Anyone else experiencing this today?
Ask HN: Anyone else Bitwarden account being attacked
1–10 of 18 posts
Re: Ask HN: Anyone else Bitwarden account being attacked
#2Re: Ask HN: Anyone else Bitwarden account being attacked
#3Re: Ask HN: Anyone else Bitwarden account being attacked
#4Nope. Someone may just be targeting you. May be worthwhile to change your master password.
Re: Ask HN: Anyone else Bitwarden account being attacked
#5Nope. Someone may just be targeting you. May be worthwhile to change your master password.
I would not recommend ever changing credentials while under attack, unless they are known to be weak (but the time to change them is before the attack, in that case). The process of changing them opens up several vectors of attack. Additionally, if the attacker already obtained the encrypted payload, it would only be harmful to give them the same data encrypted under a new key.
If they already had the data, would they be using the web account login page?
Re: Ask HN: Anyone else Bitwarden account being attacked
#6I don't use that service. Do you have two-factor authentication? If not, you should really consider using it. The 2fa is a major security upgrade for any account.
Re: Ask HN: Anyone else Bitwarden account being attacked
#7Re: Ask HN: Anyone else Bitwarden account being attacked
#8I don't use that service. Do you have two-factor authentication? If not, you should really consider using it. The 2fa is a major security upgrade for any account.
I had problems with their 2FA where the code would come via SMS but be rejected. I was able to recover via email but it was distressing. Do they have OTP service now?
Re: Ask HN: Anyone else Bitwarden account being attacked
#9Earlier quoted context omitted.
I would not recommend ever changing credentials while under attack, unless they are known to be weak (but the time to change them is before the attack, in that case). The process of changing them opens up several vectors of attack. Additionally, if the attacker already obtained the encrypted payload, it would only be harmful to give them the same data encrypted under a new key.
What additional vectors? If they already had the data, would they be using the web account login page?
And yes, if I had a bitwarden vault I wanted to crack I'd absolutely be using the web account login page. The latter is more likely to yield to have some vulnerability than the at-rest encryption, which when exploited would yield the password; or it could scare the target into falling into my PITM attack, or otherwise act irrationally.
Re: Ask HN: Anyone else Bitwarden account being attacked
#10I don't use that service. Do you have two-factor authentication? If not, you should really consider using it. The 2fa is a major security upgrade for any account.
I had problems with their 2FA where the code would come via SMS but be rejected. I was able to recover via email but it was distressing. Do they have OTP service now?