Live data from Hacker News

Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign

socket.dev

51–60 of 458 posts

Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign

#51
https://github.com/doy/rbw is a Rust alternative to the Bitwarden CLI. Although the Rust ecosystem is moving in NPM's direction (very large and very deep dependency trees), you still need to trust far fewer authors in your dependency tree than what is common for Javascript.

Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign

#52
post #26
post #20

KeePass users continue to live the stress free live. I've managed to avoid several security breaches in last 5 years alone by using KeePass locally on my own infra.

I need my passwords to be accessible from my infrastructure and my phone. How do you achieve this with KeePass? I assumed it was not possible, but in fairness, I haven't really gone down that rabbit hole to investigate.

Not op but I mean you can use a public cloud with Cryptomator on top if you don’t trust your password DB on a non E2E cloud. Or you can just use your own cloud (but then no access outside or can risk and open up infra), and then any of the well known clients on your phone. Can optionally sandbox them if possible and then just be mindful of sync conflicts with the DB file but I assume you, like most people, will 99.9% of the time be reading the DB not writing to it.

Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign

#56
I mean, what's the future now? Everyone just vibecoding their own private tools that no "foreign government" has access to? It honestly feels like everything is slowly starting to collapse.

Also didn't Microsoft (the owner of GitHub) got access to Claude Mythos in order to "seCuRe cRitiCal SoftWaRe InfRasTructUre FoR teh AI eRa"? Hows securing GitHub Action going for them?

Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign

#58

I recently had to disable their Chrome extension because it made the browser grind to a halt (spammed mojo IPC messages to the main thread according to a profiler). I wasn't the only one affected, going by the recent extension reviews. I wonder if it's related.

> CLI builds were affected [...]

> Bitwarden’s Chrome extension, MCP server, and other legitimate distributions have not been affected yet.

Re: Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign

#60
post #41
post #20

KeePass users continue to live the stress free live. I've managed to avoid several security breaches in last 5 years alone by using KeePass locally on my own infra.

Which is great for Hacker News users that can maintain their own infra. But if we're talking "stress free", that's not an answer for the average user...

The average user is reusing their password everywhere, and rotation means changing the numeral 6 at the end of the password to 7.
Post reply on HN