Live data from Hacker News

Bitwarden Heist – How to break into password vaults without using passwords

blog.redteam-pentesting.de

1–10 of 209 posts

Re: Bitwarden Heist – How to break into password vaults without using passwords

#4
TL;DR: It's definitely interesting, but this is about attacking vaults with biometric unlock enabled (and are thus stored on disk) on Windows, and requires workstation access and a Bitwarden design flaw that was fixed in April.

> the attack already assumes access to the workstation of the victim and the Windows domain

> The underlying issue has been corrected in Bitwarden v2023.4.0 in April 2023

> As it turns out, we were not the first to discover this in March 2023, it had already been reported to Bitwarden through HackerOne.[1]

I could have sworn [1] had a dedicated post here on HN but couldn't find it, it's worth a read too.

[1]: https://hackerone.com/reports/1874155

Re: Bitwarden Heist – How to break into password vaults without using passwords

#5

TL;DR: It's definitely interesting, but this is about attacking vaults with biometric unlock enabled (and are thus stored on disk) on Windows, and requires workstation access and a Bitwarden design flaw that was fixed in April. > the attack already assumes access to the workstation of the victim and the Windows domain > The underlying issue has been corrected in Bitwarden v2023.4.0 in April 2023 > As it turns out, we…

>the attack already assumes access to the workstation of the victim

I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.

Re: Bitwarden Heist – How to break into password vaults without using passwords

#7
post #3

This affects Windows only. Really feel that should've made it to the title other it feels like click bait.

I worked in managing bug bounty programs at a previous job. If there is one thing I have learned it's that blog posts like this are heavily skewed towards making the problem seem much larger than it is. It's what gets the clicks, so it's not a surprise. It makes dealing with penetration testers and bug bounty participants really stressful and frankly, annoying.

Our policy was that we would be happy if someone were to discuss bounties we paid out for, but we wanted the discussion to be fair and accurate. It did not ever really feel like it was mutually beneficial relationship. I don't miss that work at all really lol.

Re: Bitwarden Heist – How to break into password vaults without using passwords

#8
post #5

TL;DR: It's definitely interesting, but this is about attacking vaults with biometric unlock enabled (and are thus stored on disk) on Windows, and requires workstation access and a Bitwarden design flaw that was fixed in April. > the attack already assumes access to the workstation of the victim and the Windows domain > The underlying issue has been corrected in Bitwarden v2023.4.0 in April 2023 > As it turns out, we…

>the attack already assumes access to the workstation of the victim I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.

The problem is that an unsophisticated user doesn't necessarily think like that, and could come to the conclusion that it is not a big deal to leave his workstation unlocked while going to fetch a coffee, after all, well... "I have a password manager, and to have access to it, it requires unlocking". Then some colleague calls them for an ongoing meeting so they can share some insight about some question that was raised in the meeting and so on.

A far-fetched scenario? yes. But if it can happen, it will happen.

Re: Bitwarden Heist – How to break into password vaults without using passwords

#9
> As usual, we managed to get administrative access to the domain controller

As usual? Is that the state of Windows Server security these days? I never managed a Windows-based network so I have no idea. I heard about these things back in the 2000's but I'm surprised this is "usual".

Post reply on HN