Bitwarden second security audit report
51–60 of 118 posts
Re: Bitwarden second security audit report
#52What does it cost to hire somebody reputable to perform an audit like this? Its something I want to look into for one of my own projects, but I have no frame of reference for what is a reasonable price for a simple full stack app (way simpler than bitwarden for sure)
The attached PDF is an automatically generated report. You can get something like that for £5-10k if you go through one of the typical audit firms (KPMG, Deloitte and co). In addition you can look into some ISO certifications or industry specific regulations. It's basically a checklist of a thousand questions: do you use TLS? are your applications protected by authentication? can custom folks access personal data of…
Re: Bitwarden second security audit report
#53Tangential question: What password manager do you guys use?
I've considered using Pass or other open-source self-hosted/synced alternatives but I don't really want to fiddle with something like this quite yet because Bitwarden meets my needs perfectly.
Re: Bitwarden second security audit report
#54Tangential question: What password manager do you guys use?
Re: Bitwarden second security audit report
#55Re: Bitwarden second security audit report
#56It's good to see companies making reports public to provide some confidence that they're having reviews done, but in this case the scoping of this job seems a little odd, not sure if that's a bad reporting template or something else. Last page of the PDF indicates that they just did an external VA and pentest, but looking at their product set , I'd have expected (at least) a review of the web, desktop and mobile apps…
The only PDF linked in the blogpost is "Bitwarden Network Security Assessment Report", and it does indeed only cover network related topics. Their earlier report from 2018 covers lots of web/desktop application assessments: https://cdn.bitwarden.com/misc/Bitwarden%20Security%20Assess... So I wonder if they just forgot to mention that this second audit report doesn't cover that, or if there are more reports coming.
Re: Bitwarden second security audit report
#57Tangential question: What password manager do you guys use?
Bitwarden. Works well and the integration with 2FA/TOTP is amazing. I highly recommend to not rely on a single (mobile) device for 2FA. Loosing or breaking it might shut you out of certain accounts forever.
But isn't this what the backup codes are for?
Re: Bitwarden second security audit report
#58Re: Bitwarden second security audit report
#59Earlier quoted context omitted.
In this business the title "External Penetration Test and Vulnerability Assessment" means the auditing company has run qualys/nessus* against bitwarden.com. * expensive commercial vulnerability scanning tools.
Yes, but the title of the page/blog post is "Security Audit Complete".
This is one reason why people don't release this stuff in public.
Re: Bitwarden second security audit report
#60Earlier quoted context omitted.
Bitwarden. Works well and the integration with 2FA/TOTP is amazing. I highly recommend to not rely on a single (mobile) device for 2FA. Loosing or breaking it might shut you out of certain accounts forever.
> Loosing or breaking it might shut you out of certain accounts forever. But isn't this what the backup codes are for?