SDF Chatter
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
wuffa@discuss.tchncs.deM to Bitwarden@discuss.tchncs.deEnglish · 2 years ago

Biometric key is stored in Windows Credential Manager, accessible to other local unprivileged processes

hackerone.com

external-link
message-square
1
fedilink
3
external-link

Biometric key is stored in Windows Credential Manager, accessible to other local unprivileged processes

hackerone.com

wuffa@discuss.tchncs.deM to Bitwarden@discuss.tchncs.deEnglish · 2 years ago
message-square
1
fedilink
Bitwarden disclosed on HackerOne: Biometric key is stored in...
hackerone.com
external-link
Bitwarden Desktop on Windows allows the user to enable vault unlock through Windows Hello (under File > Settings > Unlock with Windows Hello). When this is done, a "Biometric master key" is generated and stored locally inside the Windows' user credential set. This is done through the "wincred" API, in particular through the functions...
alert-triangle
You must log in or register to comment.
  • Yeah2206@infosec.pub
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 years ago

    This appears to be a problem with window’s security model. Not only BW has this problem, 1P has this problem as well, and presumably other password managers that allow such convenience too. The only way is not to persist the encryption key/password/secret across app restart.

    See

    • https://community.bitwarden.com/t/does-bitwarden-save-master-password-in-tpm/31292/18
    • https://support.1password.com/windows-hello-security/

Bitwarden@discuss.tchncs.de

bitwarden@discuss.tchncs.de

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !bitwarden@discuss.tchncs.de

Discuss the Paswordmanager Bitwarden.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 1 user / week
  • 45 users / month
  • 431 users / 6 months
  • 9 local subscribers
  • 974 subscribers
  • 53 Posts
  • 287 Comments
  • Modlog
  • mods:
  • wuffa@discuss.tchncs.de
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org