[HN Gopher] Ask HN: Anyone else Bitwarden account being attacked
___________________________________________________________________
Ask HN: Anyone else Bitwarden account being attacked
My Bitwarden is being attacked. I get emails from Bitwarden about
someone trying to access my account. Emails look legit. Anyone
else experiencing this today?
Author : thedangler
Score : 19 points
Date : 2023-06-12 18:35 UTC (4 hours ago)
| adr1an wrote:
| I don't use that service. Do you have two-factor authentication?
| If not, you should really consider using it. The 2fa is a major
| security upgrade for any account.
| nytesky wrote:
| I had problems with their 2FA where the code would come via SMS
| but be rejected. I was able to recover via email but it was
| distressing. Do they have OTP service now?
| brewdad wrote:
| They also support Yubikey.
| meany wrote:
| I use an auth app for 2FA.
| j0ner wrote:
| This happened to me too (from a NordVPN IP). I presume someone is
| spamming Bitwarden with login credentials they found in some
| stolen database. It's possible that Bitwarden had a database
| breach but that's very unlikely.
| campak wrote:
| Nope. Someone may just be targeting you. May be worthwhile to
| change your master password.
| firstlink wrote:
| I would not recommend ever changing credentials while under
| attack, unless they are known to be weak (but the time to
| change them is before the attack, in that case). The process of
| changing them opens up several vectors of attack. Additionally,
| if the attacker already obtained the encrypted payload, it
| would only be harmful to give them the same data encrypted
| under a new key.
| CommitSyn wrote:
| What additional vectors?
|
| If they already had the data, would they be using the web
| account login page?
| firstlink wrote:
| E.g. PITM attack on password reset endpoints.
|
| And yes, if I had a bitwarden vault I wanted to crack I'd
| absolutely be using the web account login page. The latter
| is more likely to yield to have some vulnerability than the
| at-rest encryption, which when exploited would yield the
| password; or it could scare the target into falling into my
| PITM attack, or otherwise act irrationally.
___________________________________________________________________
(page generated 2023-06-12 23:02 UTC)