Bitwarden Passwords At Risk? | A Security Expert Explains

  Рет қаралды 31,156

Jason Rebholz - TeachMeCyber

Jason Rebholz - TeachMeCyber

Жыл бұрын

A recent report emerged that showed Bitwarden can mistakenly send your passwords to hackers if you misconfigure your settings.
📝 Sign up for my free weekly security newsletter: weekendbyte.teachmecyber.com/
❤️ Leave a comment and hit the like button because it helps spread cyber security knowledge to more people.
🔔If you found this helpful, subscribe to the channel!
www.youtube.com/@teachmecyber...
🚀 Connect with me on LinkedIn
/ jrebholz

Пікірлер: 58
@teachmecyber
@teachmecyber 10 ай бұрын
Good news, Bitwarden has fixed this issue so it's not longer vulnerable! github.com/bitwarden/clients/pull/4994
@kyn1xx
@kyn1xx 10 ай бұрын
so its safe to have it enable??
@teachmecyber
@teachmecyber 10 ай бұрын
Yes, it's safe to use now!
@kyn1xx
@kyn1xx 10 ай бұрын
@@teachmecyber but the warning is still there...
@mr.boniato6402
@mr.boniato6402 8 ай бұрын
This is one of the great benefits of open source!.. there's a problem, someone will fix it!
@puterich
@puterich 8 ай бұрын
Summary of the video: Settings > auto fill > disable autofill on page load
@teachmecyber
@teachmecyber 8 ай бұрын
That about sums it up
@tuams
@tuams Жыл бұрын
At least nothing crucial. Thank you for keeping us in the loop!
@teachmecyber
@teachmecyber Жыл бұрын
An edge case that hopefully stays minimal! Hopefully this gets Bitwarden to push a fix as well to close this out.
@SummitMTB
@SummitMTB 9 ай бұрын
I never use autofill anyway it doesn't work very well in the first place. Great video btw, lots of info condensed into a highly digestible video - love it thanks!
@teachmecyber
@teachmecyber 9 ай бұрын
I've found your mileage can vary with auto fill depending on your setup and the password manager. It's gotten better but some apps or sites can be troublesome. Thanks for the feedback!
@manny7886
@manny7886 10 ай бұрын
I never use auto-fill because I only store my passwords partially. A little inconvenience to copy and paste my username and passwords + add the missing characters but it gave me a piece of mine. I'm not worried if BW got hacked, the hacker still don't have my complete passwords.
@teachmecyber
@teachmecyber 10 ай бұрын
I've heard similar tactics from others as well. It's a pretty cool way to do it. You could still use autofill to make it a bit easier and then add your manual character at the end. It's a cool little hack!
@freewilly8557
@freewilly8557 8 ай бұрын
Partially storing your password and not auto filling is good advice if you use a password manager. This content creator is just advertising. His videos just explain how convenient it is to use password managers. There are always dangerous exposures if you store your passwords anywhere. The different password managers just have varying amounts of risk. Your practice of storing a partial password and adding something you remember is the best practice which ensures that your full password is never available anywhere.
@xileets
@xileets 2 ай бұрын
So It's like salting the data? Interesting. How much salt do you add? Is it a nonsense string? There is also always the possibility that a password is stored in a server as plain text instead of as the hashed value.
@manny7886
@manny7886 2 ай бұрын
@@xileets - It's up to you how many character(s) you want to add. In my case I add my driver license number.
@Demiarioch
@Demiarioch 6 ай бұрын
Thanks for the edumucation anyway!
@teachmecyber
