|
|
|
|
|
by fullstop
123 days ago
|
|
Bitwarden's response [1] is interesting. "All issues have been addressed by Bitwarden. Seven of which have been resolved or are in active remediation by the Bitwarden team. The remaining three issues have been accepted as intentional design decisions necessary for product functionality." They don't expand on what those three are. 1. https://bitwarden.com/blog/security-through-transparency-eth... |
|
They've also "accepted" a vulnerability --- BW01 from the paper, I believe --- that allows a malicious server to read all vault items from a user as soon as they accept any invitation (real or not) to an "organization".