603 未加载
评论 #34438723 未加载
评论 #34436874 未加载
评论 #34441655 未加载
评论 #34442186 未加载
评论 #34428159 未加载
jlundbergover 2 years ago
And here is a link to the web site of this startup:<p><a href="https:&#x2F;&#x2F;www.passwordless.dev&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.passwordless.dev&#x2F;</a><p>Anders Åberg (@andersaberg) who is the founder behind this is a really enthusiastic and inspiring coder. I&#x27;ve always enjoyed his mashup hackathon ideas and meetup presentations. :-)
评论 #34427949 未加载
评论 #34430968 未加载
xwowsersxover 2 years ago
Could someone clarify what the relationship between passkeys and WebAuthn is? Is it that Passkey is the Apple, Google, Microsoft <i>implementation</i> (commercialization?) of WebAuthn? If so, does it add anything on top of WebAuthn that makes it differ in some fundamental way? Also, are passkeys how WebAuthn is most commonly actually used in practice? Apologies for the noob questions.
评论 #34427986 未加载
评论 #34428316 未加载
评论 #34427893 未加载
评论 #34427833 未加载
评论 #34427904 未加载
评论 #34447045 未加载
评论 #34432727 未加载
评论 #34437466 未加载
ajcoll5over 2 years ago
Would have preferred to see the cash used for this to be used for things like app QoL improvements, an actual code audit (not just the basic network security assessments they list), or offer actual bounties for their bug &#x27;bounty&#x27; program.
Jsharmover 2 years ago
Wow this is really cool. I just tried the example on the homepage, that&#x27;s magic! No email, username or password. Can someone explain what is happening?
评论 #34428687 未加载
评论 #34428064 未加载
评论 #34428263 未加载
DangitBobbyover 2 years ago
Anyone know how Bitwarden fits into the &quot;passwordless&quot; equation here? I tried to log in to Dogwarden (shown in the video demo on passwordless.dev), but the Bitwarden extension&#x2F;app doesn&#x27;t seem to do anything during sign-up.<p>Also wondering if anyone knows why this device [1] doesn&#x27;t work during the &quot;passwordless&quot; sign-up&#x2F;sign-in process on dogwarden1.passwordless.dev. Am I going to have to buy yet another hardware key if I want passwordless logins?<p>1. <a href="https:&#x2F;&#x2F;www.amazon.com&#x2F;gp&#x2F;product&#x2F;B0773YLSY5&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.amazon.com&#x2F;gp&#x2F;product&#x2F;B0773YLSY5&#x2F;</a>
评论 #34430278 未加载
penciltwirlerover 2 years ago
One can easily self host a bitwarden server on digitalocean. <a href="https:&#x2F;&#x2F;bitwarden.com&#x2F;blog&#x2F;digitalocean-marketplace&#x2F;" rel="nofollow">https:&#x2F;&#x2F;bitwarden.com&#x2F;blog&#x2F;digitalocean-marketplace&#x2F;</a><p>However, I&#x27;m curious what y&#x27;all think about the cost. A digitalocean droplet for the recommended specs (4 GiB memory) is $24&#x2F;month. This is hard to stomach when you compare with Bitwarden Premium which is &lt;$1&#x2F;month. I guess it depends on how much you value your own data.
评论 #34428783 未加载
评论 #34428747 未加载
评论 #34428824 未加载
评论 #34429846 未加载
评论 #34432424 未加载
评论 #34428787 未加载
评论 #34432961 未加载
评论 #34485854 未加载
评论 #34436679 未加载
评论 #34428813 未加载
评论 #34428971 未加载
评论 #34428846 未加载
评论 #34428945 未加载
ohCh6zosover 2 years ago
I’m highly skeptical of Passkeys&#x2F;Webauthn as it would seem to not have the same legal protections that a password has in the US. Maybe this is me becoming a conspiracy theorist.
评论 #34428188 未加载
评论 #34428519 未加载
tr33houseover 2 years ago
I like where passwordless.dev is going. However, I don&#x27;t think I&#x27;d like to build a business on top of that. Is there a similar implementation that&#x27;s open-source that doesn&#x27;t depend on a third party?
