3 ms·
I love this product have used it for a long time now but more recently started getting worried about security. I hope the maintainers are doing their due dilige
by ronnier 1y ago
I love this product have used it for a long time now but more recently started getting worried about security. I hope the maintainers are doing their due diligence around securing their docker hub account (many of us run VW in docker) and are careful about libraries the project depends on. Some questionable coding practices were made that I'm not sure I agree with (calling a 3rd party sites in some scenarios). As more of us switch to self hosting VW it will become a juicer target for bad actors. Really hoping we don't wake up one day to find out that our database was uploaded by a BA
- surge 1y agoI've threat modeled this myself, and as I understand it the Bitwarden client side decrypts/encrypts everything locally. So even if backend was entirely compromised, it's never getting anything without the master password, and that's never sent across by the client. Then again, there's also the web interface.
- ronnier 1y agoYeah if an attacker was able to insert javascript then it's possible.
- blr_lpm 1y agoFor this particular threat vector, where the client is compromised, the backend doesn’t matter.
- franga2000 1y agoA compromised server can inject exfil code into the web page it serves. If you only ever use the apps then you should be fine though.
- 9cb14c1ec0 1y agoWhich is only possible if logging into the web client and not when using the bitwarden desktop app or browser extensions.
- crimsonnoodle58 1y agoIf you're running on kubernetes, a simple network policy and blocking the container from using DNS will stop any compromised image from performing a data exfill. I do this for most containers. If the container must have web access in some form, setup a squid proxy and only whitelist safe and trusted domains that can't be exfilled to.
- ronnier 1y agoI use Docker (in Unraid).
- victor106 1y ago> a simple network policy and blocking the container from using DNS Can you please point to some resources that can help with how to do this?
- NewJazz 1y agoNot sure about the DNS part, but NetworkPolicies should be familiar to anyone who takes Kubernetes seriously. https://kubernetes.io/docs/concepts/services-networking/network-policies/ https://kubernetes.io/docs/concepts/services-networking/netw... Edit: Did some research and found that Calico has a feature for some kind of DNS filtering https://www.tigera.io/blog/how-to-secure-kubernetes-workloads-using-calico-dns-security-policy/ https://www.tigera.io/blog/how-to-secure-kubernetes-workload...
- currysausage 1y agoThe web frontend could still send secrets to third parties.
- maxwellg 1y agoFor extra security, an intermediary can set Content Security Policy (CSP) headers that instruct browsers to only connect to certain domains. CSP headers aren't a total solution, but they're a good tool in the toolkit for redundancy against exfiltration. https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Content-Security-Policy/connect-src https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/...
- guerby 1y agoSecurity audits have been made by German BSI for vaultwarden (and other free software): https://www.heise.de/en/news/Password-manager-BSI-reports-critical-vulnerabilities-in-Vaultwarden-9982432.html https://www.heise.de/en/news/Password-manager-BSI-reports-cr...
- guerby 1y agoLink to reports page: https://www.bsi.bund.de/DE/Service-Navi/Presse/Alle-Meldungen-News/Meldungen/Codeanalyse-KeePass-Vaultwarden_241014.html https://www.bsi.bund.de/DE/Service-Navi/Presse/Alle-Meldunge...