4 ms·
Bitwarden argues that the finding is out of scope because from what I can gather the claim that exploiting this requires access to the device. If that were the
by ar9av 4y ago
Bitwarden argues that the finding is out of scope because from what I can gather the claim that exploiting this requires access to the device. If that were the case, I'd agree with them. But having access to the Bitwarden database is not the same as having access to the device. There are plenty of vulnerabilities that give you limited read access. Simply selling your hard drive without erasing the data first would be a very common scenario.
That's why SSH keys or GPG keys are typically protected by a pass phrase. Not a PIN, not a password, a pass phrase. At least that's the wording that OpenSSH uses, and Bitwarden should do the same. Secure your database with a pass phrase, not a PIN, or else you might be vulnerable. That's how it should be communicated to the user. These details matter.
- ddulaney 4y agoI really like the way 1Password and MacOS work together for security [0]. Even if my laptop is unlocked, each 1Password interaction needs my fingerprint. That unlocks a secret stored in the Secure Enclave, which I trust. (Security is hard and flaws are possible, but Apple has done a reasonably good job here from what I can tell.) I only have to mess around with typing a long string of nonsense in when I'm registering a new device, rather than every time I want to use my SSH or GPG key (or trusting an agent to hold it in memory, which... I'll do it, but I won't like it). I wish I could rely on similar things from Linux, but the user experience just isn't there on the desktop. A previous employer issued laptops that had both a fingerprint reader and some kind of HSM, so the hardware was there, but I remember both of them missing drivers at the time, and even with drivers the userland software support would've been very hacky. [0]: https://support.1password.com/touch-id-apple-watch-security-mac/ https://support.1password.com/touch-id-apple-watch-security-...
- KennyBlanken 4y agoKeepassXC does the same thing. Once you enter your password, you can unlock with your fingerprint.
- andrewaylett 4y agoBitwarden's fingerprint integration does exactly the same.
- lxgr 4y agoGiven that, really the only thing that Bitwarden would have needed to do is to clearly label the PIN feature as being much less secure than the biometry option, especially when used in combination with the "do not ask for passphrase after browser restarts" option, which persists an only PIN-encrypted version of the master encryption key to disk.
- andrewaylett 4y agoAgreed -- I happily use biometric unlock, but there's no way I'd turn on PIN unlock.
- Takennickname 4y agoFingerprinting and everything work perfectly fine on Fedora with the ThinkPad's built in fingerprint scanner.
- lxgr 4y agoInteresting, how can fingerprints be used as a cryptographic unlocking method on Linux? Does this involve the TPM somehow, or does the security model assume a non-compromised userspace and/or kernel?
- Takennickname 4y agoI don't know about all of linux, but default Fedora (gnome keyring) appears to support TPM since 2016.
- thrashh 4y agoYour database IS protected with a pass phrase When you enable the PIN, you deliberately weaken your security for convenience. However, when the database unloads, your database is still protected by your pass phrase.
- ambiso 4y ago> However, when the database unloads, your database is still protected by your pass phrase. This is not the case if you disable the "lock with master password on restart" option. In that case only your PIN is guarding access the the vault data. Using a PIN shouldn't have to mean weakening the security, since there's several secure implementation options of a PIN. (See other comments about Windows Hello for example)