Live data from Hacker News

Bitwarden second security audit report

bitwarden.com

21–30 of 118 posts

Re: Bitwarden second security audit report

#21

What does it cost to hire somebody reputable to perform an audit like this? Its something I want to look into for one of my own projects, but I have no frame of reference for what is a reasonable price for a simple full stack app (way simpler than bitwarden for sure)

Just ask them. Cure53 is one of the most reputable one's, and remember always make white-box testing, you want to test your system, NOT the security researcher.

Re: Bitwarden second security audit report

#22

What does it cost to hire somebody reputable to perform an audit like this? Its something I want to look into for one of my own projects, but I have no frame of reference for what is a reasonable price for a simple full stack app (way simpler than bitwarden for sure)

We (https://www.bullet-train.io/) recently had a third party perform a pretty in depth security audit - cost was low to mid 4 figure Euro. Result was a ~20 page report - I felt it struck the right balance of cost / effectiveness.

Re: Bitwarden second security audit report

#24

What does it cost to hire somebody reputable to perform an audit like this? Its something I want to look into for one of my own projects, but I have no frame of reference for what is a reasonable price for a simple full stack app (way simpler than bitwarden for sure)

Pentester for 10 odd years: usually for an external test you would scope it at X days depending on the number of IPs etc. And it should note that an external test really doesn't find much. External is usually £750/day for 1-2 days testing and one reporting. Internal testing (ie. Auditing a domain and all computers attached) is about the same price, maybe a bit more, and takes a bit longer usually. A build review is hardening the server itself, takes about a day and a day reporting. App testing is totally dependent on the app itself (this is where people have a crack at an actual installed web application usually using user accounts etc. And runs a bit more - £800+ per day usually. Specialist stuff (hardware testing, code review (what I used to do), social engineering, hardcore app testing (stuff like auditing bespoke network devices, high frequency trading apps, etc. Etc.)) is typically 1-1.2k a day.

You can get it cheaper but a lot of it - for better or for worse - really comes down to the skill of the individual consultant. You can pretty much halve these prices, but then you'd end up getting stuff outsourced to India and it wouldn't be any good. Depends if you care about the security of your product or just want a box ticked for some arbitrary compliance and want it done as cheap as possible.

I haven't been a tester/consultant for a few years now, but the prices hold up. That being said one development which has happened since I've left the industry is the advent of crowd sourced pentesting. I know a lot of friends who moonlight with these things and are very good at their jobs, and the rates are lower. The name crowd strike comes to mind, but I'm not 100% sure if that was the company or not. I know a lot of good UK based companies (if it's a web app/remote then the physical testers location doesn't matter) if you needed.

Re: Bitwarden second security audit report

#25
post #17

Tangential question: What password manager do you guys use?

Bitwarden. Works well and the integration with 2FA/TOTP is amazing. I highly recommend to not rely on a single (mobile) device for 2FA. Loosing or breaking it might shut you out of certain accounts forever.

Same, used to be LastPass but the more I learned about them as an entity I realised that they were not what they once were and I switched to Bitwarden.

I also found this suited my devices and usage, Linux, Android, Mac, Windows... happy across the board.

Also... employers tend not to use Bitwarden, they pick 1Password or LastPass, so it means I can have both work and personal on my BYODs.

Re: Bitwarden second security audit report

#27

Can someone with security industry knowledge comment on how much weight we should give this? Are these sorts of things something you can just buy and they'll go out of their way to give you a favourable report because you're the client? Is Insight Risk Consulting known and credible?

This was an external infrastructure test which carries no real weight for the app itself. It just makes sure that stupid stuff like ssh open to the internet, no public CMS available etc. Hasn't happened. That being said bitwarden do do more in depth security audits but this particular audit doesn't really mean too much.

Re: Bitwarden second security audit report

#29
post #17

Tangential question: What password manager do you guys use?

Bitwarden. Works well and the integration with 2FA/TOTP is amazing. I highly recommend to not rely on a single (mobile) device for 2FA. Loosing or breaking it might shut you out of certain accounts forever.

I find Authy on a mobile and desktop with backup turned on seems like solid enough 2FA redundancy.
Post reply on HN