Increase Third Party Audits and Penetration Testing + Routinely Vary Auditors

Hi,

I’m thinking about the fact that Bitwarden should be audited again in the future. The reasons I believe that are :

  1. future change to encryption protocols or hashing (new flaws discovered, or obsolete ones);
  2. error in codes in implementing new features or correcting some issues (lot of potential mistakes)
  3. changes in OS or browsers that are compatible wit Bitwarden
  4. etc.

It may sound paranoiac, but, passwords managers should be be a bit more paranoiac than the vast majority of softwares, no? Maybe it could be done at a regular time or within a certain range of changes. I know that Hacker One is involved it Bitwarden, but, I fear that it’s not as serious as a full audit done by a serious security company. When I look to Hacker One activity related to Bitwarden, it seems a bit light…

I guess it needs, at least, some thinking about it.

I would hope that there’ll be regular pen testing carried out by a third party. Would be nice to get more details on this.

1 Like

I was wondering too. So, I wrote to support and they give me that answer: “We have intentions of scheduling another security audit this year.” So, that’s good news! Be patient, it looks like it’s coming soon.

1 Like

Thats great to hear. Vulnerabilities arent static, with new exploits come new pen tests. :smiley:

1 Like

I would love to donate some money for an security audit.
Please consider starting a donation portal for this!

In July 2020, Bitarden successfully completed a thorough security assessment and penetration test by auditing firm Insight Risk Consulting. You can read more about this security audit here.

2 Likes

Thank you @vachan for your reply.
I just had 2018 in mind but did not know that there was a recent audit.
Good to know.

1 Like

I woud suggest trying to hire Wladimir Palant (founder of AdBlock Plus) for the next audit. He has found major security vulnerabilities in LastPass and other password managers. Here is one of his blog posts about LastPass, there are links to more in the “see also” section:

Should you be concerned about LastPass uploading your passwords to its server?

1 Like

Also, would it not be right to have a remunerated bug bounty program? As Wladimir points out, he has to make a living too…

We’ll be talking a little more about our Hackerone program this morning at this event :smiley:

Sadly I missed it. Is a recording available somewhere?

This is a feature request related to governance and policy of security practices which has a direct impact on engineering and codebase.

Request: Increase Third Party Audits and Penetration Testing + Routinely Vary the Auditors

Issue: The size of the user base for Bitwarden warrants a proportional increase in published, third party security audits of the codebase, including penetration testing. To be clear, Bitwarden does do third party audits and it does publish them. The audits appear sound and are conducted by well-known and reputable auditors with expertise in IT security. However, audits appear to be less frequent than some key competitors.

Example:
1Password: Security audits of 1Password. (6 published audits in 2022 alone)

Bitwarden: Compliance, Audits, and Certifications | Bitwarden Help Center and Compliance | Bitwarden

LastPass: Can’t find a source of consolidated, published audits.

You can see from the very small above sample where Bitwarden sits. This is not a criticism. An audit schedule is going to need to be annually budgeted for and will increase as your dominance increases in the marketplace, as this exposes you to greater attention from bad actors.

It may be argued that the open source nature of Bitwarden compared to its competitors acts as an ongoing crowd sourced auditor. This is a reasonable argument. However, bug reporting by the community and bug bounty programs are an additional security benefit, they are not something which should replace or limit the frequency of routine third party audits.

Additional published, third party security audits increase consumer confidence by affirming the already secure codebase of Bitwarden by subjecting it to routine, frequent audits by varied auditors who have dedicated expertise in security.

If you support this change, please vote.

Thank you.

4 Likes

Thanks for the feature suggestion! For forum reader reference, the full Bitwarden compliance page is located at https://bitwarden.com/compliance/. Rest assured your feedback has been passed along to the team :+1:

1 Like

Thanks. I have edited my original post to include the Bitwarden compliance page and also left the original Bitwarden Audit page.

I also notice that last year’s pen-testing’s (by Cure53) result wasn’t announced specifically (although included in the compliance page), while the previous years’ were. I think it is a good idea to definitely announce it in the blog, and announce it in communities routinely but as widely as possible. It’s good for the users to hear that BW is serious in maintaining the audit schedule and making these as transparent as possible.

This would be a contrast to LP’s claim of being audited but can’t be checked anywhere (on the company’s blog, in the media, etc.)

1 Like

Thanks for the feedback, I believe these are usually communicated out, but I’ll share feedback with the team :+1:

Oh, the Cure53 report completely slipped by - and I have a RSS feed set up for the blog so I‘d have seen it.

On that note, did you deny Cure53 the right to publish the full report themselves?
(Usually they add the reports on their website under „publications“.)