@teachmecyber 6 ай бұрын
Always good to be aware of the risks!
@LouAnn1024
@LouAnn1024 3 ай бұрын
Am I able to add an extension with my Safari browser?
@alejandroschab2764
@alejandroschab2764 Жыл бұрын
Which password manager do you recommend among these 4 in your free plan? I am between Bitwarden, Dashlane, Nordpass or Protonpass. thanks
@teachmecyber
@teachmecyber 11 ай бұрын
I would go for Bitwarden or Dashlane. I value firms that focus on their key products.
@Tech-geeky
@Tech-geeky 11 ай бұрын
Don't go for Lastpass, like me.. I gather BitWarden doesn't have "monitoring of dark web" and other features you get with Lastpass Premium. but that would be "user chose to gave it up" type thing anyway before a attack happened.
@BooleanDev
@BooleanDev 9 ай бұрын
bitwarden or KeePassX, dont use anything from Nord
@rinorbytyqi1439
@rinorbytyqi1439 Жыл бұрын
Hey is there maybe a plan for making a Q&A format?
@teachmecyber
@teachmecyber Жыл бұрын
What would you like to see for it?
@salmaniyafarooqui7703
@salmaniyafarooqui7703 8 ай бұрын
Heyy i need your help i broke my phone and lost all contacts and my master password as well for bitwarden how do i recover my bitwarden back
@teachmecyber
@teachmecyber 8 ай бұрын
Check out this link. Your options might be limited here depending how you set it up. bitwarden.com/help/forgot-master-password/
@Quizzical106
@Quizzical106 Ай бұрын
I don't get this. If I was on the proper website, it would not have a malicious on it. If I was on a fake site, it will not autofill.
@jx5189
@jx5189 Жыл бұрын
So it is just when BW. autofill's on page load that is the problem? Once the page loads isn't the malicious still on the page what happens when I manually click autofill?
@teachmecyber
@teachmecyber Жыл бұрын
Well the good news is that Bitwarden fixed the flaw, so it won't happen automatically now when autofill is enabled. When you are using the manual autofill, BW will warn you if there is an untrusted that would get filled.
@craigmonty
@craigmonty 11 ай бұрын
@@teachmecyber So should we still disable auto-fill? Or is it ok to use now?
@user-zk3rc1po2v
@user-zk3rc1po2v 11 ай бұрын
@@teachmecyber please answer So should we still disable auto-fill? Or is it ok to use now?
@teachmecyber
@teachmecyber 11 ай бұрын
All good to use now!
@tiagolima3241
@tiagolima3241 10 ай бұрын
@@teachmecyber I from Brasil. Gostei do seu vídeo. Agora fiquei com medo de usar. Isso vale pra qqr navegador? Existe algum ajuste que não carregue esse ?
@drshepherd6567
@drshepherd6567 2 ай бұрын
So just dont use the browser extension and youre good! Esay!
@xileets
@xileets 2 ай бұрын
EVERY bit of convenience other than memory in your brain is a *potential* security vulnerability. (Even your memory is a liability, for example, I'm presently working on developing security practices for older people who have memory issues.)
@subscrypts
@subscrypts 10 ай бұрын
sweet!
@teachmecyber
@teachmecyber 10 ай бұрын
Thanks for watching!
@deookello3825
@deookello3825 Жыл бұрын
I guess it's not yet a life threatening procedure 😂
@teachmecyber
@teachmecyber Жыл бұрын
Thankfully this is a minor issue and one that has since been patched!
@fearless6947
@fearless6947 Жыл бұрын
@@teachmecyber so now I don't need to check, if it's unchecked?
@teachmecyber
@teachmecyber Жыл бұрын
Correct, it will be off by default and Bitwarden fixed the underlying issue
@fearless6947
@fearless6947 Жыл бұрын
@@teachmecyber thanks :) I appreciate your reply
@Tech-geeky
@Tech-geeky 11 ай бұрын
