Live data from Hacker News

Bitwarden second security audit report

bitwarden.com

41–50 of 118 posts

Re: Bitwarden second security audit report

#41

Tangential question: What password manager do you guys use?

KeePass.

This! Just sync your keepass file with your NextCloud (or Google Drive or whatever) and you're good to go. Has a mobile App and there are probably Browser Add-Ons available. Costs nothing and works like a charm.

Re: Bitwarden second security audit report

#42
post #24

Earlier quoted context omitted.

Pentester for 10 odd years: usually for an external test you would scope it at X days depending on the number of IPs etc. And it should note that an external test really doesn't find much. External is usually £750/day for 1-2 days testing and one reporting. Internal testing (ie. Auditing a domain and all computers attached) is about the same price, maybe a bit more, and takes a bit longer usually. A build review is h…

Your comment really surprised me as I didn't expect that this was just a pen-test, but after visiting the link, indeed it was! I think it's a bit sneaky as for a product like this, people expect this to be a code and crypto audit. The "network" part should be emphasised and in the title of the page, instead of just the PDF.

[deleted]

Re: Bitwarden second security audit report

#43
post #37
post #24

Earlier quoted context omitted.

Pentester for 10 odd years: usually for an external test you would scope it at X days depending on the number of IPs etc. And it should note that an external test really doesn't find much. External is usually £750/day for 1-2 days testing and one reporting. Internal testing (ie. Auditing a domain and all computers attached) is about the same price, maybe a bit more, and takes a bit longer usually. A build review is h…

Those prices might stand up for contractors -- but are a bit low to bring in a commercial outfit, at least for any of the larger reputable security consulting businesses. Would suggest starting prices would be closer to £1000 a day. And rates are significantly higher in the US. Accountability and consistency is a real concern in crowdsourcing. There is a reason we dont spend too much time designing an idea and then c…

The crowd sourcing stuff that I've seen comes in two different formats usually. There is the one where you put your URLs/IPs up there a d say "this is in scope"and someone finds something wrong, you pay them (ie. Someone says this has xss, you pay them a few hundred dollars) which has relatively little risk in terms of you only pay for what you get. The other ones are where you'd be allocated a test which then gets shipped out to some consultant anywhere in the world. I agree these are more risky (as you pay a flat rate). These are the ones I was hinting at that my friends moonlight on,but you do need some proof of technical ability and have to take a fairly decent entrance exam to participate in which (from what I've heard) hasn't been subject to the rampant cheating/"preparation" that other UK based aptitude tests/things like OSCP have. I'd personally go to a reputable vendor and ask for a senior consultant, but it's definitely a viable alternative especially if money is tight. Disagree about the pricing though, 750 (excl VAT) a day for external testing is pretty reasonable these days even for big vendors. App testing though, yeah, the prices can easily push 1k+ depending on what it is.

Re: Bitwarden second security audit report

#44
It's good to see companies making reports public to provide some confidence that they're having reviews done, but in this case the scoping of this job seems a little odd, not sure if that's a bad reporting template or something else.

Last page of the PDF indicates that they just did an external VA and pentest, but looking at their product set , I'd have expected (at least) a review of the web, desktop and mobile apps and the browser plugins for it to be a "thorough security assessment and penetration test" (as quoted in the blog).

Not to say external reviews have no value, but they're only part of what's needed.

Re: Bitwarden second security audit report

#45
post #43
post #37

Earlier quoted context omitted.

Those prices might stand up for contractors -- but are a bit low to bring in a commercial outfit, at least for any of the larger reputable security consulting businesses. Would suggest starting prices would be closer to £1000 a day. And rates are significantly higher in the US. Accountability and consistency is a real concern in crowdsourcing. There is a reason we dont spend too much time designing an idea and then c…

The crowd sourcing stuff that I've seen comes in two different formats usually. There is the one where you put your URLs/IPs up there a d say "this is in scope"and someone finds something wrong, you pay them (ie. Someone says this has xss, you pay them a few hundred dollars) which has relatively little risk in terms of you only pay for what you get. The other ones are where you'd be allocated a test which then gets s…

Interesting how little pentest rates have moved on in the UK in the last 20 years. I was a customer of big UK testing companies back then and rates were around that already, so there's been effectively no increase there in that timeframe, if you're still getting work at the £750-£1000 range.

Re: Bitwarden second security audit report

#46
post #43

Earlier quoted context omitted.

The crowd sourcing stuff that I've seen comes in two different formats usually. There is the one where you put your URLs/IPs up there a d say "this is in scope"and someone finds something wrong, you pay them (ie. Someone says this has xss, you pay them a few hundred dollars) which has relatively little risk in terms of you only pay for what you get. The other ones are where you'd be allocated a test which then gets s…

Interesting how little pentest rates have moved on in the UK in the last 20 years. I was a customer of big UK testing companies back then and rates were around that already, so there's been effectively no increase there in that timeframe, if you're still getting work at the £750-£1000 range.

Yep, more competition, more knowledge and more efficiency is meaning that you can't really push big prices unless you're either going for a massive company (I've seen my day rate as high as 1800 before for doing relatively generic work for gov organizations). When I first started contracting we were replacing a big-4 consulting firm charging 3200/day for some stuff (!) For a UK insurance comoany. Alternatively as I mentioned if you're doing specialist work (code review, hardware, some forms of SE, mainframe testing) you can definitely push the numbers up depending on the client. I have friends still working at several of the larger companies and the day rates really around about 8-900/day on average but they just supplement it by tacking an extra day on whenever they can. All depends on the customer and the sales guy tbh.

On average I'd even say that my day rate went down compared with 10 odd years ago - when you needed an interview at GCHQ to get CHECK - as there were just few people doing it whereas there are loads now.

Re: Bitwarden second security audit report

#47

It's good to see companies making reports public to provide some confidence that they're having reviews done, but in this case the scoping of this job seems a little odd, not sure if that's a bad reporting template or something else. Last page of the PDF indicates that they just did an external VA and pentest, but looking at their product set , I'd have expected (at least) a review of the web, desktop and mobile apps…

The only PDF linked in the blogpost is "Bitwarden Network Security Assessment Report", and it does indeed only cover network related topics. Their earlier report from 2018 covers lots of web/desktop application assessments: https://cdn.bitwarden.com/misc/Bitwarden%20Security%20Assess...

So I wonder if they just forgot to mention that this second audit report doesn't cover that, or if there are more reports coming.

Post reply on HN