Live data from Hacker News

Bitwarden PINs can be brute-forced

ambiso.github.io

221–230 of 284 posts

Re: Bitwarden PINs can be brute-forced

#221

Criticisms from this article: >Bitwarden does not warn about this risk…… Bitwarden takes little effort in communicating the risks of choosing a short low-entropy PIN. Currently there is very little information to be found about the PIN in Bitwarden documentation Bitwarden's help docs on using PINs: https://bitwarden.com/help/unlock-with-pin/ . >Warning: Using a PIN can weaken the level of encryption that protects you…

They just need to put that notice in the software, when you try to enable a pin.

Re: Bitwarden PINs can be brute-forced

#222

Earlier quoted context omitted.

I realize math education in the US sucks but are really suggesting most people can’t figure out that 0 to 9999 is all the possibilities you get from 4 digits?

Yes, most people cannot figure that out, but also it would not occur to most people to consider that when opting for a PIN over a password.

One could get into a long debate about whether "most" is literally true or not, but I think most of us should be able to agree that at least a significant proportion of people - enough to matter - either won't or can't think of this without some prompting.

Re: Bitwarden PINs can be brute-forced

#223

The attacks went from LastPass and over to BitWarden. After the attacks and smear campaigns, shall the people unwilling to use KeyPass and other high-lift/high-risk pieces of software move on to using tiered password strategies for their hundreds of sites again?

It's not really an attack.

Pin is obviously less secure (however this could be mitigated by using a TPM as other commenters said) but it's not the default.

Their help page on pin even warns about the security risk, they should have the warning in the application.

I'll still use bitwarden (without pin).

Re: Bitwarden PINs can be brute-forced

#225
post #105

Of course the PIN can be brute forced. It feels like reporting "I can walk over the lawn fence". That PIN is probably here to prevent your kids from messing with your vault when you grab your coffee with your computer unlocked. Protecting from an attacker with your laptop locked should be done at the OS level with FDE and secure boot. Protecting from a real attacker with access to your unlocked computer is a bit hope…

That was my initial reaction as well, but it isn't necessarily true. If you read up on how Windows Hello uses a PIN, then it becomes clear that they can be pretty secure where: (1) a PIN is tied to the device; (2) a PIN is local to the device; and (3) a PIN is backed by hardware.

https://learn.microsoft.com/en-us/windows/security/identity-...

Re: Bitwarden PINs can be brute-forced

#226
post #82

Earlier quoted context omitted.

Bummer that its not usable on the browser extension though. I used to have the desktop app but it ended up being mostly useless. 99% of my passwords go into the browser where I want autofill, and for the rest I almost always have a browser open anyways so I can just as easily copy/paste from the extension as the app.

You can use biometrics in the browser app, but you have to run the application and unlock that with biometrics after enabling browser integration in the settings. You also can't use the Windows Store version of the Bitwarden app. https://bitwarden.com/help/biometrics/

Clunky, but hey I'll take it. Thanks!

Re: Bitwarden PINs can be brute-forced

#227

Earlier quoted context omitted.

> Is it safe to rely on a 4 digit PIN? Obviously not, when there are only 10000 possible combinations. You shouldn't need Bitwarden to tell you that though. Most people really don’t know that. It is not obvious to a normal user.

I realize math education in the US sucks but are really suggesting most people can’t figure out that 0 to 9999 is all the possibilities you get from 4 digits?

You're thinking like an engineer.

I'm confident your average person would understand that a PIN is insecure if it was explained to them.

But think about other things in life that use a PIN -- debit cards, customer support shortcuts, etc. These are things that can't or typically won't be brute forced and are deemed as "secure enough" in our world.

Your average person has no idea how a 2FA token is generated, but they know it's just a few numbers that they have to enter on various websites and apps, and those numbers resemble a PIN. Yet another reinforcement that just a few numbers keeps things secure.

If you walk a user through software setup, and at some point they need to provide a complex master password, they would never automatically assume that being presented with an option to use a PIN would remove the security provided by a complex master password.

Only if they were to think it through, or have someone who thinks analytically, would they understand that in this scenario, given that it's Internet-accessible software, a PIN could be brute forced in no time unlike their debit card or any other PIN they may need to use in the course of their day to day life.

Re: Bitwarden PINs can be brute-forced

#228

Earlier quoted context omitted.

Not allowing people the convenience they want means they'll switch to a method that does. Worst case: a passwords.txt. Wouldn't that be a worse downgrade attack?

I have no opinion other than it is obviously a downgrade attack. As a fair to middling organic language model, I cannot tell you how to keep your keys safe; I myself am blessed with a good memory and 160wpm typing speed so I use that.

As you say yourself, that is a blessing, and not everyone has it. Only allowing those with such blessings to use Bitwarden doesn't help anyone.

Re: Bitwarden PINs can be brute-forced

#229
post #112

Earlier quoted context omitted.

We've been building a p2p password vault called Polykey. https://GitHub.com/MatrixAI/Polykey .

> No server is currently available to service your request. Found the SPOF! But also, "AI"? And "we've been building" doesn't sound like it's production-ready yet. I don't know, lots of red flags here to me.

No it's not production ready yet. Matrix AI is just our company name.

Re: Bitwarden PINs can be brute-forced

#230

Earlier quoted context omitted.

I have no opinion other than it is obviously a downgrade attack. As a fair to middling organic language model, I cannot tell you how to keep your keys safe; I myself am blessed with a good memory and 160wpm typing speed so I use that.

As you say yourself, that is a blessing, and not everyone has it. Only allowing those with such blessings to use Bitwarden doesn't help anyone.

Again, as a fair-to-middling organic language model, my only opinion is that, a PIN, as currently implemented in Bitwarden and described above, leaves Bitwarden users open to a form of exploitation that can be categorized as a downgrade attack.

Presumably, a better implementation would be fine.

You are free to keep using Bitwarden's PIN implementation, but it will still be open to: downgrade attack.

This is because Bitwarden's security, as described in this article, is open to: downgrade attack.

This is not an emotional term. It is no more laden with implication than observing that #F00 is 'red'. You are free to keep using #F00, just don't call it blue.

Donwgrade attacks are relatively straightforward, and ease-of-use features, such as PINs, are a traditional place to look for them.

I have no opinion on this matter other than that it implies that Bitwarden can be configured in a manner which is insecure, and the specific form of insecurity is: openness to downgrade attack.

Post reply on HN