Daily Shaarli

All links of one day in a single page.

January 3, 2024

Bitwarden Heist - How to Break Into Password Vaults Without Using Passwords - RedTeam Pentesting
thumbnail

Sometimes, making particular security design decisions can have unexpected consequences. For security-critical software, such as password managers, this can easily lead to catastrophic failure: In this blog post, we show how Bitwarden’s Windows Hello implementation allowed us to remotely steal all credentials from the vault without knowing the password or requiring biometric authentication. When we discovered this during a penetration test it was so unexpected for us that we agreed with our client to publish a blog post about it and tell the story.