15 ms·
Bitwarden Heist – How to break into password vaults without using passwords
- nati0n 3y agoWebsite overloaded. Archived version here:https://web.archive.org/web/20240103131242/https://blog.redteam-pentesting.de/2024/bitwarden-heist/ https://web.archive.org/web/20240103131242/https://blog.redt...
- nlawalker 3y agoTL;DR: It's definitely interesting, but this is about attacking vaults with biometric unlock enabled (and are thus stored on disk) on Windows, and requires workstation access and a Bitwarden design flaw that was fixed in April. > the attack already assumes access to the workstation of the victim and the Windows domain > The underlying issue has been corrected in Bitwarden v2023.4.0 in April 2023 > As it turns out, we were not the first to discover this in March 2023, it had already been reported to Bitwarden through HackerOne.[1] I could have sworn [1] had a dedicated post here on HN but couldn't find it, it's worth a read too. [1]: https://hackerone.com/reports/1874155 https://hackerone.com/reports/1874155
- Dalewyn 3y ago>the attack already assumes access to the workstation of the victim I seldom can take "vulnerabilities" that require physical access seriously, because if a hostile is physically next to my computer I have more pressing concerns than some passwords.
- elzbardico 3y agoThe problem is that an unsophisticated user doesn't necessarily think like that, and could come to the conclusion that it is not a big deal to leave his workstation unlocked while going to fetch a coffee, after all, well... "I have a password manager, and to have access to it, it requires unlocking". Then some colleague calls them for an ongoing meeting so they can share some insight about some question that was raised in the meeting and so on. A far-fetched scenario? yes. But if it can happen, it will happen.
- BobaFloutist 3y agoThat unsophisticated user is also likely to have a printed out list of passwords taped to their monitor, or an unprotected excel file labelled "Passwords".
- eddythompson80 3y agoTo this day I don’t understand how “computer repair” shops are in business. When I was a shithead 16 year old I used to work at one. I found it amusing to see what files people deleted before giving us full physical access to their machines. I definitely saw things I shouldn’t have seen. It wasn’t until I saw something illegal that I freaked out and stopped doing it. I was so paranoid that I srm’ed my entire drive and theirs and never mentioned it to anybody. In retrospect I should have, but I was 16 and didn’t know what to do.
- Dalewyn 3y agoFor most people (ie: not us), computers are just another household appliance in the same vein as televisions, washing machines, refrigerators, and air conditioners. If it breaks, you get it fixed by a technician or go and get a new replacement.
- eddythompson80 3y agoYet they instinctively understand that they should delete certain files and prepare their computers for repair. We've had many who would walk in asking "hey, my computer is doing X is this fixable?" we would have no idea of course. We'd always ask can we see it, and they would say "I just don't wanna have to get it ready for repair if it wasn't possible" This is why I totally understand when Apple or MS go overzealous with encryption or T2 or secure boot. Despite "people like us" complaining about it.
- Zetobal 3y agoIf you have machines that have users logged in, are unlocked when none of your users are working on them and that are in reach of a 3rd party you have bigger problems than this.
- gtirloni 3y agoIn this case, physical access is very brief and almost imperceptible if you're not paying attention. It's different from trying to pry open an encrypted hard disk from a laptop or something similar. You probably won't even know that coworker you trust is compromised and attacked you this way.
- RedTeamPT 3y agoYes, it requires an attacker in a powerful position but it does not require physical access. Any program that runs in the user's session (without any special privileges) could have autonomously retrieved the biometric key and decrypted the vault without user interaction and without Bitwarden running.
- dist-epoch 3y agoThey mentioned not wanting to use keyloggers which would be their standard approach.
- deleted 3y ago[deleted]
- 2bluesc 3y agoThis affects Windows only. Really feel that should've made it to the title other it feels like click bait.
- deleted 3y ago[deleted]
- selykg 3y agoI worked in managing bug bounty programs at a previous job. If there is one thing I have learned it's that blog posts like this are heavily skewed towards making the problem seem much larger than it is. It's what gets the clicks, so it's not a surprise. It makes dealing with penetration testers and bug bounty participants really stressful and frankly, annoying. Our policy was that we would be happy if someone were to discuss bounties we paid out for, but we wanted the discussion to be fair and accurate. It did not ever really feel like it was mutually beneficial relationship. I don't miss that work at all really lol.
