Live data from Hacker News

Bitwarden second security audit report

bitwarden.com

1–10 of 118 posts

Re: Bitwarden second security audit report

#2
Can someone with security industry knowledge comment on how much weight we should give this? Are these sorts of things something you can just buy and they'll go out of their way to give you a favourable report because you're the client? Is Insight Risk Consulting known and credible?

Re: Bitwarden second security audit report

#3

Can someone with security industry knowledge comment on how much weight we should give this? Are these sorts of things something you can just buy and they'll go out of their way to give you a favourable report because you're the client? Is Insight Risk Consulting known and credible?

Does it matter?

They found something worth fixing, despite the project being open source wit bug bounties and previous audits being made.

Re: Bitwarden second security audit report

#5

Can someone with security industry knowledge comment on how much weight we should give this? Are these sorts of things something you can just buy and they'll go out of their way to give you a favourable report because you're the client? Is Insight Risk Consulting known and credible?

I recognise Insight (going by the name & logo) as one that is on at least one of our larger clients' (we work on systems to manage regulatory compliance, primarily with investment banks) PSLs for application penetration testing. Assuming this is the same company and not some small-fry crook who is trying to steal their thunder (I've not looked in any depth beyond "I know that logo"), that would suggest that the report is not of the "pay to pass" variety. There would be some noise if a company on the banks' security provider PSLs were found to be offering pay-to-pass security audits.

Such companies sometimes offer a range of penetration testing options from relatively superficial to aggressive, in-depth, and detailed, so you'd need to read the report (I will when I have more time as we are considering Bitwarden for our credential management) to see if what it is saying is sufficiently reassuring.

Re: Bitwarden second security audit report

#6

Can someone with security industry knowledge comment on how much weight we should give this? Are these sorts of things something you can just buy and they'll go out of their way to give you a favourable report because you're the client? Is Insight Risk Consulting known and credible?

> Are these sorts of things something you can just buy and they'll go out of their way to give you a favourable report because you're the client?

That happens.

I can't comment on Insight Risk Consulting, as I don't know that company. They write they had a previous audit from Cure53. That's a well known and very skilled security company and I would expect that you can't buy an "please ignore as many vulns as possible" report from them.

Re: Bitwarden second security audit report

#8
post #3

Can someone with security industry knowledge comment on how much weight we should give this? Are these sorts of things something you can just buy and they'll go out of their way to give you a favourable report because you're the client? Is Insight Risk Consulting known and credible?

Does it matter? They found something worth fixing, despite the project being open source wit bug bounties and previous audits being made.

That has nothing to do with it being open source. In close-source systems I've seen penetration testers find security issues that have been present for years despite annual audits during that time. This is one of the reasons why our services get at least annual penetration testing, even the legacy ones that won't have changed since the last test. It is not a bad idea to cycle through providers too, on the off chance that some may use different tooling that exposes certain flaws more readily than the techniques used by others.

Being open source just increases the chance of a problem being spotted if there are sufficiently clue-up people looking. Being open does not at all guarantee that any given problem will be spotted during the normal course of work. Security issues can be dues to combinations of flaws in widely spaced code so even if working directly on one part you might not realise there is an issue in conjunction with another part. That is why it is necessary to have tests/audits like this, for oth open and closed source systems, where someone is task specifically to look for security problems.

It isn't right to criticise Bitwarden for being tested and issues being found (unless those issues are systemic and/or just plain stupid, or you believe the project's response to resolve them is too slow or incomplete). Instead concern should be aimed at security related products that are not regularly subject to external audit at all. Not having any issues because you have not checked for them is a much greater worry!

Re: Bitwarden second security audit report

#9
post #3

Earlier quoted context omitted.

Does it matter? They found something worth fixing, despite the project being open source wit bug bounties and previous audits being made.

That has nothing to do with it being open source. In close-source systems I've seen penetration testers find security issues that have been present for years despite annual audits during that time. This is one of the reasons why our services get at least annual penetration testing, even the legacy ones that won't have changed since the last test. It is not a bad idea to cycle through providers too, on the off chance…

I think that was the point of the previous comment.

That, despite the software being open-source and therefore more likely to have bugs spotted, and despite having a bug bounty program, the auditing company found a moderate, therefore they must be thorough.

Re: Bitwarden second security audit report

#10

Earlier quoted context omitted.

That has nothing to do with it being open source. In close-source systems I've seen penetration testers find security issues that have been present for years despite annual audits during that time. This is one of the reasons why our services get at least annual penetration testing, even the legacy ones that won't have changed since the last test. It is not a bad idea to cycle through providers too, on the off chance…

I think that was the point of the previous comment. That, despite the software being open-source and therefore more likely to have bugs spotted, and despite having a bug bounty program, the auditing company found a moderate, therefore they must be thorough.

If you were selling bogus report results for clients you'd still include a non-major thing or two. Gives a better impression of legitimacy than full marks across the board.
Post reply on HN