KeePass users continue to live the stress free live. I've managed to avoid several security breaches in last 5 years alone by using KeePass locally on my own infra.
Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
41–50 of 458 posts
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#42KeePass users continue to live the stress free live. I've managed to avoid several security breaches in last 5 years alone by using KeePass locally on my own infra.
I need my passwords to be accessible from my infrastructure and my phone. How do you achieve this with KeePass? I assumed it was not possible, but in fairness, I haven't really gone down that rabbit hole to investigate.
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#43Never used the CLI, but I do use their browser plugin. Would be quite a mess if that got compromised. What can I do to prevent it? Run old --tried and tested-- versions? Quite bizarre to think much much of my well-being depends on those secrets staying secret.
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#44> Russian locale kill switch: Exits silently if system locale begins with "ru", checking Intl.DateTimeFormat().resolvedOptions().locale and environment variables LC_ALL, LC_MESSAGES, LANGUAGE, and LANG So bold and so cowards at the same time...
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#45KeePass users continue to live the stress free live. I've managed to avoid several security breaches in last 5 years alone by using KeePass locally on my own infra.
https://cyberpress.org/hackers-exploit-keepass-password-mana...
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#46Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#47I had a really bad experience with the bitwarden cli. I believe it was `bw list` that I ran, assuming it would list the names of all my passwords, but too my surprise, it listed everything, including passwords and current totp codes. That's not the worst of it though. For some reason, when I ssh'ed into one of my servers and opened tmux, where I keep a weechat irc client running, I noticed that the entire content of…
Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
#48Never used the CLI, but I do use their browser plugin. Would be quite a mess if that got compromised. What can I do to prevent it? Run old --tried and tested-- versions? Quite bizarre to think much much of my well-being depends on those secrets staying secret.
Integration points increase the risk of compromise. For that reason, I never use the desktop browser extensions for my password manager. When password managers were starting to become popular there was one that had security issues with the browser integration so I decided to just avoid those entirely. On iOS, I'm more comfortable with the integration so I use it, but I'm wary of it.