Tangential question: What password manager do you guys use?
Bitwarden second security audit report
61–70 of 118 posts
Re: Bitwarden second security audit report
#62Tangential question: What password manager do you guys use?
Re: Bitwarden second security audit report
#63https://github.com/bitwarden/jslib/issues/52 I am astounded to see this missing from the report. Apparently the report was just their external API configuration or something?
1. External vulnerability assessment of the Bitwarden computing systems and web applications
2.External penetration testing of the Bitwarden computing systems and web applications
Re: Bitwarden second security audit report
#64Tangential question: What password manager do you guys use?
After a few months, I watched back to LastPass. Bitwarden never quite worked right and as far as I know doesn't provide a way to review access history (I was hacked and wanted to see if other IP addresses accessed Bitwarden).
Re: Bitwarden second security audit report
#65Earlier quoted context omitted.
Those prices might stand up for contractors -- but are a bit low to bring in a commercial outfit, at least for any of the larger reputable security consulting businesses. Would suggest starting prices would be closer to £1000 a day. And rates are significantly higher in the US. Accountability and consistency is a real concern in crowdsourcing. There is a reason we dont spend too much time designing an idea and then c…
The crowd sourcing stuff that I've seen comes in two different formats usually. There is the one where you put your URLs/IPs up there a d say "this is in scope"and someone finds something wrong, you pay them (ie. Someone says this has xss, you pay them a few hundred dollars) which has relatively little risk in terms of you only pay for what you get. The other ones are where you'd be allocated a test which then gets s…
The discussion of relative merit of bug bounty versus a pentest is well trod ground, so I won't rehash here except to say I would never consider a bug bounty replacement for a pentest, and if you're asked for a pentest report as part of third-party vetting etc. many organizations will be concerned to see a bug bounty program compiled report.
The latter example sounds like https://cobalt.io/. I've seen several reports and all I can say is if I were vetting a third-party or otherwise looking for assurance of security posture I would still want to see a "real" pentest from a reputable firm.
Re: Bitwarden second security audit report
#66Tangential question: What password manager do you guys use?
Re: Bitwarden second security audit report
#67What does it cost to hire somebody reputable to perform an audit like this? Its something I want to look into for one of my own projects, but I have no frame of reference for what is a reasonable price for a simple full stack app (way simpler than bitwarden for sure)
Pentester for 10 odd years: usually for an external test you would scope it at X days depending on the number of IPs etc. And it should note that an external test really doesn't find much. External is usually £750/day for 1-2 days testing and one reporting. Internal testing (ie. Auditing a domain and all computers attached) is about the same price, maybe a bit more, and takes a bit longer usually. A build review is h…
Boutique Firm X billed at 285/hr with an average of 60 hours for a small application. That comes out to $2,280 USD a day.
Standard Small Consulting Firm Y billed at 250/hr. In the past 6 years I have yet to see anything below 235/hr, which is still $1880 USD/day (1479, GBP).
Hope that helps, GP.
Re: Bitwarden second security audit report
#68Tangential question: What password manager do you guys use?
Re: Bitwarden second security audit report
#69Tangential question: What password manager do you guys use?