For password protection, dump LastPass for open source Bitwarden
- Reference: 1673868611
- News link: https://www.theregister.co.uk/2023/01/16/dump_lastpass_bitwarden/
- Source link:
LastPass is perhaps the world's most popular password manager. It's also arguably the most broken password manager. There's a better, safer open source alternative.
But before I dive into Bitwarden, let's talk a little bit about why LastPass is problematic. Late last year, [1]LastPass CEO Karim Toubba revealed that an [2]August security incident had been much worse than they'd first admitted. Instead of simply losing internal source code and developer documents – bad enough – they'd also [3]lost customer account information and vault data .
[4]
What does that mean? It means that, at the least, someone out there may have your unencrypted subscriber account data. That includes your LastPass usernames, company names, billing addresses, email addresses, phone numbers, and IP addresses. They also have your vault data. That includes website URLs and your encrypted usernames and passwords.
[5]
[6]
Has your account been breached? LastPass isn't saying. How many people's account data has been stolen? We don't know. Has everyone's data been swiped? Maybe.
Toubba claims that the encrypted data remains "secured with 256-bit AES encryption and can only be decrypted with a unique encryption key derived from each user's master password using our Zero Knowledge architecture." So, in theory, your passwords should be safe.
[7]
Yeah. Right. If you used a weak password for your master password, say, the ever-popular "123456," you're as good as cracked. And with that, all your other passwords will fall right into the attacker's hands. Even the best encryption lock in the world won't help you if you've given the attacker the key with an easy-to-guess master password.
I also find it more than a little sketchy that LastPass isn't telling anyone any further details of what's what with the break-in. Bitwarden, on the other hand, is transparent with its [8]audits and certifications besides its open codebase. The difference is clear.
LastPass recommends you change your master password and all your other passwords. I recommend you kiss LastPass goodbye and switch to another password manager.
[9]
There are many good password managers. They include 1Password, DashLane, and NordPass. But for my money, or no money at all, you can't beat Bitwarden.
[10]Bitwarden is a kinda sorta open source program . Specifically, it uses a source-available license. The company admits the Bitwarden License does not qualify as open source under the Open Source Initiative (OSI) definition, but they "believe that the license successfully balances the principles of openness and community with our business goals."
[11]LastPass admits attackers have a copy of customers' password vaults
[12]Intruders get their hands on user data in LastPass incident
[13]LastPass source code, blueprints stolen by intruder
[14]Popular password manager LastPass to be spun out from LogMeIn
I wish it were under, say, an Apache license, but it's still more open source-friendly than anything else out there so I'll live with it.
Leaving aside the licensing issue, the practical side of Bitwarden is it's free to use both on a server or a client. For example, as a client, you can run it on Linux, Windows, macOS, Android, iPhone, and iPad. With its browser extensions, you can also use it on Brave, Chrome, Edge, Firefox, Safari, Opera, Vivaldi, and Tor. The cost? You can run it for free on every device and browser you've got.
For free, you also get a cloud-based store for all your passwords, Bitwarden Web Vault; a random password generator; two-factor authentication (2FA); and the added safety of Bitwarden's database breach feature. This last feature checks to see if any of your passwords have already been exposed.
Spoiler alert: odds are your passwords are already out there. Don't believe me? Check your email address or phone number on HaveIbeenPwned and prepare for an unpleasant surprise.
Suppose, however, you don't trust anyone with your IDs and passwords? In that case, you can do what I do and [15]run your own Bitwarden server . If doing it from scratch is too daunting for you, you can set Bitwarden up pretty easily on your own machine using Docker containers. Don't have a server of your own? You can even [16]install and run Bitwarden off a Raspberry Pi .
Let's say you're not a Linux system administrator, and not as paranoid as I am. In that case, you may want to invest in one of Bitwarden's commercial tiers.
For $10 a year, you get a password strength report; a gigabyte of storage for encrypted file attachments; and 2FA hardware secure login support for YubiKey and/or Duo. I'm a big believer in physical 2FA keys. It's just way too easy to crack texting/SMS 2FA. The most popular authenticator apps, such as Google and Microsoft's, are tied at the hip to major companies.
If you have a family or small group, there's a $40-a-year plan for six users. You can also share passwords with this plan. Do not, I repeat, do not do this. Maybe you trust your brother. Me? I'm not so trusting.
Finally, there are two Bitwarden business plans. The first, Teams, for small organizations, costs $3 a month per user. The bigger and more full-featured Enterprise plan will run you $5 per user monthly.
