4 ms·
This was an external infrastructure test which carries no real weight for the app itself. It just makes sure that stupid stuff like ssh open to the internet, no
by morrbo 6y ago
This was an external infrastructure test which carries no real weight for the app itself. It just makes sure that stupid stuff like ssh open to the internet, no public CMS available etc. Hasn't happened. That being said bitwarden do do more in depth security audits but this particular audit doesn't really mean too much.
- user5994461 6y agoThe report itself was automatically generated by one of the popular scanning tools. It's 1 hour to run the automated scan and 1 day to format the PDF nicely for the customer. The thing is half worthless, verifying that the CDN has TLS and raising warnings about obscure HTTP/CORS headers. But occasionally it can find some really bad misconfiguration or library with a critical vulnerability in dire need of an upgrade. (Of course they would never publish a report finding issues like that).