Live data from Hacker News

Bitwarden Completes Third-Party Security Audit

blog.bitwarden.com

51–60 of 148 posts

Re: Bitwarden Completes Third-Party Security Audit

#51

We used LastPass for several years in our home, mostly because it was able to fill Firefox http basic auth dialogs. When Firefox switched to the webextension format, LastPass started using the Chrome version as the foundation for Firefox. This was a huge step backwards and my wife HATED it. The biggest problem she had was that it was that the standard workflow of it capturing generated passwords became unreliable and…

I moved from Lastpass to 1Password recently. Neither fill basic auth dialogs, and both companies state this is a feature not a bug. It still pisses me off.

Re: Bitwarden Completes Third-Party Security Audit

#52
Would it be possible to know, ballpark, how much a similar security assessment can cost? I understand it's hard to say in general, but given this output I assume it's possible to "get a quote".

In an ideal world, all security-related OS project should have periodic scans like this, but clearly the cost may be prohibitive. Maybe there are ways to get funds, or to form groups of projects that get analyzed together, for example I'm thinking that while Cure53 is analyzing Bitwarden, they could do a similar work for other password managers that buy in.

Independently, a big thank you to Bitwarden for sharing this, knowing which were their vulnerabilities will help a lot everyone in the space. I'm personally very sensitive to these problems, I'm working on open source security products too.

Re: Bitwarden Completes Third-Party Security Audit

#53
post #43

We used LastPass for several years in our home, mostly because it was able to fill Firefox http basic auth dialogs. When Firefox switched to the webextension format, LastPass started using the Chrome version as the foundation for Firefox. This was a huge step backwards and my wife HATED it. The biggest problem she had was that it was that the standard workflow of it capturing generated passwords became unreliable and…

Yes, I use KeePass and Kee for Firefox. Before WebExtensions it was perfect. Now, it has a dialog that tries to intercept basic/negotiate auth, but it never works. Luckily, keepass has a very nice auto-type functionality that works perfectly with basic auth dialogs. Now if I could just disable the Kee dialog that doesn't actually do anything...

Is your "Always show global auto-type entry selection dialog" option checked in the Options \ Advanced \ Auto-Type section? Mine is unchecked, and for sites / applications that only have one entry, it just enters it without showing a dialog...

Re: Bitwarden Completes Third-Party Security Audit

#54
post #52

Would it be possible to know, ballpark, how much a similar security assessment can cost? I understand it's hard to say in general, but given this output I assume it's possible to "get a quote". In an ideal world, all security-related OS project should have periodic scans like this, but clearly the cost may be prohibitive. Maybe there are ways to get funds, or to form groups of projects that get analyzed together, for…

It varies widely, but a code review I was party to came in at around 60k.

Re: Bitwarden Completes Third-Party Security Audit

#55
post #29

I used Lastpass for about 5 years and moved to bitwarden a couple of years back. I never had to turn back again. The browser addons are great, but the mobile app is fantastic, simple, usable and lightweight. It's great to hear that it's pretty secure too.

From your experiences is there any downside or drawbacks with switching? I've been considering it, particularly as Lastpass's Firefox app has been flakey and unreliable. In general Lastpass has become less reliable since the LogMeIn take-over, and they've now added ads to the vault which bug me from a security perspective (even if I happily pay $2/month, it is the principle of putting profits over security).

Another LastPass user of ~5 years. I was actually dreading the switch, just because of the amount of time I had spent using it (mostly always Premium). That and I have a workflow within the family for sharing, etc.

I planned on a week long switch over to make sure things went smooth. However after switching, and validating all common accounts has been imported correctly I just never had to open LastPass again. This took all of 2 hours.

BitWarden has the upper hand in three key areas for me: Android, FireFox and CLI. The LastPass extension for FireFox has become downright useless and that was the main catalyst for me switching.

I've switched now about a month ago and can't imagine going back. It just works like you'd expect in most situations. I'm fighting it less than LastPass and my store of passwords is all cleaned up and far more sanitary. LastPass lets you make a mess far easier, so a nice side effect of BitWarden is that the structure is more prescriptive but I've been yet to bump into an area where it's blocked me from doing what I need.

Highly recommend BitWarden if you're fed up with LastPass and FireFox.

Re: Bitwarden Completes Third-Party Security Audit

#57
post #2

At the time of writing the link to actual report in the blog post does not work. Here is the correct link: https://cdn.bitwarden.com/misc/Bitwarden%20Security%20Assess...

I don't like their response to BWN-01-010 (not rotating the encryption key and re-encrypting the database on master password change). Their justification boils down to "either the attacker has full access to a compromised devices, or they don't." Meaning they could re-steal your master password AND encrypted database, or neither. I don't believe that is true. Let me give an example where their justification breaks do…

Maybe bring that issue to Bitwarden's attention on GitHub or other channels, and not just a comment here on HN?

Re: Bitwarden Completes Third-Party Security Audit

#58

Earlier quoted context omitted.

I don't like their response to BWN-01-010 (not rotating the encryption key and re-encrypting the database on master password change). Their justification boils down to "either the attacker has full access to a compromised devices, or they don't." Meaning they could re-steal your master password AND encrypted database, or neither. I don't believe that is true. Let me give an example where their justification breaks do…

Maybe bring that issue to Bitwarden's attention on GitHub or other channels, and not just a comment here on HN?

Cure53 just brought it to their attention, that's what this thread is about.

I'm simply questioning their justification/excuses for not fixing an issue Cure53 quite correctly flagged. Me opening an issue on Github that mirrors one from Cure53's audit report wouldn't be constructive.

Re: Bitwarden Completes Third-Party Security Audit

#59
post #48

We used LastPass for several years in our home, mostly because it was able to fill Firefox http basic auth dialogs. When Firefox switched to the webextension format, LastPass started using the Chrome version as the foundation for Firefox. This was a huge step backwards and my wife HATED it. The biggest problem she had was that it was that the standard workflow of it capturing generated passwords became unreliable and…

Switched to Lastpass half a year ago and it's been a rocky move (I didn't have a password manager before). It's consistently been painful to use. For example, my work email transfers between different domains for log in versus viewing and I think even a third. Lastpass never manages to suggest the password at the right time because of this and I always forget where to find it. The mobile app routinely makes me type m…

LastPass has gone downhill since the acquisition. It's horrible compared to what it was before.

Re: Bitwarden Completes Third-Party Security Audit

#60

We used LastPass for several years in our home, mostly because it was able to fill Firefox http basic auth dialogs. When Firefox switched to the webextension format, LastPass started using the Chrome version as the foundation for Firefox. This was a huge step backwards and my wife HATED it. The biggest problem she had was that it was that the standard workflow of it capturing generated passwords became unreliable and…

Yeah, I noticed the change in LastPass' behavior. It turns out that it actually DOES save the random passwords it generates... it's just very well hidden. If you generate a random password for a site, register your account, and LastPass does not catch it and doesn't prompt you to save the account info, it's not lost. If you open the 'Generate secure password' page by itself from the context menu extension, you'll get…

They added that feature after I and probably other users complained about it stupidly losing set passwords after the UI revamp.
Post reply on HN