😆 Apple iFrame... Watch this space.... ..... Arn't all online password managers at "risk" then ? Lastpass has auto-fill has well, but as least we know now *why* its disabled by default. Since its disabled anyway, and the number of sites is 'low' for this risk, perhaps the option shouldn't be there at all. Stop that at its source. :) what would be the legit reason for this low risk exploit?
@teachmecyber
@teachmecyber 11 ай бұрын
I see it as an oversight in the code. They didn't account for different s they could be sitting on the main web page. This has been fixed now thankfully!
@jakepthsd
@jakepthsd 7 ай бұрын
Bitwarden a year ago didn't have that auto-fill or prompt-to-fill or select to fill feature ...that was why I went to another vendor! Not sure how much improvement Bitwarden has now ,,,but it seems to slack behind other vendor!
@teachmecyber
@teachmecyber 7 ай бұрын
It's a bit like the Android vs Apple argument. Other password managers have a more streamlined interface and are easier to use but don't have as much customization, like Apple. Bitwarden isn't the best looking but it has most of the features and a lot more customization.
@thurm101
@thurm101 Жыл бұрын
I’ll just copy/paste.
@teachmecyber
@teachmecyber Жыл бұрын
That's a tried and true method. One benefit of the autofill (with user interaction) is that it can help you detect phishing sites. If you click on a link and it prompts for a login, your password manager will look for the URL. If it's not something it recognizes, there's no password to put in.
@Tech-geeky
@Tech-geeky 11 ай бұрын
I just drag'n'drop .... Doesn't go to clipboard that way
@teachmecyber
@teachmecyber 11 ай бұрын
That's a good approach.
@zoenagy9458
@zoenagy9458 3 ай бұрын
Booo, this is not fixing the root cause
@teachmecyber
@teachmecyber 3 ай бұрын
They recently released a full fix for this
@joelkaplan8172
@joelkaplan8172 2 ай бұрын
This is the end of bitwarden for me
Hackers Targeting Bitwarden Vaults | Easy Steps to Protect Your Passwords
4:16
Jason Rebholz - TeachMeCyber
Рет қаралды 16 М.
Bitwarden Tutorial: 12 essenzielle Tipps & Tricks
17:56
PrivacyTutor
Рет қаралды 43 М.
World’s Deadliest Obstacle Course!
28:25
MrBeast
Рет қаралды 158 МЛН
Wachtwoordmanager maken met Bitwarden
4:16
Informatica Pieter Nieuwland
Рет қаралды 1,7 М.
The Most Important Bitwarden Setting You Never Heard Of
12:20
Jason Rebholz - TeachMeCyber
Рет қаралды 45 М.
Proton Pass Tutorial | Is it Worth Switching Your Password Manager?
14:14
Jason Rebholz - TeachMeCyber
Рет қаралды 36 М.
Bitwarden Review 2024 | Is it Actually Secure?
7:59
Cyber Lab
Рет қаралды 38 М.
Is Bitwarden's 2FA Code a Security Risk?
11:06
Pro Tech Show
Рет қаралды 10 М.
Passbolt - Why I Can't Recommend This Password Manager
10:12
The Easiest (and MOST SECURE) Way to Log into Bitwarden
9:00
Jason Rebholz - TeachMeCyber
Рет қаралды 26 М.
I Tested 7 Password Managers: the BEST of 2024 is…
5:48
All Things Secured
Рет қаралды 152 М.
What are Passkeys? | Are Passwords Dead? | A Security Expert Explains
8:07
Jason Rebholz - TeachMeCyber
Рет қаралды 23 М.
Debunking 5 MYTHS About Yubikey
15:36
Shannon Morse
Рет қаралды 188 М.
Simple maintenance. #leddisplay #ledscreen #ledwall #ledmodule #ledinstallation
0:19
LED Screen Factory-EagerLED
Рет қаралды 24 МЛН
GamePad İle Bisiklet Yönetmek #shorts
0:26
Osman Kabadayı
Рет қаралды 635 М.
В России ускорили интернет в 1000 раз
0:18
Короче, новости
Рет қаралды 1,8 МЛН
ИГРОВОВЫЙ НОУТ ASUS ЗА 57 тысяч
25:33
Ремонтяш
Рет қаралды 338 М.
⚡️Супер БЫСТРАЯ Зарядка | Проверка
1:00