Live data from Hacker News

Bitwarden second security audit report

bitwarden.com

51–60 of 118 posts

Re: Bitwarden second security audit report

#52

What does it cost to hire somebody reputable to perform an audit like this? Its something I want to look into for one of my own projects, but I have no frame of reference for what is a reasonable price for a simple full stack app (way simpler than bitwarden for sure)

The attached PDF is an automatically generated report. You can get something like that for £5-10k if you go through one of the typical audit firms (KPMG, Deloitte and co). In addition you can look into some ISO certifications or industry specific regulations. It's basically a checklist of a thousand questions: do you use TLS? are your applications protected by authentication? can custom folks access personal data of…

If you want an automatically generated report you can just run ZAP, Burp or Checkmarx against your system yourself :/

Re: Bitwarden second security audit report

#53

Tangential question: What password manager do you guys use?

Bitwarden. I used to use LastPass but I prefer Bitwarden because the clients are open-source (including optional self-hosting and a mobile app on F-Droid), the URL matching seems to be more flexible and intuitive to configure than I found on LastPass (more than just separate subdomains), and the syncing across devices and auto-fill using standard Android APIs works perfectly with the mobile app. I also pay the $10 USD/year for the premium plan mainly for native YubiKey 2FA without using TOTP codes.

I've considered using Pass or other open-source self-hosted/synced alternatives but I don't really want to fiddle with something like this quite yet because Bitwarden meets my needs perfectly.

Re: Bitwarden second security audit report

#56

It's good to see companies making reports public to provide some confidence that they're having reviews done, but in this case the scoping of this job seems a little odd, not sure if that's a bad reporting template or something else. Last page of the PDF indicates that they just did an external VA and pentest, but looking at their product set , I'd have expected (at least) a review of the web, desktop and mobile apps…

The only PDF linked in the blogpost is "Bitwarden Network Security Assessment Report", and it does indeed only cover network related topics. Their earlier report from 2018 covers lots of web/desktop application assessments: https://cdn.bitwarden.com/misc/Bitwarden%20Security%20Assess... So I wonder if they just forgot to mention that this second audit report doesn't cover that, or if there are more reports coming.

They did a code audit in 2018, and this is a network/pentest audit. They're two different things, that's all, and both are valuable.

Re: Bitwarden second security audit report

#57
post #17

Tangential question: What password manager do you guys use?

Bitwarden. Works well and the integration with 2FA/TOTP is amazing. I highly recommend to not rely on a single (mobile) device for 2FA. Loosing or breaking it might shut you out of certain accounts forever.

> Loosing or breaking it might shut you out of certain accounts forever.

But isn't this what the backup codes are for?

Re: Bitwarden second security audit report

#58
post #33

Tangential question: What password manager do you guys use?

Dashlane. Tried 1Password, LastPass and they are all not good enough. Bitwarden doesn't even come close.

In what ways do you find Bitwarden lacking? What are the advantages of Dashlane?

Re: Bitwarden second security audit report

#59

Earlier quoted context omitted.

In this business the title "External Penetration Test and Vulnerability Assessment" means the auditing company has run qualys/nessus* against bitwarden.com. * expensive commercial vulnerability scanning tools.

Yes, but the title of the page/blog post is "Security Audit Complete".

A page title fails to correct your misconception about a multiyear project and it is their fault?

This is one reason why people don't release this stuff in public.

Re: Bitwarden second security audit report

#60
post #17

Earlier quoted context omitted.

Bitwarden. Works well and the integration with 2FA/TOTP is amazing. I highly recommend to not rely on a single (mobile) device for 2FA. Loosing or breaking it might shut you out of certain accounts forever.

> Loosing or breaking it might shut you out of certain accounts forever. But isn't this what the backup codes are for?

Sure. But not everybody has them or they might be on that device...
Post reply on HN