Earlier quoted context omitted.
>the attack already assumes access to the workstation of the victim I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.
The problem is that an unsophisticated user doesn't necessarily think like that, and could come to the conclusion that it is not a big deal to leave his workstation unlocked while going to fetch a coffee, after all, well... "I have a password manager, and to have access to it, it requires unlocking". Then some colleague calls them for an ongoing meeting so they can share some insight about some question that was rais…
Bitwarden Heist – How to break into password vaults without using passwords
11–20 of 209 posts
Re: Bitwarden Heist – How to break into password vaults without using passwords
#12TL;DR: It's definitely interesting, but this is about attacking vaults with biometric unlock enabled (and are thus stored on disk) on Windows, and requires workstation access and a Bitwarden design flaw that was fixed in April. > the attack already assumes access to the workstation of the victim and the Windows domain > The underlying issue has been corrected in Bitwarden v2023.4.0 in April 2023 > As it turns out, we…
>the attack already assumes access to the workstation of the victim I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.
It's different from trying to pry open an encrypted hard disk from a laptop or something similar.
You probably won't even know that coworker you trust is compromised and attacked you this way.
Re: Bitwarden Heist – How to break into password vaults without using passwords
#13This affects Windows only. Really feel that should've made it to the title other it feels like click bait.
Re: Bitwarden Heist – How to break into password vaults without using passwords
#14TL;DR: It's definitely interesting, but this is about attacking vaults with biometric unlock enabled (and are thus stored on disk) on Windows, and requires workstation access and a Bitwarden design flaw that was fixed in April. > the attack already assumes access to the workstation of the victim and the Windows domain > The underlying issue has been corrected in Bitwarden v2023.4.0 in April 2023 > As it turns out, we…
Re: Bitwarden Heist – How to break into password vaults without using passwords
#15Earlier quoted context omitted.
>the attack already assumes access to the workstation of the victim I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.
The problem is that an unsophisticated user doesn't necessarily think like that, and could come to the conclusion that it is not a big deal to leave his workstation unlocked while going to fetch a coffee, after all, well... "I have a password manager, and to have access to it, it requires unlocking". Then some colleague calls them for an ongoing meeting so they can share some insight about some question that was rais…
Re: Bitwarden Heist – How to break into password vaults without using passwords
#16> As usual, we managed to get administrative access to the domain controller As usual? Is that the state of Windows Server security these days? I never managed a Windows-based network so I have no idea. I heard about these things back in the 2000's but I'm surprised this is "usual".
So, I read this to be "as usual for us during our engagements", not "as usual for everyone all the time".
Re: Bitwarden Heist – How to break into password vaults without using passwords
#17> As usual, we managed to get administrative access to the domain controller As usual? Is that the state of Windows Server security these days? I never managed a Windows-based network so I have no idea. I heard about these things back in the 2000's but I'm surprised this is "usual".
Re: Bitwarden Heist – How to break into password vaults without using passwords
#18This affects Windows only. Really feel that should've made it to the title other it feels like click bait.
I worked in managing bug bounty programs at a previous job. If there is one thing I have learned it's that blog posts like this are heavily skewed towards making the problem seem much larger than it is. It's what gets the clicks, so it's not a surprise. It makes dealing with penetration testers and bug bounty participants really stressful and frankly, annoying. Our policy was that we would be happy if someone were to…
Re: Bitwarden Heist – How to break into password vaults without using passwords
#19I wonder if biometric bitwarden unlock on Android has the same kind of issue or not.
Re: Bitwarden Heist – How to break into password vaults without using passwords
#20TL;DR: It's definitely interesting, but this is about attacking vaults with biometric unlock enabled (and are thus stored on disk) on Windows, and requires workstation access and a Bitwarden design flaw that was fixed in April. > the attack already assumes access to the workstation of the victim and the Windows domain > The underlying issue has been corrected in Bitwarden v2023.4.0 in April 2023 > As it turns out, we…
>the attack already assumes access to the workstation of the victim I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.