- deleted 3y ago[deleted]
- UberFly 3y ago"BITWARDEN HEIST - HOW TO BREAK INTO PASSWORD VAULTS WITHOUT USING PASSWORDS" Like this one??
- hypeatei 3y agoI'm glad they made some improvements to security as a result of this finding. This "attack" is still very specialized though and requires local access which (as mentioned) could've exposed the user to keyloggers and other malware.
- RedTeamPT 3y agoYes, it requires an attacker in a powerful position with local access. However, it does not require special privileges or techniques that may trigger endpoint security (such as keyloggers or memory dumping). The only requirements are reading a JSON file and making a single Windows API call to retrieve the key.
- hypeatei 3y agoGood point.
- malfist 3y agoDo hardware keyloggers trigger endpoint security?
- RedTeamPT 3y agoNo, but hardware keylogger require physical access.
- malfist 3y agoWhat is the difference between "physical access" and "powerful position with local access"
- Robin_Message 3y agoIt's the difference between the evil maid attack (someone sneaks a keylogger into your turned-off machine whilst cleaning your room) vs local privilege escalation (the sysadmin installs a game and now your entire network is owned).
- gtirloni 3y ago> As usual, we managed to get administrative access to the domain controller As usual? Is that the state of Windows Server security these days? I never managed a Windows-based network so I have no idea. I heard about these things back in the 2000's but I'm surprised this is "usual".
- ziddoap 3y agoWell, they're a pentesting company. Getting access to the DC is goal #1 for every engagement they do. So, I read this to be "as usual for us during our engagements", not "as usual for everyone all the time".
- deleted 3y ago[deleted]
- jabroni_salad 3y agoYes. If you have LLMNR, NTLM enabled, unsigned SMB allowed, and nonencrypted LDAP bindings then your domain controller can be popped with zero effort by metasploit. Legacy protocols can be very sticky and most repeat pentest engagements I am able to use the same exact method every time because they will never get addressed. Modern windows (since like vista-era) will use better stuff out of the box but will also allow downgrade attacks in the name of compatibility. Hell, I still find SMBv1 in a lot of places.
- SV_BubbleTime 3y ago>Hell, I still find SMBv1 in a lot of places. It cost me thousands of dollars last year to get our MSP to disable SMBv1 and force correct policies. They "Needed to audit for a week" to make sure this "didn't break older software". It was annoying I even had to ask that they didn't come to me saying "We won't support you if you have SMBv1 enabled".
- charcircuit 3y agoWhy hasn't Microsoft at least sandboxed these protocols if they are so bad in regards to security?
- guerby 3y agoI wonder if biometric bitwarden unlock on Android has the same kind of issue or not.
- RedTeamPT 3y agoNot that we are aware of. The security model of Android and iOS also makes it much easier to implement biometric unlock correctly.
- harrygeez 3y agoThere are a few convenient scapegoats here but ultimately in this case it is not biometric unlock that enabled this but rather characteristic of the Active Directory's design (I'm not sure I will call it a weakness). For Android and iOS if you forget your PIN code I believe you are screwed, as in no one can decrypt your device for you.
- RedTeamPT 3y agoActually it is not just an issue with AD design, but the AD design only makes it slightly worse. The underlying issue is that biometrics are not required to retrieve the biometric key from DPAPI and instead of authenticating with Windows Hello, any program could just simply ask DPAPI for the key.
- magicalhippo 3y agoMy understanding from a quick reading is that Bitwarden essentially used Windows Hello to ask "is the user there" and if so, asked DAPI to give Bitwarden the secret vault credentials which it happily did because that's its job. The problem with this was that the vault credentials in DAPI was not safe from other programs running as the user, nor from domain admins which could use the recovery key stored on the AD server (which they did in their attack after gaining admin access). The solution was to use Windows Hello the way it was meant. That is, to store an asymmetric key pair, where the private key is hidden and protected by the biometrics or hardware security key, and use that to encrypt the secret vault credentials before storing them in DAPI.
