grb
December 30, 2022, 2:04am
28
DoctorB:
. That data will likely be encrypted again by BW on their server and hence they can claim 100% encryption. Certainly this is what LastPass have done.
Your post has a lot of speculation that is not accurate. What you have written above is not true about Bitwarden, and it is not true about LastPass. Also, neither service claim “100% encryption”, they only claim “zero-knowledge”, which essentially means that the encrypted data cannot be decrypted by the company.
This GitHub Gist shows an example of what the user vault data would look like when stored on Bitwarden’s servers — please take a look. There is no server-side encryption of the vault data:
Cipher.md
|Id|UserId|OrganizationId|Type|Data|Favorites|Folders|Attachments|CreationDate|RevisionDate|DeletedDate|Reprompt|
|---|---|---|---|---|---|---|---|---|---|---|---|
|082db5fe-672d-4fe2-a408-aeaf00cfba97|d5f4a43b-d63b-48d4-ae35-aeae0132e6b1|NULL|1|{"Uris":[{"Uri":"2.a1+qHnq2WrpgAzWfMUEONg==\|l0GkuwJXxz5RenMW8/9XrU3Kwo3ReYUpNjgcOtloSF8eKc5/uw/cW1ILTdABe5yY\|JziTV78cdnLzPCHZYWpyHx3pAy2JDC97n1+K+Oy6Hf8="}],"Username":"2.Th3koMGmv+MygdZ8wK2Vrg==\|sFsLK3PSaRtEAUU7Sk2g1g==\|4dWvwEGBX4rwYYzOUEMPO9TmUc9uEHNiv/J8J+vvC/o=","Password":"2.SctMJiLmKL91oKl1xX90MA==\|3QWIZvege3s2uVyFk+s3mQ==\|x7669Eef8faZOL4Zuh70KVX7BQ3gRHKwZWCCoXUbuLk=","PasswordRevisionDate":"2022-12-29T14:13:16.392Z","Name":"2.NZwczlu5Y3FAY8DC02DmUw==\|nnATSql7S0/dfqSnYsoC9dfxIxiXJqQezbZ5QnARN3E=\|D8M9dftTvAARpYi3AAP4wgTAZ9KQPTwfiRK9VCb5fmA=","PasswordHistory":[{"Password":"2.yJMIvogMOpOAbHxHi8ArZQ==\|IIV4d2XUlHPXvYx+k1pDKw==\|zDH9xc0AzImXJasUXI4Pv16wkD537d8cl+UgICdk0zQ=","LastUsedDate":"2022-12-29T14:13:16.392Z"}]}|{"D5F4A43B-D63B-48D4-AE35-AEAE0132E6B1":true}|NULL|NULL|2022-06-09 12:36:18.9300000|2022-12-29 14:13:29.3400000|NULL|1|
Device.md
|Id|UserId|Name|Type|Identifier|PushToken|CreationDate|RevisionDate|
|---|---|---|---|---|---|---|---|
|094d5d66-9926-4988-b794-aeae013319a2|d5f4a43b-d63b-48d4-ae35-aeae0132e6b1|firefox|10|f1d68af8-4934-4f26-9a33-fcda3f6f9079|NULL|2022-06-08 18:38:07.0400000|2022-06-08 18:38:07.0400000|
Organization.md
|Id|Name|BusinessName|BillingEmail|Plan|PlanType|Seats|MaxCollections|UseGroups|UseDirectory|UseTotp|SelfHost|Storage|MaxStorageGb|Gateway|GatewayCustomerId|GatewaySubscriptionId|Enabled|LicenseKey|ExpirationDate|CreationDate|RevisionDate|BusinessAddress1|BusinessAddress2|BusinessAddress3|BusinessCountry|BusinessTaxNumber|UsersGetPremium|UseEvents|Use2fa|TwoFactorProviders|UseApi|UsePolicies|Identifier|ReferenceData|UseSso|UseResetPassword|PublicKey|PrivateKey|OwnersNotifiedOfAutoscaling|MaxAutoscaleSeats|UseKeyConnector|UseScim|UseCustomPermissions|