评论 #34429694 未加载
评论 #34430149 未加载
srigiover 2 years ago
The idea of FIDO2 with HW tokens is great, but not practical if you don&#x27;t own atleast 2 pieces: - one constantly inserted into main working machine - second somewhere with the keys, ready to be used on other devices<p>You should be having third one - backup token stored securely in the safe or vault. That is $150 investment just to do it right.<p>And then - not all webapps allow to register more that one FIDO2 device, which totally cancels the above best practises.
heresjohnnyover 2 years ago
Interesting demo. What happens though if the device holding the private key is lost? Or Apple decides to shut down your iCloud? Is there a backup option, similar to backup codes for OTP?
评论 #34432055 未加载
评论 #34429444 未加载
评论 #34432586 未加载
评论 #34431893 未加载
judge2020over 2 years ago
This seems a bit odd to me - is setting up WebAuthn in your main backend so hard that an external service like this for validating credentials is required?
评论 #34428571 未加载
评论 #34431837 未加载
badrabbitover 2 years ago
Passwordless as a concept needs to die along with biometric auth.<p>You have really good newer methods of auth. Instead of selling them as good MFA alternatives security vendors decided to replace passwords because that differentiates them more. But in reality, the layer of defense &quot;what you know&quot; should be complemented not replaced. A reduction in security being sold as a feature is dishonest and harmful.
评论 #34429816 未加载
评论 #34429716 未加载
ithkuilover 2 years ago
The demo on the homepage is available only on chrome. I tried both safari and firefox on macos and I can&#x27;t see the &quot; Experience Passwordless.dev in action&quot; link there.
评论 #34432700 未加载
boringgover 2 years ago
Is this the password wars heating up? I.e. Bitwarden vs 1Password?
jacooperover 2 years ago
I still don&#x27;t understand how it works. I went into the website under authenticated using my phones API, where is my account now? There is nothing in my Bitwarden vault.
评论 #34429049 未加载
velharticeover 2 years ago
I’ve been using the keepass ecosystem for years after switching from 1password. It’s open source, highly portable, and you don’t need a degree to set it up.
评论 #34438758 未加载
Repturover 2 years ago
I&#x27;d like to see a video on how losing your device and recovery of the account works with Passwordless.
wurstehansover 2 years ago
Sounds a bit worrisome to me… Maybe I&#x27;m just overly cautious, but i guess it&#x27;s time to look around again. Has anybody checked out APass yet? <a href="https:&#x2F;&#x2F;github.com&#x2F;balu-&#x2F;a-pass">https:&#x2F;&#x2F;github.com&#x2F;balu-&#x2F;a-pass</a>
评论 #34428157 未加载
评论 #34428225 未加载
StreamBrightover 2 years ago
I am not sure how much is this better than magic link logins.
评论 #34431878 未加载
评论 #34431957 未加载
moneywoesover 2 years ago
Any idea on the multiple?
AdmiralAsshatover 2 years ago
As a recent convert to Bitwarden from LastPass, I start to get a bit nervous when I see acquisitions happening. LastPass getting acquired was the beginning of the end for it, IMO, before stagnating into criminal negligence.<p>Granted this is Bitwarden <i>acquiring</i> rather than being acquired, but I still worry it leads to a trend of building &quot;portfolio value&quot; rather than focusing on the product. I sincerely hope I&#x27;m wrong.
评论 #34428623 未加载
评论 #34427920 未加载
评论 #34427952 未加载
评论 #34428665 未加载
评论 #34427925 未加载
评论 #34427981 未加载
评论 #34433343 未加载
评论 #34429774 未加载
评论 #34427829 未加载
评论 #34434976 未加载
评论 #34432284 未加载
评论 #34429512 未加载
评论 #34430308 未加载
评论 #34434979 未加载
ubermonkeyover 2 years ago
Yeah, this is not a good sign IMO.
zackifyover 2 years ago
I own passwordless.app. I wonder if they will want to buy it from me now.
评论 #34429499 未加载
Jerrrryover 2 years ago
Your passwords shouldn&#x27;t leave your device.<p>Chrome&#x27;s password manager is pushing it.<p>Everything else should be considered malware.<p>I don&#x27;t understand how such a &#x27;techy&#x27; crowd here on HN can be so belligerent with this security vs convenience trade off.<p>KeePass locally, gmail yourself an encrypted backup. That&#x27;s it. FFS.
评论 #34429316 未加载
评论 #34429365 未加载
评论 #34429395 未加载
评论 #34429359 未加载
评论 #34430119 未加载