Live data from Hacker News

Bitwarden Heist – How to break into password vaults without using passwords

blog.redteam-pentesting.de

11–20 of 209 posts

Re: Bitwarden Heist – How to break into password vaults without using passwords

#11
post #5

Earlier quoted context omitted.

>the attack already assumes access to the workstation of the victim I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.

The problem is that an unsophisticated user doesn't necessarily think like that, and could come to the conclusion that it is not a big deal to leave his workstation unlocked while going to fetch a coffee, after all, well... "I have a password manager, and to have access to it, it requires unlocking". Then some colleague calls them for an ongoing meeting so they can share some insight about some question that was rais…

That unsophisticated user is also likely to have a printed out list of passwords taped to their monitor, or an unprotected excel file labelled "Passwords".

Re: Bitwarden Heist – How to break into password vaults without using passwords

#12
post #5

TL;DR: It's definitely interesting, but this is about attacking vaults with biometric unlock enabled (and are thus stored on disk) on Windows, and requires workstation access and a Bitwarden design flaw that was fixed in April. > the attack already assumes access to the workstation of the victim and the Windows domain > The underlying issue has been corrected in Bitwarden v2023.4.0 in April 2023 > As it turns out, we…

>the attack already assumes access to the workstation of the victim I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.

In this case, physical access is very brief and almost imperceptible if you're not paying attention.

It's different from trying to pry open an encrypted hard disk from a laptop or something similar.

You probably won't even know that coworker you trust is compromised and attacked you this way.

Re: Bitwarden Heist – How to break into password vaults without using passwords

#14

TL;DR: It's definitely interesting, but this is about attacking vaults with biometric unlock enabled (and are thus stored on disk) on Windows, and requires workstation access and a Bitwarden design flaw that was fixed in April. > the attack already assumes access to the workstation of the victim and the Windows domain > The underlying issue has been corrected in Bitwarden v2023.4.0 in April 2023 > As it turns out, we…

[deleted]

Re: Bitwarden Heist – How to break into password vaults without using passwords

#15
post #5

Earlier quoted context omitted.

>the attack already assumes access to the workstation of the victim I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.

The problem is that an unsophisticated user doesn't necessarily think like that, and could come to the conclusion that it is not a big deal to leave his workstation unlocked while going to fetch a coffee, after all, well... "I have a password manager, and to have access to it, it requires unlocking". Then some colleague calls them for an ongoing meeting so they can share some insight about some question that was rais…

To this day I don’t understand how “computer repair” shops are in business. When I was a shithead 16 year old I used to work at one. I found it amusing to see what files people deleted before giving us full physical access to their machines. I definitely saw things I shouldn’t have seen. It wasn’t until I saw something illegal that I freaked out and stopped doing it. I was so paranoid that I srm’ed my entire drive and theirs and never mentioned it to anybody. In retrospect I should have, but I was 16 and didn’t know what to do.

Re: Bitwarden Heist – How to break into password vaults without using passwords

#16
post #9

> As usual, we managed to get administrative access to the domain controller As usual? Is that the state of Windows Server security these days? I never managed a Windows-based network so I have no idea. I heard about these things back in the 2000's but I'm surprised this is "usual".

Well, they're a pentesting company. Getting access to the DC is goal #1 for every engagement they do.

So, I read this to be "as usual for us during our engagements", not "as usual for everyone all the time".

Re: Bitwarden Heist – How to break into password vaults without using passwords

#17
post #9

> As usual, we managed to get administrative access to the domain controller As usual? Is that the state of Windows Server security these days? I never managed a Windows-based network so I have no idea. I heard about these things back in the 2000's but I'm surprised this is "usual".

[deleted]

Re: Bitwarden Heist – How to break into password vaults without using passwords

#18
post #7
post #3

This affects Windows only. Really feel that should've made it to the title other it feels like click bait.

I worked in managing bug bounty programs at a previous job. If there is one thing I have learned it's that blog posts like this are heavily skewed towards making the problem seem much larger than it is. It's what gets the clicks, so it's not a surprise. It makes dealing with penetration testers and bug bounty participants really stressful and frankly, annoying. Our policy was that we would be happy if someone were to…

[deleted]

Re: Bitwarden Heist – How to break into password vaults without using passwords

#20
post #5

TL;DR: It's definitely interesting, but this is about attacking vaults with biometric unlock enabled (and are thus stored on disk) on Windows, and requires workstation access and a Bitwarden design flaw that was fixed in April. > the attack already assumes access to the workstation of the victim and the Windows domain > The underlying issue has been corrected in Bitwarden v2023.4.0 in April 2023 > As it turns out, we…

>the attack already assumes access to the workstation of the victim I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.

Yes, it requires an attacker in a powerful position but it does not require physical access. Any program that runs in the user's session (without any special privileges) could have autonomously retrieved the biometric key and decrypted the vault without user interaction and without Bitwarden running.
Post reply on HN