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|64758741-98f9-4ed7-9d27-aeba01172990|Enterprise Org|NULL|[email protected] |Enterprise (Annually)|11|29|NULL|1|1|1|1|NULL|1|0|cus_changedcusjustincase|sub_changedsubjustincase|1|GUmf6MWLtSUE9i4raH44|2022-07-27 16:56:25.0000000|2022-06-20 16:56:23.9433333|2022-06-20 16:56:23.9433333|NULL|NULL|NULL|NULL|NULL|1|1|1|NULL|1|1|NULL|{"id":null}|1|1|MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA7v0rGhnq6wGZkI6KmfKAyjcMrpA6HRayDpLwlBUTPVZmz0f3lNGE4YUOZN2f8ImheWE9ankffJWbJeW+enhW5f9BYVw84lTn+KZmhzk/crgBDFoz3fO/q03fjtpvrTVJVWXvCXM4pImOPaJiGIEtdAZIqjJgIkkw8kSD8guHfx/B0Yrygd1V8iHndrpe7xFC6Z0TGetC+tMw4Pxi5mpUrpkm8nOvs8R9YZofz9d0iO5/JCJO1knFqSMByPK0IG1nD4fUjkEVCixNl8Fjknd8a25LXQVvOe1M4i3EZU6yrLARqNFPSg4SwhubKiP0TlAxsujOZbYU3ZWPbuYfKMmjgQIDAQAB|2.Y0cOb2Pb2Y+bqRhVrMdhpA==\|4rEv8EGIdXgJ39J00WTYFA1jY+oh6+ZqDnAwlnX2ULp1jES2drFQHDw1mdAYhPe8AdNen30eosnGDtOed064lCBmMeM4BRvbFXJixX56/brkwN7xVXzCvu7OaI1wuQuQ0yQdz2qob0diAVIaArhom4aRHzZhBx3VKxKPXywN86ldypYWtsf8fatBeNC7dm0IZpDeooVbBq06StakhLZAFwPMYFy4Sect59NBxqyxBw0ynlLmSynCGb+CF/T9ZzBTnW4WP7W9OgGVzVYPb5b+OnCtbqp4pAbR7HL/Sw0tcayBLLx/1x3z6Dqvu62dI1/+Oa/mYqper/oRKIWhF8/ZJUtYnZ6prx930FMvJqxBAAVRint2qfkVcXxZJfWESOqiektPWf6deXj+1I3A9TyfUzcucb2HgYYykj5535x74ZEm2SNBK5VQAwb+p6S7FxIT2Gb856oiz4ooFoHO4oy0bFOGxoueS9vqtUJMHjT0UCbMYKyJPnN2y4jqtrG5E9jMVzb5ZneE07iqOnVuVhIEm96XievhO7WC8uL4IlRSEIhRlcuW28wSIfOYBJRVlQVc/V6x6a8vdAu5mjhWPtmbITByc3lo+iKuaQsqjfEimqac8f9yiJCupGOTIXTfMRZhTgGDxbM6DyjTIvco+8XFWoAHSdjc3QsHpAH+lCdxW1Qj+3TzLyGFKsCinyvSx/WyAcZVZsLNNMlHLJ3imnR3DEYHPAEzsUmEla52VyppIf543UCiq7H8c4E2bOfvlASfT0F4nB7Cz8QepBT6E2Zzx8fss2LcGb1V0pBUQKQVlLnB/rByk+CzGHUH6sMAU0YamPCgB4LwUch+dHeFP6o0w/vntqWSn5T6JvZ11lfiZIdinWc2//Gu6bIVl8Ojxvj2Evy52/DoCzv/GR9X2+o08iCqrMLPKKgkWAvYrYmmhO/AUwDDqAQ6hzguk4slEIeA9Y9tiZv9kKwKDFcCvjMh+eYy8ovqufjn/79RqXRN9G/QQbkcaEuy4Li61xkh3SwkXGJLTq65RGie8rZERJGplPnWSvCvXnZdNI3DZMH9VzjdEGLX8/rnergZzmVvbAkhURXEP5vzjxYERtXslK2dCAGGrW2KTre2jzd8UrJ3QZmKthvaGBKBv1XJjAfrk6EphKE7ISSITHahTqf3ANWE9VFvO+tSLPCo01dO096sC+yQ9xRbfq3Ap+ItnKePEFogYvipdyKqkOAAf0rBJ9ZQBuxgzZKKS7htkfhBF/Nm7wc8DWBidl5fzfiKtB3361jaWLk5Nq8gnjGrSEdBPwR2SoTrb5d7NlrTXpOwthtu3xokJo1IJpIJdS8KyqOW2dS0d0oTOMGGXpBih4s6i4XKYWlXpmquDiMiXx2HJ8FLIxb3w0Tr3t0vVjmu5sS/DmrsalZM2qRlWrP0uhG8SgngptrcIv+V1x31znIrPrPvLdpmzj+EmDJWyQ1w4j+0mCKLEOdt4Yo/UzHP0bOlmYguis4720NwMARo3kYhesBgitSJfRamG9umkqSAVhL+/Wh224VTemP4i5xgCsOm+4TXZCZa5TI/KLPIHWH/RO0v3ZW43BdksRQ1xXD5/FwC51VNeZnRxAmatN4KHqmz89c3PjpgKa6P7jJaUqAOyat18WU=\|oOgqZaUkcydo0ncbnx46+N+6PS1l2d1aqwBWgfETstE=|2022-09-14 11:59:41.7900000|NULL|0|0|1|
There are more than three files. show original
1 Like