Password managers less secure than promised
61–70 of 87 posts
Re: Password managers less secure than promised
#62Earlier quoted context omitted.
Haha this was a powermove. It is genuinely great that since it’s just a file you can host it anywhere you want. S3, WebDAV, your own site. I personally use copyparty and WireGuard for my kdbx file. I find it better than syncthing because there’s an obvious master copy (edited in place), and there’s no good way to keep syncthing running all the time on iOS, which can lead to sync conflicts.
Just how do you use copyparty and wireguard for this if you kindly elaborate on that please
Re: Password managers less secure than promised
#63Earlier quoted context omitted.
Bitwarden's response [1] is interesting. "All issues have been addressed by Bitwarden. Seven of which have been resolved or are in active remediation by the Bitwarden team. The remaining three issues have been accepted as intentional design decisions necessary for product functionality. " They don't expand on what those three are. 1. https://bitwarden.com/blog/security-through-transparency-eth...
you can see them in the report at the bottom, but I counted four. See my post above.
Re: Password managers less secure than promised
#64Re: Password managers less secure than promised
#65What a sane idea to store all your secrets in one place.... for attackers to get ahold of them in one move.
Re: Password managers less secure than promised
#66Re: Password managers less secure than promised
#67caveat not properly addressed in the blog post: all "attacks" are assuming full takeover of web servers, which is certainly a scenario that should be protected against, but isn't really a vulnerability unless chained with something else. almost all online services would be "vulnerable" in this way - take almost any login system. an RCE on a system hosting a login page would obviously be vulnerable to account takeover…
Re: Password managers less secure than promised
#68The article is nearly useless for users of the software who want to know how their data may have been affected. The researchers' website is more descriptive, especilly wrt specific findings. https://zkae.io/
Bitwarden's response [1] is interesting. "All issues have been addressed by Bitwarden. Seven of which have been resolved or are in active remediation by the Bitwarden team. The remaining three issues have been accepted as intentional design decisions necessary for product functionality. " They don't expand on what those three are. 1. https://bitwarden.com/blog/security-through-transparency-eth...
They've also "accepted" a vulnerability --- BW01 from the paper, I believe --- that allows a malicious server to read all vault items from a user as soon as they accept any invitation (real or not) to an "organization".
Re: Password managers less secure than promised
#69Someone on Reddit says they reported some of those Bitwarden issues to them 4 years ago and they were ignored: https://www.reddit.com/r/Bitwarden/s/LsJWCaQ6YD
Re: Password managers less secure than promised
#70> cloud-based password managers. Enough said. This kind of stuff should be offline only. If you need to access your password database on multiple devices, set up a LAN and/or a Wireguard tunnel for remote access.