- deleted 3y ago[deleted]
- glub103011 3y ago[dead]
- walki 3y agoMicrosoft's %Appdata% directory is a security nightmare in my opinion. Ideally applications should only have access to their own directories in %Appdata% by default. I recently came across a python script on GitHub that allows to decrypt passwords the browser stores locally in their %Appdata% directory. Many attacks could be prevented if access to %Appdata% was more restricted. I also found a post of an admin a few days ago where he asked if there was a Windows setting for disallowing any access to %Appdata%. The response was that if access to %Appdata% is completely blocked Windows won't work anymore.
- mrguyorama 3y ago>python script on GitHub that allows to decrypt passwords the browser stores locally in their %Appdata% directory. Yes, otherwise known as "if you run code on your computer, it can run code on your computer". If a random python program can "decrypt" the passwords, that's not encryption. And browser password management isn't about security, but convenience.
- lukevp 3y agoFull unrestricted disk access for all users and code isn’t the only way an OS can be designed.
- mrguyorama 3y agoAppData is specifically where apps store data, and there are and were plenty of legitimate examples where you want some code to access data from an app in there. The entire point is that it is not meant to be a secure location, was never meant to be a secure location, has no intended security features etc. If you store your passwords in a text file on the desktop, that is also insecure but you would be wrong to say Notepad has a security vulnerability. Similarly, if you stored your passwords in the Windows registry unencrypted, that would also be insecure, but does not demonstrate a flaw in the Windows registry. If you want to be able to leave your secrets in the open without them being compromised, then you encrypt them. Browser password managers are not secure. That is not Window's fault.
- 0xbadcafebee 3y agotl;dr This means that any process that runs as the low-privileged user session can simply ask DPAPI for the credentials to unlock the vault, no questions asked and no PIN or fingerprint prompt required and Windows Hello is not even involved at all. The only caveat is that this does not work for other user accounts. Yikes Bitwarden has since made changes to their codebase to mitigate this particular scenario, which we will quickly summarize in the next section. They have also changed the default setting when using Windows Hello as login feature to require entering the main password at least once when Bitwarden is started. Phew Props to the security researchers for finding this bug! It's great that we have the infosec community to help protect us. Feels like one of the few industries whose monetary incentive is to help the public.
- WalterBright 3y agoI've always considered password vaults as a single point of failure that will compromise all of your passwords. I've had lots of intelligent, well-informed programmers argue that my concern is groundless.
- Sohcahtoa82 3y agoWithout using a vault, people end up re-using passwords or using weak passwords, which is IMO worse.
- hypeatei 3y agoThey make it easy to have strong passwords and sync across devices. You could use a local vault and sync yourself, use a piece of paper in a safe, or use your brain to store them. All of these come with tradeoffs and their own risks. Pick your poison.
- lordofmoria 3y agoEverything is a tradeoff - but the basic balance is very strongly in favor of password managers: 1. without a password manager that is shared on all your devices, you WILL re-use passwords out of frustration. 2. without a password manager, if you do any sort of regular sharing passwords with a engineering team, friends & family, you'll resort to pretty insecure channels. 3. true E2E encryption, while still providing some surface area, has proven in the field through multiple pretty bad breaches[1], that it's a security model that holds up under real-world circumstances. On the flip side, you are right: you are one compromised browser extension / binary away from having your local vault decrypted, and ALL your passwords compromised. But think about this: if someone has this much local access, chances are they can install a keylogger anyway, or read your clipboard, so the real difference is you've conveniently pre-loaded all your sensitive information in one go for the bad actor. [1]For example: https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/ https://blog.lastpass.com/2022/12/notice-of-recent-security-...
- WalterBright 3y agoWith a keylogger, you lose passwords you typed in since the keylogger was installed, but that is rarely all of your passwords.
- tamimio 3y agoOk but it assumes the domain is compromised as stated in the article, and if the domain controller is compromised, it’s a game over for connected machines hence these attacks usually focus on domain admin or schema admin. Edit: it seems the second non-biometric method doesn’t need domain, it’s still however need that local access > S-1-5-21-505269936… Kind of off topic but around 20years ago when I had my first portable harddisk, I used this method by creating these type of folders and remembering the numbers sequence in a creative way to hide my files when traveling/crossing borders while putting some decoy files in the plain sight, before knowing/using data encryptions, and it worked, I remember the agent taking my hdd and seeing him going through the decoy files and then returning my hdd normally.
