3 ms·
For those just scanning the comments, "full remote access" is just being used to mean "has an automatic update system" here
by codys 6y ago
For those just scanning the comments, "full remote access" is just being used to mean "has an automatic update system" here
- sneak 6y agoAn interaction-free automatic update system is, by definition, RCE, which is equivalent to full remote access. The Bitwarden devs can always access your passwords at any time if they choose to do so, as a result. This, to me, is as serious a vulnerability as lacking encryption in the first place.
- brigandish 6y agoHow do they decrypt the vault without the master password?
- sneak 6y agoBy replacing the client code with code that exfiltrates the password the next time you enter it. Alternately, brute forcing the client password is straightforward due to their use of a too-fast KDF and low iteration count. https://github.com/bitwarden/jslib/issues/52 https://github.com/bitwarden/jslib/issues/52 https://github.com/bitwarden/server/issues/589 https://github.com/bitwarden/server/issues/589
- brigandish 6y agoI agree that automatic updates should have a toggle, Signal desktop is another client where the devs won't provide one and have even taken egregious steps to prevent blocking it. Run in a reduced-privilege account though and either client will still require your assent via the admin rights to install. You're also right about the KDF but to be fair to them the devs say they'll accept work from a fork[0] to Argon2, if and when it's done (properly). [0] https://community.bitwarden.com/t/switch-to-argon2/350/24 https://community.bitwarden.com/t/switch-to-argon2/350/24
- gruez 6y agoHow do you feel about browsers or operating systems that are updated on a monthly/weekly basis? Do you not upgrade them ever? Do you set them to manual update but blindly accept all the updates? Or do you manually update only after performing a detailed code review of all the source code changes, along with doing a build yourself to make sure nothing malicious was slipped in?
- sneak 6y agoI disable automatic updates on all software on my machines, and update them periodically on a schedule, using downloads that are verified as authentic. I'm not sure where the rest of your questions come from. "Do you not upgrade them ever?" does not logically follow from being opposed to the major security vulnerability that no-interaction automatic binary modification poses.