Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
xxkylexx
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
1.
▲
BlueBubbles – iMessage on Android, Windows, and Linux
(bluebubbles.app)
1 points
by
xxkylexx
2y ago
|
0 comments
2.
▲
by
xxkylexx
2y ago
Settings < Autofill < Click items to autofill from Vault
3.
▲
by
xxkylexx
2y ago
It's not mandatory, it's a default. I asked the help docs team to update the FAQ to include that there is an opt-out option under account settings.
4.
▲
by
xxkylexx
2y ago
It's not mandatory, it's a default. I asked the help docs team to update the FAQ to include that there is an opt-out option under account settings.
5.
▲
by
xxkylexx
2y ago
You can turn this feature off under settings.
6.
▲
Bitwarden transitions from Manifest v2 to v3
(bitwarden.com)
6 points
by
xxkylexx
2y ago
|
0 comments
7.
▲
Bitwarden Launches New Authenticator App
(bitwarden.com)
3 points
by
xxkylexx
2y ago
|
1 comments
8.
▲
by
xxkylexx
3y ago
Bitwarden has had VC investors for years, long before the mentioned 2022 funding. I think our track record to date shows how we operate in this relationship. We specifically choose partners that align with our vision, not just anyone that c
9.
▲
by
xxkylexx
3y ago
The "new" CEO has been at the helm since 2019. Long before the mentioned funding in 2022. We don't really have a HQ since we are a 100% remote company. Source: I am the Bitwarden founder.
10.
▲
by
xxkylexx
3y ago
AC, or alternating current, is a type of power. Usually available as a wall plug in your house. DC, or direct current, is another type. For example a battery. Or in this case, PoE.
11.
▲
by
xxkylexx
3y ago
Criticisms from this article: >Bitwarden does not warn about this risk…… Bitwarden takes little effort in communicating the risks of choosing a short low-entropy PIN. Currently there is very little information to be found about the PIN i
12.
▲
by
xxkylexx
3y ago
The Bitwarden docs warn users about the exact risk this article talks about. https://bitwarden.com/help/unlock-with-pin/
13.
▲
Bitwarden Acquires Passwordless.dev
(bitwarden.com)
479 points
by
xxkylexx
4y ago
|
391 comments
14.
▲
New Lightweight Deployment Option for Self-Hosting Bitwarden
(bitwarden.com)
2 points
by
xxkylexx
4y ago
|
1 comments
15.
▲
Mozilla Is Shutting Down Its Password Management App
(pcmag.com)
21 points
by
xxkylexx
5y ago
|
2 comments
16.
▲
Bitwarden Send for secure one-to-one information sharing
(bitwarden.com)
1 points
by
xxkylexx
6y ago
|
0 comments
17.
▲
by
xxkylexx
6y ago
Browser extension updates are still rolling out
18.
▲
by
xxkylexx
6y ago
Re point #2 - You can set a max access count to 1.
19.
▲
by
xxkylexx
7y ago
It’s actually released now on the website.
20.
▲
by
xxkylexx
7y ago
Hey Rodney. Nice to see you on HN. - You know who :)
21.
▲
by
xxkylexx
7y ago
> Resolution > An option to rotate the encryption key and mac key has been added to the change password operation. Rotating the keys will generate new, random key values and re-encrypt all vault data with these new keys.
22.
▲
by
xxkylexx
8y ago
The requirement is 2GB. Where do you see 4GB?
23.
▲
by
xxkylexx
8y ago
@Aquakor I am the lead developer of Bitwarden and was intimately involved in the security audit mentioned. I can understand that those two paragraphs may seem a bit concerning out of context. To provide more context, there were several poin
24.
▲
by
xxkylexx
8y ago
Yes, new account keys are identified (presence of a mac key) and block the downgrade (see code link above).
25.
▲
by
xxkylexx
8y ago
It does do this [1], however, it is a little more complex since Bitwarden has to backwards-compat support old data that was AES-CBC encrypted from long ago before auth checks were implemented, while also combating against downgrade attacks.
26.
▲
by
xxkylexx
8y ago
FYI: There is also a full history of generated passwords available in each Bitwarden client app. So if you manage to lose one during the onboarding process, it should still be available in the history log.
27.
▲
by
xxkylexx
8y ago
> it doesn't have a minimum character account so it contains 'words' such as 'aa' and 'aaa'. The PR discusses how the original word list that was referenced was changed out to the better long word list
28.
▲
by
xxkylexx
8y ago
The report doesn't close the issue. It just provides an explanation for the current state of the issue (along with a current workaround) and details the impact of how it affects users.
29.
▲
by
xxkylexx
8y ago
The audit was literally completed last week. Immediately pressing vulnerabilities were patched and shipped while plans were established for other long term fixes for the others. This report just provides disclosure of the issues.
30.
▲
by
xxkylexx
8y ago
All AES-CBC data is authenticated with HMAC SHA-256. This was highlighted in the BWN-01-011 issue (which was determined to be a false positive since it was deemed that authentication was properly done).
More ›