Live data from Hacker News

Bitwarden Completes Third-Party Security Audit

blog.bitwarden.com

141–148 of 148 posts

Re: Bitwarden Completes Third-Party Security Audit

#141

>On a less positive note, the assessment of the deployed cryptographic design led to the discovery of certain issues that must be addressed in due course. One was rated “Critical” because a malicious vault could obtain and modify organization items. This approach relied on MitM attack described in BWN-01-008. The overall code quality of the crypto implementations was deemed to be overly complex and frequently mislead…

Can anyone knowledgeable comment on this. Right now I'm using enpass and trying to wonder if BitWarden would be better. Enpass has some issues when if sync fails it doesn't really report that (for me at least). I also have had some issues when I'm in a trusted machine (at work) but not my own when having a web-vault access might be good.

On the other hand I do love the no cloud mode of enpass which potentially of makes it slightly more secure (a cloud for password storage would be a juicy target). It also means I have a local backup of all my password in my devices in case of some issue including bitwarden web vault being down.

Re: Bitwarden Completes Third-Party Security Audit

#142
post #51

We used LastPass for several years in our home, mostly because it was able to fill Firefox http basic auth dialogs. When Firefox switched to the webextension format, LastPass started using the Chrome version as the foundation for Firefox. This was a huge step backwards and my wife HATED it. The biggest problem she had was that it was that the standard workflow of it capturing generated passwords became unreliable and…

I moved from Lastpass to 1Password recently. Neither fill basic auth dialogs, and both companies state this is a feature not a bug. It still pisses me off.

I read a while back that browser-based password management with autofill is a big security risk. I can't remember the details, but the article author cited some actual exploits that have affected browser-based password managers.

I was considering switching to KeepassXC in response but didn't get around to it.

Re: Bitwarden Completes Third-Party Security Audit

#143

>On a less positive note, the assessment of the deployed cryptographic design led to the discovery of certain issues that must be addressed in due course. One was rated “Critical” because a malicious vault could obtain and modify organization items. This approach relied on MitM attack described in BWN-01-008. The overall code quality of the crypto implementations was deemed to be overly complex and frequently mislead…

Is it good to release this audit so soon? Wouldn't it have been better to release it in 1-3 months after they fixed the issues so that they don't alert attackers that there's an opportunity? Actually curious what the best practice is and why it is so.

Re: Bitwarden Completes Third-Party Security Audit

#145
post #76

Earlier quoted context omitted.

They recently added that: "Oct 9 - This is in the next release for various apps." [1] the PR is from Oct 6 [2]. It is a very basic implementation as of now. The wordlist is English-only, and it doesn't have a minimum character account so it contains 'words' such as 'aa' and 'aaa'. [1] https://community.bitwarden.com/t/add-an-ability-to-generate... [2] https://github.com/bitwarden/jslib/pull/12

> it doesn't have a minimum character account so it contains 'words' such as 'aa' and 'aaa'. The PR discusses how the original word list that was referenced was changed out to the better long word list from https://www.eff.org/dice .

Great, thank you. Some more choices in that regard would be great (such as a native language wordlist) but I very much appreciate you added this basic functionality. Even in its current form it is an improvement over nothing or manually doing this (am a satisfied Premium subscriber).

Re: Bitwarden Completes Third-Party Security Audit

#146
post #37

Earlier quoted context omitted.

I wonder if this will nudge 1password to release a Linux client?

https://support.1password.com/explore/linux/ ?

Is that a browser client that connects to a centralized vault or a local client?

Re: Bitwarden Completes Third-Party Security Audit

#147

>On a less positive note, the assessment of the deployed cryptographic design led to the discovery of certain issues that must be addressed in due course. One was rated “Critical” because a malicious vault could obtain and modify organization items. This approach relied on MitM attack described in BWN-01-008. The overall code quality of the crypto implementations was deemed to be overly complex and frequently mislead…

@Aquakor I am the lead developer of Bitwarden and was intimately involved in the security audit mentioned. I can understand that those two paragraphs may seem a bit concerning out of context. To provide more context, there were several points discussed between the Bitwarden developers and the auditing team about how we could redesign specific features (ex. organization user confirmations) so that the crypto implementations would be stronger and more resilient against certain attack vectors. A consensus was reached and that is what is being referenced here about re-designing things.

The purpose of an audit like this is to find issues. When issues are found, that is a good thing. We want to find problems so that they can be fixed. What would be bad is if we found issues that could not be properly fixed, or an abnormally large number of issues, neither of which was the case with Bitwarden. What I can tell you is that all issues referenced in this audit have already been resolved in very short order (the audit was only completed just last week), with relatively simple fixes, and that Bitwarden is even safer to use today than it was before.

Re: Bitwarden Completes Third-Party Security Audit

#148
post #66

Earlier quoted context omitted.

It's a mature product that hasn't had any major security issues. When I checked a few years ago, no other product ticked both boxes. Nowadays there might be another such product, but I'm not going to switch to find out at this point.

Which one are you talking about? 1Password?

Oops, yes, sorry.
Post reply on HN