[HN Gopher] Ask HN: Anyone else Bitwarden account being attacked
       ___________________________________________________________________
        
       Ask HN: Anyone else Bitwarden account being attacked
        
       My Bitwarden is being attacked. I get emails from Bitwarden about
       someone trying to access my account. Emails look legit.  Anyone
       else experiencing this today?
        
       Author : thedangler
       Score  : 19 points
       Date   : 2023-06-12 18:35 UTC (4 hours ago)
        
       | adr1an wrote:
       | I don't use that service. Do you have two-factor authentication?
       | If not, you should really consider using it. The 2fa is a major
       | security upgrade for any account.
        
         | nytesky wrote:
         | I had problems with their 2FA where the code would come via SMS
         | but be rejected. I was able to recover via email but it was
         | distressing. Do they have OTP service now?
        
           | brewdad wrote:
           | They also support Yubikey.
        
           | meany wrote:
           | I use an auth app for 2FA.
        
       | j0ner wrote:
       | This happened to me too (from a NordVPN IP). I presume someone is
       | spamming Bitwarden with login credentials they found in some
       | stolen database. It's possible that Bitwarden had a database
       | breach but that's very unlikely.
        
       | campak wrote:
       | Nope. Someone may just be targeting you. May be worthwhile to
       | change your master password.
        
         | firstlink wrote:
         | I would not recommend ever changing credentials while under
         | attack, unless they are known to be weak (but the time to
         | change them is before the attack, in that case). The process of
         | changing them opens up several vectors of attack. Additionally,
         | if the attacker already obtained the encrypted payload, it
         | would only be harmful to give them the same data encrypted
         | under a new key.
        
           | CommitSyn wrote:
           | What additional vectors?
           | 
           | If they already had the data, would they be using the web
           | account login page?
        
             | firstlink wrote:
             | E.g. PITM attack on password reset endpoints.
             | 
             | And yes, if I had a bitwarden vault I wanted to crack I'd
             | absolutely be using the web account login page. The latter
             | is more likely to yield to have some vulnerability than the
             | at-rest encryption, which when exploited would yield the
             | password; or it could scare the target into falling into my
             | PITM attack, or otherwise act irrationally.
        
       ___________________________________________________________________
       (page generated 2023-06-12 23:02 UTC)