# iPhone Passwords app

**URL:** https://discuss.privacyguides.net/t/iphone-passwords-app/20912
**Category:** Questions
**Tags:** software
**Created:** 2024-09-15T17:00:38Z
**Posts:** 39

## Post 1 by @0xboy — 2024-09-15T17:00:38Z

![IMG_0293](//forum-uploads.privacyguidesusercontent.com/original/2X/6/67ba9f99d79d94dedf1e1fd2cd134d61ab220d6e.webp)

I used Bitwarden before, but when iOS 18 came out with a password manager, I switched. This app is smooth and does everything I need from password management to 2FA. The only thing I need is to remember my Apple account, the other passwords are taken care of by that app.

I love Bitwarden and have been using it for a long time. Its value is open-source but I’m still afraid that one day their server gets hacked or their data gets breached like Lastpass. I am so confident in Apple’s security that I leave my account data here.

---

## Post 2 by @fria — 2024-09-15T17:04:19Z

I’ve been using the built in password manager for a while but this one is a big upgrade for sure. I don’t think you need to worry about bitwarden getting hacked since it’s all e2ee, unless you use their web client.

---

## Post 3 by @0xboy — 2024-09-15T17:09:18Z

yeah i know bro but I didn’t do self-host bitwarden. I do save passwords through their servers so that’s why I was afraid

---

## Post 4 by @anon36940904 — 2024-09-15T17:36:32Z

So you’re trusting proprietary security more than open source software?

Well, you do you but the general advice is to always go with open source as they are vetted pieces of technology.

---

## Post 5 by @anon48875053 — 2024-09-15T17:57:14Z

Read about E2EE.

---

## Post 6 by @0xboy — 2024-09-15T18:24:45Z

Thanks but what if bitwarden server got hacked, hacker got my info and they could decrypt it ?

---

## Post 7 by @0xboy — 2024-09-15T18:25:18Z

I mean who could hack apple ? :thinking:

---

## Post 8 by @fria — 2024-09-15T18:30:22Z

No. They would have to hack Bitwarden and serve you malicious JavaScript on their web app. Bitwarden themselves don’t have access to your data so an attacker that breaches their servers also doesn’t.

---

## Post 9 by @0xboy — 2024-09-15T18:32:53Z

Thanks  
What about 2FA  
Which is da best option on iPhone ?

---

## Post 10 by @overdrawn98901 — 2024-09-15T21:36:02Z

> [@0xboy](#):
>
> they could decrypt it ?

From [Bitwardens docs](https://bitwarden.com/help/what-encryption-is-used/#aes-cbc):

> Bitwarden uses [AES-CBC](https://bitwarden.com/help/what-encryption-is-used/#aes-cbc) 256-bit encryption for your vault data, and [PBKDF2](https://bitwarden.com/help/what-encryption-is-used/#pbkdf2) SHA-256 or [Argon2](https://bitwarden.com/help/what-encryption-is-used/#argon2id) to derive your encryption key.
> 
> Bitwarden **always** encrypts and/or hashes your data on your local device before anything is sent to cloud servers for storage. **Bitwarden servers are only used for storing encrypted data.** For more information, see [Storage](https://bitwarden.com/help/data-storage/).  
> …  
> AES-CBC  
> [AES](https://en.wikipedia.org/wiki/Advanced_Encryption_Standard)-CBC [(cipher block chaining)](https://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Cipher_block_chaining_(CBC)), used to encrypt vault data, is a standard in cryptography and used by the US government and other government agencies around the world for protecting top-secret data. With proper implementation and a strong encryption key (your master password), AES is considered unbreakable.

TLDR; if your master password is strong, you are fine. If an attacker hacked birwarden servers, they would probably dump millions of accounts and yours blend in with everyone else. If someone wanted to crack your encrypted data, I’d imagine it would take a government level threat and decades before it gets decrypted.

As is a rite of passage, I have to post this obligatory comic.

 ![security](//forum-uploads.privacyguidesusercontent.com/original/2X/b/bb5b553ab292f19602541fc1eb8dcbe4f10ee294.png)

---

## Post 11 by @Bhaelros — 2024-09-15T21:43:05Z

Advanced Data Protection with 2 security keys

---

## Post 12 by @fria — 2024-09-15T21:43:29Z

Passwords are E2EE with or without ADP.

---

## Post 13 by @anon36940904 — 2024-09-15T21:48:34Z

Or so they claim

---

## Post 14 by @anon36940904 — 2024-09-15T21:48:58Z

Perhaps you should learn of Pegasus

---

## Post 15 by @overdrawn98901 — 2024-09-15T21:55:15Z

> [@0xboy](#):
>
> yeah i know bro but I didn’t do self-host bitwarden. I do save passwords through their servers so that’s why I was afraid

If you backup your passwords on iCloud, you are also saving this data on someone else’s server. All you’ve done is shift trust from one entity to another. Arguably, I’d trust Bitwarden over iCloud any day if the threat model involves police or government agency. Otherwise, it’s probably a neutral move.

---

## Post 16 by @fria — 2024-09-15T21:58:14Z

The point of E2EE is you don’t need to trust the server.

---

## Post 17 by @fria — 2024-09-15T21:59:15Z

Bitwarden wont protect you from Pegasus. They werent decrypting your data on Apple’s servers they were attacking your phone itself.

---

## Post 18 by @Rasta — 2024-09-15T21:59:46Z

Did they make it easier to export your passwords from the app? Previously to export your keychain it required a Mac and that’s part of the walled garden keeping you using their products because not everyone with an iPhone has access to a Mac.

---

## Post 19 by @overdrawn98901 — 2024-09-15T21:59:47Z

Correct. Hence why I said it was probably a net neutral move for OP.

