Bitwarden Heist – How to break into password vaults without using passwords
blog.redteam-pentesting.de
Bitwarden Heist – How to break into password vaults without using passwords
1–10 of 209 posts
Re: Bitwarden Heist – How to break into password vaults without using passwords
#2Re: Bitwarden Heist – How to break into password vaults without using passwords
#3Really feel that should've made it to the title other it feels like click bait.
Re: Bitwarden Heist – How to break into password vaults without using passwords
#4> the attack already assumes access to the workstation of the victim and the Windows domain
> The underlying issue has been corrected in Bitwarden v2023.4.0 in April 2023
> As it turns out, we were not the first to discover this in March 2023, it had already been reported to Bitwarden through HackerOne.[1]
I could have sworn [1] had a dedicated post here on HN but couldn't find it, it's worth a read too.
Re: Bitwarden Heist – How to break into password vaults without using passwords
#5TL;DR: It's definitely interesting, but this is about attacking vaults with biometric unlock enabled (and are thus stored on disk) on Windows, and requires workstation access and a Bitwarden design flaw that was fixed in April. > the attack already assumes access to the workstation of the victim and the Windows domain > The underlying issue has been corrected in Bitwarden v2023.4.0 in April 2023 > As it turns out, we…
I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.
Re: Bitwarden Heist – How to break into password vaults without using passwords
#6Re: Bitwarden Heist – How to break into password vaults without using passwords
#7This affects Windows only. Really feel that should've made it to the title other it feels like click bait.
Our policy was that we would be happy if someone were to discuss bounties we paid out for, but we wanted the discussion to be fair and accurate. It did not ever really feel like it was mutually beneficial relationship. I don't miss that work at all really lol.
Re: Bitwarden Heist – How to break into password vaults without using passwords
#8TL;DR: It's definitely interesting, but this is about attacking vaults with biometric unlock enabled (and are thus stored on disk) on Windows, and requires workstation access and a Bitwarden design flaw that was fixed in April. > the attack already assumes access to the workstation of the victim and the Windows domain > The underlying issue has been corrected in Bitwarden v2023.4.0 in April 2023 > As it turns out, we…
>the attack already assumes access to the workstation of the victim I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.
A far-fetched scenario? yes. But if it can happen, it will happen.
Re: Bitwarden Heist – How to break into password vaults without using passwords
#9As usual? Is that the state of Windows Server security these days? I never managed a Windows-based network so I have no idea. I heard about these things back in the 2000's but I'm surprised this is "usual".