Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What if, for example, a piece of software is logging your key presses without your knowledge? You could have the best, most secure password but you're typing it into a complex machine which could be doing any number of things. Don't forget that you're human and make mistakes too so it doesn't necessarily have to be malicious; a bad copy paste into a public forum post could hose you.

A second factor makes it extremely unlikely that one slip up results in a complete compromise of your vault.



> What if, for example, a piece of software is logging your key presses...

Even easier: What if someone beats you with a stick until you unlock your password manager?

Security is always a compromise around a lot of assumptions about threat model, usability, etc.

Nudges are a great way to increase overall user security with almost no drawbacks, but ofc ultimately things like this always have to be user choice.


I think what you're forgetting is that Bitwarden only has access to my passwords, not any account (that does any important work) itself.

All my high security accounts themselves are protected by 2FA and in some cases 2+ factors (such as my bank).

2FA on a password manager is useless. I'm going to end up entering phone codes multiple times for a single login and that will drive me away from using the password manager.


If there is software that is logging my keys it can also likely steal my cookies, in which case they don't even need any of my passwords or 2FA codes.


You don't even need a keylogger for password leakage. You could accidentally type in your password into a logged field because you forgot to press tab or alt-tab to move cursor focus.

2FA for setup doesn't strike me as too onerous. It only happens once per device, after which you're free to rely on just your master password or even biometrics.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: