Bitwarden second security audit report
bitwarden.com
Bitwarden second security audit report
1–10 of 118 posts
Re: Bitwarden second security audit report
#2Re: Bitwarden second security audit report
#3Can someone with security industry knowledge comment on how much weight we should give this? Are these sorts of things something you can just buy and they'll go out of their way to give you a favourable report because you're the client? Is Insight Risk Consulting known and credible?
They found something worth fixing, despite the project being open source wit bug bounties and previous audits being made.
Re: Bitwarden second security audit report
#4Re: Bitwarden second security audit report
#5Can someone with security industry knowledge comment on how much weight we should give this? Are these sorts of things something you can just buy and they'll go out of their way to give you a favourable report because you're the client? Is Insight Risk Consulting known and credible?
Such companies sometimes offer a range of penetration testing options from relatively superficial to aggressive, in-depth, and detailed, so you'd need to read the report (I will when I have more time as we are considering Bitwarden for our credential management) to see if what it is saying is sufficiently reassuring.
Re: Bitwarden second security audit report
#6Can someone with security industry knowledge comment on how much weight we should give this? Are these sorts of things something you can just buy and they'll go out of their way to give you a favourable report because you're the client? Is Insight Risk Consulting known and credible?
That happens.
I can't comment on Insight Risk Consulting, as I don't know that company. They write they had a previous audit from Cure53. That's a well known and very skilled security company and I would expect that you can't buy an "please ignore as many vulns as possible" report from them.
Re: Bitwarden second security audit report
#7Re: Bitwarden second security audit report
#8Can someone with security industry knowledge comment on how much weight we should give this? Are these sorts of things something you can just buy and they'll go out of their way to give you a favourable report because you're the client? Is Insight Risk Consulting known and credible?
Does it matter? They found something worth fixing, despite the project being open source wit bug bounties and previous audits being made.
Being open source just increases the chance of a problem being spotted if there are sufficiently clue-up people looking. Being open does not at all guarantee that any given problem will be spotted during the normal course of work. Security issues can be dues to combinations of flaws in widely spaced code so even if working directly on one part you might not realise there is an issue in conjunction with another part. That is why it is necessary to have tests/audits like this, for oth open and closed source systems, where someone is task specifically to look for security problems.
It isn't right to criticise Bitwarden for being tested and issues being found (unless those issues are systemic and/or just plain stupid, or you believe the project's response to resolve them is too slow or incomplete). Instead concern should be aimed at security related products that are not regularly subject to external audit at all. Not having any issues because you have not checked for them is a much greater worry!
Re: Bitwarden second security audit report
#9Earlier quoted context omitted.
Does it matter? They found something worth fixing, despite the project being open source wit bug bounties and previous audits being made.
That has nothing to do with it being open source. In close-source systems I've seen penetration testers find security issues that have been present for years despite annual audits during that time. This is one of the reasons why our services get at least annual penetration testing, even the legacy ones that won't have changed since the last test. It is not a bad idea to cycle through providers too, on the off chance…
That, despite the software being open-source and therefore more likely to have bugs spotted, and despite having a bug bounty program, the auditing company found a moderate, therefore they must be thorough.
Re: Bitwarden second security audit report
#10Earlier quoted context omitted.
That has nothing to do with it being open source. In close-source systems I've seen penetration testers find security issues that have been present for years despite annual audits during that time. This is one of the reasons why our services get at least annual penetration testing, even the legacy ones that won't have changed since the last test. It is not a bad idea to cycle through providers too, on the off chance…
I think that was the point of the previous comment. That, despite the software being open-source and therefore more likely to have bugs spotted, and despite having a bug bounty program, the auditing company found a moderate, therefore they must be thorough.