Password managers

Commissario
Joined
16 Oct 2002
Posts
2,829
Location
In the radio shack
"On September 29, we detected suspicious activity on our Okta instance that we use to manage our employee-facing apps. We immediately terminated the activity, investigated, and found no compromise of user data or other sensitive systems, either employee-facing or user-facing."

 
Sgarrista
Commissario
Joined
9 Aug 2013
Posts
10,450
Location
Bromsgrove
Today is the day I finally nuked my crappass account.

Have been using proton exclusively for the last month and zero issues. Not missing anything from lastpass at all.
 
Soldato
Joined
11 Oct 2009
Posts
16,591
Location
Greater London
I'm starting to notice more services rolling out passkeys. Bitwarden just recently updated both their US and EU servers to support it, and according to their X account the clients should be updated within a couple of days.

I'm still a bit confused with passkeys, are they meant to replace both passwords and 2FA?
 
Sgarrista
Commissario
Joined
9 Aug 2013
Posts
10,450
Location
Bromsgrove
I'm starting to notice more services rolling out passkeys. Bitwarden just recently updated both their US and EU servers to support it, and according to their X account the clients should be updated within a couple of days.

I'm still a bit confused with passkeys, are they meant to replace both passwords and 2FA?

Yes.

Think of a 2fa as a "backup" to your password. Even if the password is compromised the 2fa keeps people out.

Passkeys does away with the weakness of a password as it is end to end encrypted from your device to the service.
 
Associate
Joined
27 Jan 2022
Posts
667
Location
UK
I've been considering getting a password manager but it just seems like a matter of time before whichever service I chose gets compromised.
Hah yes I had used Lasspass and another for a while until a couple of years ago when they started getting hacked and encrypted passwords leaked.

I've been using Google/Chrome to save passwords plus MFA for more important accounts, plus I use a Pixel phone so it makes sense for me. If Google is ever hacked the whole world is screwed.

Just remember to transfer the MFA accounts correctly when transferring to a new phone.
 
Associate
Joined
8 Sep 2011
Posts
1,893
Location
Northern Ireland
Im liking passkeys very much. Started using yubikeys last october and have it setup as passkeys for accounts that support it. Cant wait for bitwarden to have full support for it
 
Last edited:
Sgarrista
Commissario
Joined
9 Aug 2013
Posts
10,450
Location
Bromsgrove
I've been considering getting a password manager but it just seems like a matter of time before whichever service I chose gets compromised.

Protons security model is a bit more secure than other password managers.

Every item in a vault is individually encrypted. (including metadata)
Each vault is individually encrypted.
And then your account itself is secured using bcrypt, end to end encryption, TOTP if you have it enabled, and argon2id and passkeys coming soon.

The top item is the most important, as even if proton is compromised, hackers wont be able to see "Online banking login" or "My 2 million bitcoin seed phrase". It will just be hashed information.

Im liking passkeys very much. Started using yubikeys last october and have it setup as passkeys for accounts that support it. Cant wait for bitwarden to have full support for it


Last time I checked yubikeys had a limited number of passkeys they can support, as well as no ability to create backups? Has that changed?
 
Last edited:
Associate
Joined
8 Sep 2011
Posts
1,893
Location
Northern Ireland
Didnt know about the passkey limit but i have not encountered it yet. So far i enrolled only a handful of passkeys.

For backup, i have a separate yubikey that is also registered as a passkey. No cloning feature though so had to register the 2 keys.
 
Soldato
Joined
13 Mar 2007
Posts
13,528
Location
South Yorkshire
So far so good with Proton Pass and importing from Bitwarden, few websites that it's not detecting the login form to autofill (i.e no icon appearing) that Bitwarden does detect and fill.
 
Soldato
Joined
29 Apr 2004
Posts
4,891
Location
Bath
Anyone else been creating passkeys? I used watchtower in 1Password to find all the supported logins and create passkeys for each. It always seems to fallback to the password login though, shouldn't all the sites and apps provide an option to actually delete the password leaving only the passkey for login?
 
Man of Honour
Joined
20 Sep 2006
Posts
34,046
Anyone else been creating passkeys? I used watchtower in 1Password to find all the supported logins and create passkeys for each. It always seems to fallback to the password login though, shouldn't all the sites and apps provide an option to actually delete the password leaving only the passkey for login?
Very few support true passwordless (is that even a word?), Microsoft do it and I think Google do.
 
Soldato
Joined
1 Nov 2008
Posts
4,413
Be careful as some sites apparently disabled 2FA when you enable passkeys, namely Github. Not sure if they fixed this yet.

I've avoided them for the time being, I should probably experiment with one or two sites though.
 
Soldato
Joined
1 Nov 2008
Posts
4,413
lol, just used the exposed passwords report tool in bitwarden and I had the password admin for something local I was testing, exposed nearly 2M times :eek: :D

uFTI31D.png
 
Soldato
Joined
18 Aug 2007
Posts
9,710
Location
Liverpool
Anyone else been creating passkeys? I used watchtower in 1Password to find all the supported logins and create passkeys for each. It always seems to fallback to the password login though, shouldn't all the sites and apps provide an option to actually delete the password leaving only the passkey for login?
I use passkeys everywhere they're available. They're much better security wise (cryptographic single-use certificate based pukbey auth), and they're painless for the user. I generally set up two passkeys per service to be safe, one in Vaultwarden (self-hosted Bitwarden) and one on my iCloud Apple Keychain. That way, every site I visit with a passkey has the Bitwarden addon pop up with the key as soon as I hit the login page, but if I'm ever somewhere on a shared computer, or somehow Vaultwarden is unavailable, I have a backup that works anywhere using my phone's camera. I love them.

Be careful as some sites apparently disabled 2FA when you enable passkeys, namely Github. Not sure if they fixed this yet.

I've avoided them for the time being, I should probably experiment with one or two sites though.
I have Yubikey, OTP and passkeys enabled on Github and they all work. I just use whichever I get to first (press my Yubikey or hit enter on the Bitwarden popup if it 'wins').
 
Back
Top Bottom