The Easiest (and MOST SECURE) Way to Log into Bitwarden

Published 2023-10-01
Bitwarden is winning the security game against other password managers. They recently updated their security settings to allow anyone (paid or free) to implement FIDO2 WebAuthn as 2FA.

This makes it easier to log in AND more secure.

Update your settings today!

📝 Sign up for my free weekly security newsletter: weekendbyte.teachmecyber.com/

Links
Bitwarden: bitwarden.com/
Passkeys Overview:    • What are Passkeys? | Are Passwords De...  

📝 Sign up for my free weekly security newsletter: weekendbyte.teachmecyber.com/

❤️ Leave a comment and hit the like button because it helps spread cyber security knowledge to more people.

Table of Contents
00:00 - Intro
00:19 - FIDO2 / WebAuthN
00:40 - Passkey Overview
01:56 - Flexible Security
03:11 - Phishing Resistant
04:12 - Setup Instructions
06:31 - Login Test
07:04 - Best Practices
08:20 - Closing

🔔If you found this helpful, subscribe to the channel!
youtube.com/@teachmecyber?sub_confirmation=1

🚀 Connect with me on LinkedIn
www.linkedin.com/in/jrebholz

FREE Bitwarden Security Update | Do This TODAY! | FIDO2 WebA

All Comments (21)
  • Great tutorial, I just subscribed but I am very puzzled by this. It sounds great but when I try to do it on my Win11 PC it seems the Bitwarden setup requires me to use a security key such as Yubikey which I don't have and which doesn't appear to have happened for you.
  • @TromboneAl
    Excellent, thanks. Is it possible to use a Yubikey on one device (e.g. on my iMac which doesn't have biometrics) and a passkey on another (e.g. on my tablet)?
  • @AWalterDavies
    Thanks, but when I try to set up WebAuthn on my Mac in Safari, and press the Read Key buttom, it gives me a choice of the Safari Passwords page or a Hardware key - no mention of BitWarden Vault. Am I doing something wrong?
  • Hello. You could make a short explainer video on how to store passkeys in Bitwarden (if this option is already enabled); something similar to the video from a few days ago where you explained how to do it with 1Password. Greetings and blessings from Cuba, learning many from your videos 🙏🏼 Hola. Puede hacer un breve video explicativo sobre cómo almacenar claves de acceso en Bitwarden (si esta opción ya está habilitada); algo similar al vídeo de hace unos días donde explicabas cómo hacerlo con 1Password. Saludos y bendiciones desde Cuba, aprendiendo muchas de sus videos 🙏🏼
  • @StijnHommes
    If a passkey is linked to a specific domain, won't that cause a lot of hassle in setting up new passkeys whenever a site decides to change their domain? I've had it happen rarely, but every time it happens, it's a pain in the backside. Also, device-bound passkeys are a pain when you get a new phone and have to set up new keys for all the sites that had a key linked to your old phone...
  • @Shining6074
    Jason what is the naming convention of the passkey for the vault? Is it a password or phrase? Enjoy your videos, thanks
  • @Rednunzio
    The passkey in this example is associated with Chrome and no other device, right? Only from that device can I use it until I add another one. So it doesn't support multi device passkey? If I saved that passkey to a password manager like 1password I wouldn't be able to use it from all the devices that have the 1 password vault synced. There is a bit of confusion about these new passkeys and they seem promising but they should become the only way to log in because if they are an alternative the risks are the same. Sorry for the novel 😆
  • @RedStarSQD
    if you did have 3 mfa pathways setup for backup, then what happens if you do lose your mfa on a lost or stolen phone? wouldn't that defeat your stronger mfa when the hacker now has your phone? Would it be better not to have mfa on your phone now?
  • @jetblast00
    My desktop has no Bio-metric capabilities. The WebAuthN is asking for a USB to continue. Is a Yubi Key required to setup? I don't see an option to just enter a password to authorize the public key.
  • @theothirsk4533
    I have several gmail accounts for personnel, business and two organizations. I use MacBook (10 years old, iPad Pro (4 years old) desktop PC (1 year) and android phone (less than 6 months). Do I need separate accounts for each gmail account?
  • @nonielon
    but what if your email was already has malwer and that email has already the bait of phishing and you go get passkeys and the person or owner dosent know anthing that the email has virus,hacker,scammers...got all info that will be game over to the owner of the gadgets? like me i dont know if my email has virus and my facebook got hacked...
  • @Gorky25
    I don't have security usb key, it asks me to enter win pin, it is 4 digits, is it ok to use it?
  • @streampalace
    Thanks for the great video. I have Bitwarden Premium. I have two YubiKeys. A master key and a backup key. Is the premium version worth it if Fido is also available in the free version?
  • Can Bitwarden ask for login/password AND otp app code AND hardware key ?
  • Why did you not show how to set your phone as a second webauth passkey?
  • @wildmanofborneo
    Hello Bitwarden won't recognize a login page that only asks for the username (once the username is entered, the NEXT page asks for the password). How to get Bitwarden to recognize this situation? It works ok if the page asks for both the username and password.