Anders Åberg

2.6K posts

Anders Åberg banner
Anders Åberg

Anders Åberg

@andersaberg

I like to build and learn, in that order. Creator of https://t.co/0XVfx0047h, https://t.co/VjowmSVisI. Now at Bitwarden. Ex CTO @ Caspeco

Sweden Katılım Ocak 2010
452 Takip Edilen729 Takipçiler
Johannes Mauerer
Johannes Mauerer@johannesmauerer·
I built a secret broker for an AI agent today. @Bitwarden's BWS CLI fetches credentials from a remote vault, but only after I tap approve on a phone notification. Sounds great, right? Except the secret still lands in the agent's process memory to be useful. And the agent has full system access.
English
2
0
1
89
Moxie Marlinspike
Moxie Marlinspike@moxie·
I've been building Confer: private AI chat where your conversations are end-to-end encrypted so that only you can access them. It's still new, but I've been using it every day and beta testing it with friends. Let me know what's missing! confer.to/blog/2025/12/c…
English
61
79
418
69.4K
Anders Åberg
Anders Åberg@andersaberg·
@moxie I hear you! It’s planned but we have some blockers we need to roll out before we ship prf
English
2
0
1
408
Moxie Marlinspike
Moxie Marlinspike@moxie·
@andersaberg Lots of people have been wanting to use Confer with Bitwarden, and right now the only advice I can give them is to use a different authenticator. Would be great if Bitwarden released passkey prf support!
English
1
0
3
186
Anders Åberg
Anders Åberg@andersaberg·
@ColeMickens @Bitwarden Creating a passkey should be instantaneous, will run some tests with corrupted network and see if we can repro the faulty conditions. Was browser and browser extension version did you use?
English
1
0
0
44
Anders Åberg
Anders Åberg@andersaberg·
@ColeMickens @Bitwarden Hi Cole, I work at Bitwarden and do a lot of work on passkeys. What you're describing sounds like a very unexpected behaviour. Bitwarden should not "loose" your passkeys, even if your client is offline. We store your ciphers locally and sync them once your client reconnects.
English
2
0
0
38
Anders Åberg
Anders Åberg@andersaberg·
@moxie @Bogorad @Bitwarden @signalapp Yes that’s right. Yeah, the number of sites that use PRF has been very limited so we’ve prioritized other passkey feature over extensions historically.
English
1
0
1
172
Moxie Marlinspike
Moxie Marlinspike@moxie·
Ah thanks, I saw bitwarden.com/blog/prf-webau… and didn't read it closely enough; you're using PRF to generate your own key material from the platform authenticator, but don't yet support PRF for apps using Bitwarden as the authenticator? Would be great if you added support so Confer could work for Bitwarden users =)
English
2
1
2
510
Anders Åberg
Anders Åberg@andersaberg·
@moxie @Bogorad @Bitwarden Hey @moxie. I work on passkeys at Bitwarden. We currently don’t support passkeys with extensions like PRF in the vault (we do support PRF for login+unlock) Happy to see a good reason to implement vault support with @signalapp.
English
2
0
2
208
Anders Åberg
Anders Åberg@andersaberg·
@somoscode Hey Rafael, the challenge needs to be generated randomly to remain secure. The challenge is generated as part of the assertion/attestation-options.
English
1
0
1
56
Rafael Dominguez
Rafael Dominguez@somoscode·
@andersaberg Hi Anders, I'm checking out your FIDO2 .net library and was trying to figure out where the challenge issued by the rp is being created. I was hoping to test with custom challenge. Thanks.
English
1
0
0
51
Felix Magedanz
Felix Magedanz@flxmgdnz·
@zenorocha Passkey auth helps you get rid of passwords in your database. The fastest way would be to use @hanko_io’s passkey provider for Next-Auth.
English
1
0
1
677
Zeno Rocha
Zeno Rocha@zenorocha·
We’re currently reevaluating all of our security tech stack. Question - What are your favorite security tools/vendors?
English
54
3
190
86.9K
Anders Åberg
Anders Åberg@andersaberg·
@akella Fun! Yeah this would be for fun, so we can adjust time as needed. What’s your email? I’ll send some more thoughts and details.
English
1
0
0
44
akella
akella@akella·
@andersaberg sure! im up for something fun! depends on deadlines/amount of course too =)
English
1
0
0
54
Anders Åberg
Anders Åberg@andersaberg·
@akella Hey Yuri, hope all is well. I’m working on some creative data visualizations for fun, was wondering if you’d want to collaborate on the visualization part! Let me know, I always enjoy seeing your work.
English
1
0
0
48
Anders Åberg
Anders Åberg@andersaberg·
@AgnesWold Tack för svar, även om tolkningen av studien är lite klurig för en lekman. Känner du till några studier av fysikaliska/syntetiska solskydd? Specifikt Titaniumdioxid verkar ju diskuterat som cancerogent vid inandning, dock inte hittat studier. Kanske en fråga för er podd?
Svenska
2
0
0
114
Anders Åberg
Anders Åberg@andersaberg·
@AgnesWold Hej Agnes! Vi hade en diskussion i helgen och behöver lite vetenskaplig input. Hur är det egentligen med faran med sol vs. solkräm? Efter lite läsande på internet framstår ju solkräm som superfarligt, oavsett kemiska/fysikaliska. Vad säger vetenskapen?
Svenska
1
0
1
146