- alberth 3y agoAgreed. > "We recently conducted a penetration test with the goal of compromising the internal network of a client in a Windows environment. As usual, we managed to get administrative access to the domain controller" This article feels like click-bait, when they buried the lede.
- kritr 3y agoSounds like the bigger issue in this case is that it’s not clear to developers in which cases they can rely on DPAPI to be entirely local, which I assume is what’s needed for password manager style applications.
- hiatus 3y agoInterestingly, the latest versions of bitwarden for mac that are available for download from github no longer work with biometric authentication, requiring the user to download the app from the app store in order to use that functionality.
- Pesthuf 3y agoI wonder why that is. Do App Store Applications get extra privileges? Why isn’t being signed enough for an application to store secrets only it can access in the keychain?
- hiatus 3y agoI too wonder. The App Store version did ask for keychain access for the biometric data, while the non-app store version did not (and never asked for that, to my knowledge).
- Aerbil313 3y agoTangential, what is the state of security on Linux desktop nowadays? Say out-of-the-box Debian 12 using Wayland. Is it still just that nobody is attacking Linux so it's safe?
- dharmab 3y agoOut of the box is not enough. Debian has a checklist for building a secure system, as well as some helper tools for configuration: https://www.debian.org/doc/manuals/securing-debian-manual/index.en.html https://www.debian.org/doc/manuals/securing-debian-manual/in...
- rdl 3y agoThe complexity of deployed identification/auth chain/secrets management/ec. is pretty terrifying; even if you can somehow understand it for one OS and hardware platform, if your service needs to support multiple OSes plus web plus multiple auth technologies plus a recovery path and everything else, dragons. This is one of the few things cryptocurrency gets right in one specific way better than most other applications -- in most cases, everything is explicitly about operations with a key, and you build up protections on both sides of that. Unfortunately those protections themselves are often inadequate (hence billions of dollars in losses), but it's at least conceptually simpler and potentially could be fixed.
- dannyw 3y agoI'm not convinced crypto is inherently less secure; I'd argue it's more secure on average. Data breaches happen every day; whether in financial services or not. The difference is that a breach is catastrophic for crypto; but just bad for most businesses.
- lxgr 3y agoHave any of these catastrophic failures happened due to client/wallet-side user confusion, though? I'm not a big fan of many things in crypto, but what I've seen in terms of "what you see is what you sign", clear user interfaces, secure user verification and confirmation etc. in some popular wallets is something that many existing banks could take a lesson from.
- rdl 3y agoA lot of them -- the whole "phishing" thing happens to crypto users with regularity, and often for surprisingly large amounts. Usually not the single-victim/cause $100mm+ hacks, but lots of $1-5mm losses. The "new" fun thing is creating spoofed addresses where first 4 and last 4 characters match a target, but are controlled by attacker, but variations on getting users to initiate transfers to the wrong address are pretty common. Crypto gets a few things really right, and can do some things which can't be done by tradfi, but has a huge number of problems which need to be solved (some are "open problems" which don't really have solutions yet; some are taking what the top 0.1% of people or what people do some amount less than 100% of the time and making it universal, which is mostly what I am doing now as CSO at a crypto insurance company.)
- southernplaces7 3y agoI've always thought the trust placed in password managers was deeply misplaced. Like any company, it's only a question of time and circumstance until one of them is massively breached, but right here on HN, a whole bunch of people who should know better recommending them as if they were flowers from heaven. Because of course hey, "it's just convenient".
- southernplaces7 3y agoAnd why would this be downvoted? Is there some specific holy aspect to password management services that makes them immune to being the victims of the same massive data leaks that frequently affect a whole broad range of tech companies?
- rmbyrro 3y agoThere should be a warning label on Windows like there is for cigarretes. Every time a user logs, Microsoft should be obliged by Law to show: "Your computer will get cancer if you proceed logging in."
- deleted 3y ago[deleted]