Results of Bitwarden security audit published
#1
Information 
[Image: bitwarden-audit.png]
Quote:Bitwarden hired the German security company Cure 53 to audit the security of Bitwarden software and technologies used by the password management service.

Bitwarden is a popular choice when it comes to password managers; it is open source, programs are available for all major desktop operating systems, the Android and iOS mobile platforms, the Web, as browser extensions, and even the command line.

Cure 53 was hired to "perform white box penetration testing, source code auditing, and a cryptographic analysis of the Bitwarden ecosystem of applications and associated code libraries".

Bitwarden released a PDF document that highlights the findings of the security company during the audit and the company's response.

The research term uncovered several vulnerabilities and issues in Bitwarden. Bitwarden made changes to its software to address pressing issues immediately; the company changed how login URIs work by limiting allowed protocols.

The company implemented a whitelist that allows the schemes https, ssh, http, ftp, sftp, irc, and chrome only at the point in time and not other schemes such as file.
Full reading: https://www.ghacks.net/2018/11/13/result...published/
[-] The following 1 user says Thank You to harlan4096 for this post:
  â€˘ silversurfer
Reply


Messages In This Thread
Results of Bitwarden security audit published - by harlan4096 - 13 November 18, 08:08

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AxCrypt 3.1.5.0
AxCrypt 3.1.5.0: ...harlan4096 — 11:50
AMD will reinstate memory encryption on ...
The feature was qu...harlan4096 — 11:48
Microsoft confirms Windows 11 version 26...
Who would have gue...harlan4096 — 11:46
Windows 11 June 2026 Update Breaks Recyc...
Microsoft has conf...harlan4096 — 11:45
Microsoft Edge 149.0.4022.80
Release Summary ...harlan4096 — 15:38

[-]
Birthdays
Today's Birthdays
avatar (48)kinotHeemn
avatar (39)Ceballos1976
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (40)efynu

[-]
Online Staff
There are no staff members currently online.

>