If I run the compromised CLI, do they get all my passwords?
Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
11–20 of 458 posts
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#12Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#13Edit: The CLI itself apparently does not, which will have limited the damage a bit, but if it's installed as a snap, it might. Incidents like this should hopefully cause a rollback of this dumb system of forcefully and frequently updating people's software without explicit consent.
Also the time range provided in https://community.bitwarden.com/t/bitwarden-statement-on-che... can help with knowing if you were at risk. I only used the CLI once in the morning yesterday (ET), so I might not have been affected?
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#14Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#15Quite bizarre to think much much of my well-being depends on those secrets staying secret.
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#16If you see any package that has hundreds of libraries, that increases the risk of a supply chain attack.
A password manager does not need a CLI tool.
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#17I had a really bad experience with the bitwarden cli. I believe it was `bw list` that I ran, assuming it would list the names of all my passwords, but too my surprise, it listed everything, including passwords and current totp codes. That's not the worst of it though. For some reason, when I ssh'ed into one of my servers and opened tmux, where I keep a weechat irc client running, I noticed that the entire content of…
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#18Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#19Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#20I've managed to avoid several security breaches in last 5 years alone by using KeePass locally on my own infra.