4 ms·
I'm using Bitwarden and all of my passwords are long, complex, and unique. Am I at risk? I understand that this is not good, but if my passwords are unique th
by Timpy 6y ago
I'm using Bitwarden and all of my passwords are long, complex, and unique. Am I at risk? I understand that this is not good, but if my passwords are unique then the only thing that can happen is losing the credentials to the one account that got leaked, right? I don't think my bank's website has an unsecure subdomain that I have to worry about. Should I remove Bitwarden from my browser until this is fixed?
- nichos 6y agoThings important as banking and email should have 2FA turned on. If they don't, I'd still say you're reasonably safe given that you're using unique passwords.
- jeroenhd 6y agoYou are at risk if you have credentials stored for any website that allows arbitrary subdomains to be controlled by customers, such as Github pages, Gitlab pages, some ISP and university hosting solutions, etc. You can ensure the login doesn't leak by changing the match detection settings for your logins. If you've got the match detection for a login set to "base domain" (the default AFAIK), then a login for example.com is also matched for evil.example.com which might be a risk if you get linked or redirected there. If you've got the login configured with "hostname" or "starts with", then you're probably safe. You're also safe if you've locked your Bitwarden vault. If you want to disable Bitwarden to be sure and you don't want to lose access to your synced data and your settings, just don't unlock the vault (or only unlock it while logging in and lock it immediately after). I won't personally remove Bitwarden because my most important logins don't allow subdomains to be abused like this. You'll have to make that choice for yourself though.
- EE84M3i 6y agoIs this true? Are you implying bitwarden doesn't respect the PSL? It seems like it does.
- jeroenhd 6y agoThe PSL is not a real solution to this threat, though it does protect a lot of high profile websites; it's a useful tool, but by no means a complete solution to subdomain attacks. With cloud platforms like Azure it's possible for a dangling subdomain to be taken over[1], for example; sure, that's preventable, but it still poses a risk. As I've said in another comment, many educational facilities also offer subdomains or shared hosting space for students and working groups. An attacker with control over evil.student.university.edu could steal university.edu credentials and use them for all kinds of nasty things like identity theft and blackmail. Theoretically this could be solved by adding all of these domains to the PSL, but there's more universities in the world than people using PSL so good luck with that. You also risk breaking educational utilities with uninformed listings so you'd need a list from the IT facilitators to be sure about listing something in the PSL. I don't think it's going to happen, and I wouldn't assume the PSL is a waterproof security tool for these kinds of risks. [1]: https://blog.cystack.net/subdomain-takeover-chapter-two-azure-services/ https://blog.cystack.net/subdomain-takeover-chapter-two-azur...
- EE84M3i 6y agoI agree completely. However, you listed "Github pages" in your examples which is very well known to be on the PSL.