The problem is these password managers are lucrative targets, especially being able to gain access to a person's financial accounts. Simply disregarding the issue and categorizing it as "Attacks requiring physical access to a user's device" isn't good enough. Yes, there's only so much Bitwarden can do from the software side of things, without hardware support to back it up. But Bitwarden should still do what it can t…
Bitwarden PINs can be brute-forced
21–30 of 284 posts
Re: Bitwarden PINs can be brute-forced
#22the more I see hacked password vaults (lastpass for example), the more I want to build a p2p password vault that only lives on my own devices.
Re: Bitwarden PINs can be brute-forced
#23It’s practically game over if an attacker has access to your laptop. They can for example install a keylogger and capture your master password for any password manager.
Re: Bitwarden PINs can be brute-forced
#24It’s practically game over if an attacker has access to your laptop. They can for example install a keylogger and capture your master password for any password manager.
Re: Bitwarden PINs can be brute-forced
#25Re: Bitwarden PINs can be brute-forced
#26The author mentions this finding was marked as out-of-scope when they reported it to Bitwarden. A couple of categories that are considered out-of-scope are listed, namely: attacks requiring physical access to a user's device, and "other side of airtight hatchway"[0] type issues. The latter seems reasonable, if the assumption is that the device is fully compromised, and ongoing surreptitious monitoring of user activit…
Re: Bitwarden PINs can be brute-forced
#27The silly thing is that Windows already has Windows Hello and its accompanying APIs which can be used to guard something like it with anti-hammering protections. Ditto for macOS and the Secure Enclave. I know it's not 100% of its market but using those two features could drastically improve security for the vast majority of people who pay no mind to things deep down in the weeds such as this.
Re: Bitwarden PINs can be brute-forced
#28the more I see hacked password vaults (lastpass for example), the more I want to build a p2p password vault that only lives on my own devices.
Re: Bitwarden PINs can be brute-forced
#29The silly thing is that Windows already has Windows Hello and its accompanying APIs which can be used to guard something like it with anti-hammering protections. Ditto for macOS and the Secure Enclave. I know it's not 100% of its market but using those two features could drastically improve security for the vast majority of people who pay no mind to things deep down in the weeds such as this.
Re: Bitwarden PINs can be brute-forced
#30the more I see hacked password vaults (lastpass for example), the more I want to build a p2p password vault that only lives on my own devices.
It has some cool features too, like not injecting anything into pages until you activate it (so no performance cost or risk of breaking sites) being less reliant on perfect detection of fields when it is activated, etc.