24 ms·
If I run the compromised CLI, do they get all my passwords?
by sigmonsays 6mo ago
If I run the compromised CLI, do they get all my passwords?
- bhouston 6mo agoExactly, that could widen the blast radius of this particular compromise significantly.
- NeckBeardPrince 6mo agoRead the article
- rtaylorgarlock 6mo agokinda crazy to see this comment required in this particular context, yet here we are
- hgoel 6mo agoIt's an understandable question, the article reads like an AI generated mess.
- valicord 6mo agoWhere does it answer this question in the article?
- ErneX 6mo agoThe article explains what is extracted.
- valicord 6mo agoNo it doesn't?
- jeroenhd 6mo agoThe article waffles on forever and gives some generic advice. Meanwhile, Bitwarden themselves state that end users were almost never affected: https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127 https://community.bitwarden.com/t/bitwarden-statement-on-che... You had to install the CLI through NPM at a very short time frame for it to be affected. If you did get infected, you have to assume all secrets on your computer were accessed and that any executable file you had write access to may be backdoored.
- kbolino 6mo agoNo, at least according to Bitwarden themselves: https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127 https://community.bitwarden.com/t/bitwarden-statement-on-che...