4 ms·
Don't confuse access to working laptop with access to encrypted data [upd: that was] stored inside it.
by ris58h 4y ago
Don't confuse access to working laptop with access to encrypted data [upd: that was] stored inside it.
- prophesi 4y agoTo clarify for those that jumped straight to the comments; the threat model this article is talking about is extracting the encrypted database stored locally on your machine to brute-force the PIN. Personally, I'd agree with Bitwarden on this that it's an attack that requires physical access to a user's device, or worse, remote admin privileges. > Using a PIN can weaken the level of encryption that protects your application's local vault database. > If you are worried about attack vectors that involve your device's local data being compromised, > you may want to reconsider the convenience of using a PIN. https://bitwarden.com/help/unlock-with-pin/#enable-unlock-with-pin https://bitwarden.com/help/unlock-with-pin/#enable-unlock-wi...
- yazzku 4y agoThen why encrypt it in the first place? That's the point the author makes (text in bold).
- prophesi 4y agoIt's a choice on the user to weaken the encryption. I don't use Bitwarden, but if they communicate that properly to the user, it's a valid compromise for convenience-versus-security.
- yazzku 4y agoThis doesn't answer the question. Why is there a choice to encrypt something when it's completely unnecessary (according to their threat model)? No point in building unnecessary complexity into software, especially software meant for security.
- prophesi 4y agoThe client-side lock of 5 PIN attempts solves the much more common threat model the layman is concerned with.
- waboremo 4y agoUsing the PIN is outdated anyways when it comes to convenience, all reasonable user OS now support biometrics and those offer better risk mitigation in comparison. It is something they should remove entirely in an upcoming version after giving users enough warning.
- NoZebra120vClip 4y agoPINs can be changed. How many fingers ya got?
- renewiltord 4y agoTen. I don't get why this is a constraint. If they're rubberhosing me, I'll just give them the master pass. They won't have to take my finger. If they get my fingerprint some other way, I can just switch to my next finger. And when I'm done, I can use PINs. I don't think it's mutability that matters. It's just that I leave fingerprints everywhere.
- waboremo 4y agoI'm pretty sure you can register the same finger over and over again for new "keys". Assuming you go through the tedious process of disabling, restarting, etc whatever each one of the underlying OS demands. It's an additional layer that Bitwarden (and other apps) do not get direct access to. So no excuse if you value convenience, PINs are not good. Short easy to remember and enter PINs are also the reason Apple is under fire due to how easily you can avoid biometrics and just use the 6 digit PIN.
- mt360 4y agoI wouldn't put too much faith in biometrics either, a real shame considering their convenience. https://blog.kraken.com/post/11905/your-fingerprint-can-be-hacked-for-5-heres-how/ https://blog.kraken.com/post/11905/your-fingerprint-can-be-h... Personally I advocate using BitWarden for commonly used logins that, if they were compromised, would not be catastrophic; perhaps in some cases because 2FA provides another, tautologically, factor, and KeePass secured with a FIDO2 device in challenge response mode, a passphrase, and possibly setting a higher key stretching work factor to further blunt any brute force attempt, in which more important data is held.