---

## Post 20 by @Bhaelros — 2024-09-15T22:12:44Z

Yes, but 0zboy asked for 2FA. ADP is the best option for 2FA and additional protection.

---

## Post 21 by @fria — 2024-09-15T22:18:37Z

ADP doesn’t have anything to do with 2FA. 2FA codes to your phone is on by default and you can set up hardware security keys if you want.

Maybe you’re thinking of Google’s Advanced Protection Program.

---

## Post 22 by @Bhaelros — 2024-09-15T23:49:03Z

To activate Apple ADP you need to provide two security keys. Won‘t these count as 2FA too?

---

## Post 23 by @fria — 2024-09-15T23:52:55Z

You don’t have to set up two security keys you just need to set up a recovery method which isn’t 2FA.

---

## Post 24 by @Bhaelros — 2024-09-16T00:01:20Z

Hmm, I need to check it again because last time I activated it, it asked for two security keys on my iPhone

---

## Post 25 by @fria — 2024-09-16T00:03:09Z

Did you previously set up your security keys? I just did it and all I had to do is set up a recovery method.

---

## Post 26 by @Bhaelros — 2024-09-16T00:04:32Z

I did it with two keys before, was several months ago. Today I will try with my wife‘s phone and let you know.

---

## Post 27 by @fria — 2024-09-16T00:06:43Z

> **[How to turn on Advanced Data Protection for iCloud - Apple Support](https://support.apple.com/en-us/108756)**
>
> Advanced Data Protection for iCloud offers our highest level of cloud data security and protects the majority of your iCloud data using end-to-end encryption.

Apples documentation doesn’t mention needing a security key.

---

## Post 28 by @anon73250778 — 2024-09-16T06:01:52Z

This could be looked at an eggs-in-one-basket kind of situation.

_If you had no other copy_ of the password database, you would be locked in _ **all** _ of your accounts had you only relied on one provider (in this case Apple).

Or if someone maliciously filed a complaint to Apple about you and you do not have access to your email or any other kind of service. You also could not ask for a support ticket or have great difficulty in getting one.

---

## Post 29 by @fria — 2024-09-16T06:25:53Z

It’s not anymore than Bitwarden. You lose access to Bitwarden somehow then all your passwords are gone as well. If someone “maliciously files a complaint” to Bitwarden then I guess you’re toast too.

To lose access to you Apple passwords you’d need to somehow not be able to log in to any of your devices and also lose your recovery method and not be able to log in to your iCloud. I don’t know what maliciously filing a complaint is, if that’s ever happened I’d love an example and an explanation why it doesn’t also apply to Bitwarden.

---

## Post 30 by @Tech-Trooper — 2024-09-16T10:56:16Z

This is true for all apps. There was a guy who locked up his proton pass account. :grinning_face: So, you need to keep backups irrevelant of the service you use.

---

## Post 31 by @Bhaelros — 2024-09-16T11:19:15Z

You are right. Finally did the testing with wife’s iPhone and it didn’t ask for two security keys. It is weird because I bought my Yubikey pairs just for this

---

## Post 32 by @anon73250778 — 2024-09-16T12:24:17Z

> [@fria](#):
>
> To lose access to you Apple passwords you’d need to somehow not be able to log in to any of your devices and also lose your recovery method and not be able to log in to your iCloud.

No, it could be as simple as a false positive flag of CSAM and you’d get insta ban wrongly. Or a government requesting to Apple to (maybe temporarily) suspend your account.

---

## Post 33 by @fria — 2024-09-16T14:24:41Z

They don’t do CSAM scanning it was never implemented. Again they could just as easily ban your Bitwarden account. The passwords are local to your phone anyway so actually they couldn’t do that. The worst that could happen is you lose iCloud syncing I suppose in the event that the government decides to step in and suspend your account? Has that ever actually happened before?

---

## Post 34 by @anon70581596 — 2024-09-18T16:01:03Z

Relaying on Apple Passwords forces you to upgrade all your devices periodically.  
I encountered this problem myself when I wanted to enable ADP but had an old MacBook that couldn’t be updated to the latest macOS that support it, by enabling ADP I couldn’t access my passwords on my Mac so I moved to Bitwarden.

---

## Post 35 by @fria — 2024-09-18T16:09:36Z

Passwords are always E2EE don’t need to enable ADP. True though at some point if your computer is old enough it probably won’t be able to sync properly, although you should ideally be using a supported machine anyway.

---

## Post 36 by @anon70581596 — 2024-09-18T16:15:30Z

Passwords are E2EE but enabling ADP encrypts even more Apple services.  
Back then when I enabled ADP I was forced to unlink the device from my Apple ID so I couldn’t sync anything including my Passwords.

---

## Post 37 by @Tech-Trooper — 2024-09-18T22:32:59Z

From the pure security point, your whole system is vulnerable when you use a system including other password managers, which does not get security updates.

---

## Post 38 by @arandomduck — 2024-09-19T05:47:06Z

This message could have been perfectly sarcastic, but I know it’s not. Let’s be honest: Apple has done a great job of making normies believe that they care about user privacy and their systems are very secure. I myself am an apple user, too, but this belief is far from the truth. Read this:

> **[Apple Data Breaches: Full Timeline Through 2023](https://firewalltimes.com/apple-data-breach-timeline/)**
>
> On July 10, Apple patched a zero-day vulnerability in their devices, and acknowledged that it may have been exploited by hackers. You can find a full list of security updates on Apple’s website. Below…

---

## Post 39 by @fria — 2024-09-19T07:21:32Z

Every system has vulnerabilities and Apple devices are widely used so therefore highly targeted. Doesn’t mean they’re not secure.
