Tangential question: What password manager do you guys use?
KeePass.
Bitwarden second security audit report
41–50 of 118 posts
Re: Bitwarden second security audit report
#42Earlier quoted context omitted.
Pentester for 10 odd years: usually for an external test you would scope it at X days depending on the number of IPs etc. And it should note that an external test really doesn't find much. External is usually £750/day for 1-2 days testing and one reporting. Internal testing (ie. Auditing a domain and all computers attached) is about the same price, maybe a bit more, and takes a bit longer usually. A build review is h…
Your comment really surprised me as I didn't expect that this was just a pen-test, but after visiting the link, indeed it was! I think it's a bit sneaky as for a product like this, people expect this to be a code and crypto audit. The "network" part should be emphasised and in the title of the page, instead of just the PDF.
Re: Bitwarden second security audit report
#43Earlier quoted context omitted.
Pentester for 10 odd years: usually for an external test you would scope it at X days depending on the number of IPs etc. And it should note that an external test really doesn't find much. External is usually £750/day for 1-2 days testing and one reporting. Internal testing (ie. Auditing a domain and all computers attached) is about the same price, maybe a bit more, and takes a bit longer usually. A build review is h…
Those prices might stand up for contractors -- but are a bit low to bring in a commercial outfit, at least for any of the larger reputable security consulting businesses. Would suggest starting prices would be closer to £1000 a day. And rates are significantly higher in the US. Accountability and consistency is a real concern in crowdsourcing. There is a reason we dont spend too much time designing an idea and then c…
Re: Bitwarden second security audit report
#44Last page of the PDF indicates that they just did an external VA and pentest, but looking at their product set , I'd have expected (at least) a review of the web, desktop and mobile apps and the browser plugins for it to be a "thorough security assessment and penetration test" (as quoted in the blog).
Not to say external reviews have no value, but they're only part of what's needed.
Re: Bitwarden second security audit report
#45Earlier quoted context omitted.
Those prices might stand up for contractors -- but are a bit low to bring in a commercial outfit, at least for any of the larger reputable security consulting businesses. Would suggest starting prices would be closer to £1000 a day. And rates are significantly higher in the US. Accountability and consistency is a real concern in crowdsourcing. There is a reason we dont spend too much time designing an idea and then c…
The crowd sourcing stuff that I've seen comes in two different formats usually. There is the one where you put your URLs/IPs up there a d say "this is in scope"and someone finds something wrong, you pay them (ie. Someone says this has xss, you pay them a few hundred dollars) which has relatively little risk in terms of you only pay for what you get. The other ones are where you'd be allocated a test which then gets s…
Re: Bitwarden second security audit report
#46Earlier quoted context omitted.
The crowd sourcing stuff that I've seen comes in two different formats usually. There is the one where you put your URLs/IPs up there a d say "this is in scope"and someone finds something wrong, you pay them (ie. Someone says this has xss, you pay them a few hundred dollars) which has relatively little risk in terms of you only pay for what you get. The other ones are where you'd be allocated a test which then gets s…
Interesting how little pentest rates have moved on in the UK in the last 20 years. I was a customer of big UK testing companies back then and rates were around that already, so there's been effectively no increase there in that timeframe, if you're still getting work at the £750-£1000 range.
On average I'd even say that my day rate went down compared with 10 odd years ago - when you needed an interview at GCHQ to get CHECK - as there were just few people doing it whereas there are loads now.
Re: Bitwarden second security audit report
#47It's good to see companies making reports public to provide some confidence that they're having reviews done, but in this case the scoping of this job seems a little odd, not sure if that's a bad reporting template or something else. Last page of the PDF indicates that they just did an external VA and pentest, but looking at their product set , I'd have expected (at least) a review of the web, desktop and mobile apps…
So I wonder if they just forgot to mention that this second audit report doesn't cover that, or if there are more reports coming.
Re: Bitwarden second security audit report
#48Tangential question: What password manager do you guys use?
I moved from 1Password to BitWarden... 2 years ago now? (2 years 2 months) Oh the experience was SO much nicer than 1Password. And the iOS app WORKED!
Re: Bitwarden second security audit report
#49Good to see. Aside from the Apple ecosystem's password management, Bitwarden is what I've been using.
Re: Bitwarden second security audit report
#50Tangential question: What password manager do you guys use?