4 ms·
Sounds like a bug with autocomplete disabled, but I don’t see this as a security issue. What is the risk with using Bitwarden in this circumstance? That I trus
by davidg109 6y ago
Sounds like a bug with autocomplete disabled, but I don’t see this as a security issue.
What is the risk with using Bitwarden in this circumstance? That I trust one server of the company but not the other and therefore a bad actor now has my creds?
- viraptor 6y agoOr you trust one user of a company but not another. Many services give each org a separate subdomain. If they support basic auth for whatever reason then just going to the other organisation will give them a hash of your credentials.
- niksakl 6y agoWith basic auth you give something more than that. You give the ACTUAL credentials, because they are base64 encoded and not hashed. It is trivial to decode them and have the raw values. To assume that a user trusts the subdomain because she trusts the domain, is something I find insane.
- viraptor 6y agoYou're right. I was thinking of digest auth which at least has nonces and hashing. Basic does not.