Bitwarden Heist - How to Break Into Password Vaults Without Using Passwords
3 January 2024
Sometimes, making particular security design decisions can have unexpected
consequences. For security-critical software, such as password managers, this
can easily lead to catastrophic failure: In this blog post, we show how
Bitwarden’s Windows Hello implementation allowed us
to remotely steal all credentials from the vault without knowing the password
or requiring biometric authentication. When we discovered this during a
penetration test it was so unexpected for us that we agree...
Read more at blog.redteam-pentesting.de