Whatever you decide to do, I urge you to quit LastPass and switch to another password manager. I don't know what's going on there. No one does. Frankly, I just don't trust them anymore. And neither should you. ®
Get our [17]Tech Resources
[1] https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/
[2] https://www.theregister.com/2022/08/25/lastpass_security/
[3] https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y8WCtJ9Ly@JRR5Ih4aswmgAAAIU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8WCtJ9Ly@JRR5Ih4aswmgAAAIU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8WCtJ9Ly@JRR5Ih4aswmgAAAIU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y8WCtJ9Ly@JRR5Ih4aswmgAAAIU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[8] https://bitwarden.com/help/is-bitwarden-audited/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y8WCtJ9Ly@JRR5Ih4aswmgAAAIU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[10] https://github.com/bitwarden/server/blob/master/LICENSE_FAQ.md
[11] https://www.theregister.com/2022/12/23/lastpass_attack_update/
[12] https://www.theregister.com/2022/12/01/lastpass/
[13] https://www.theregister.com/2022/08/25/lastpass_security/
[14] https://www.theregister.com/2021/12/14/lastpass_spinout/
[15] https://github.com/bitwarden/server
[16] https://raspberrytips.com/install-bitwarden-on-raspberry-pi/
[17] https://whitepapers.theregister.com/
Re: +1 for Bitwarden
Yes, I migrated from LP to DashLane. After a while they changed their UI and it was really bad. Actually prevented me from logging in to a bank account! Now a happy Bitwarden user and I get the functionality for free that I had with the paid sub to DashLane.
The most popular authenticator apps, such as Google and Microsoft's, are tied at the hip to major companies.
I use Authy, which does the job nicely, cross-platform. https://authy.com (website under maintenance at time of posting).
The most popular authenticator apps, such as Google and Microsoft's, are tied at the hip to major companies.
I too prefer hardware tokens to TOTP authenticator apps, but these are standard implementations of TOTP. How are they tied at the hip to anything?
My first thought was "what does Top Of The Pops have to do with passwords?" Showing my age, I suppose...
One of the earliest passwords....?
JS4v1113
As far as I know TOTP apps create tokens based on details of the website. So they have a record of every website you have an account for and (again AFAIK) they're not encrypted.
Not correct. They use a pre-shared key (some 30-odd mix of letters and numbers) which is generated when you setup the 2FA - this key is combined with the current time to give you the 6-digit token.
There's an RFC for that, if you want the details.
There's a key shared, but every TOTP app I've used asks for an issuer to go along with it.
SafeInCloud
I’ve used SafeInCloud for years. I like the fact it uses a cloud storage provider of your choice to store the DB.
However, Bitwarden sounds like it’s worth a look.
For free, you also get a cloud-based store for all your passwords, Bitwarden Web Vault;
Why is this necessarily any more secure than LastPass, or any other password manager? At the end of the day, most of these breaches come down to human error and/or social engineering, and being open source doesn't magically exempt software from that sort of attack. Personally I have no particular desire to delegate my password security to a third party, whether they are stored "in the cloud" or not.
AFAIK Bitwarden stores all passwords in an encrypted binary blob which gets sent to the local device and is decrypted there, ie your master password (which can be as strong as you want/can remember) never leaves your device. And same for encrypting.
Having said that, I use BW for websites that are uncritical (like El Reg) but not for banking and the like... these things sit in a local KeePass database with a strong password and a keyfile.
While BitWarden is great, also consider the competition such as Passbolt.
A risk with BitWarden seems to be that it's another one-man-show type of project, at least last I checked, Kyle was the only developer.
There's a truly open source version of BitWarden's backend server called Vaultwarden: https://github.com/dani-garcia/vaultwarden It's a lot lighter too and doesn't require Microsoft SQL Server. BitWarden's Docker setup will install MS SQL in a container for you, but still...
The ties to Microsoft exist because BitWarden (the company) was initially supported by MS and I think one of the stipulations was that MS SQL and C# be used.
Former Lastpass subscriber and Bitwarden user here: I won't use the cloud directly for this sort of thing now. KeepassXC for me keeps things local, and whilst I do use Dropbox to share the vault across devices, the use of a manually-transferred key file makes sure that even if you got my vault and could crack my password, you still won't have access to the vault's contents. It's certainly less convenient, I suppose, but I learnt years ago that when it comes to security or convenience, pick one. :)
Another switcher - Lastpass had one job - and they blew it - and I didn't realise there's unencrypted and "hacker useful" data in there, even if they can't practically decrypt due to complex master passwords.
I've switched to Bitwarden as I need a "family friendly" solution - have had my kids on Lastpass for years and they do use it - so any switch need to be usable which means I steer clear of anything too hairshirt!
Hopefully Bitwarden won't make similar mistakes!
KeePass
I'll stick with KeePass, and syncing my database between my devices with Resilio Sync. I'll never feel happy putting my password db in the cloud, regardless whether the software used is open-source or not, so that's the best solution I can come up with.
Re: KeePass
Absolutely correct. The cloud is just "someone else's computer" and why would you put your sensitive data there?
Keep your sensitive data to yourself. It's that simple.
Re: KeePass
So I guess the banks and the government all keep your data on.... somewhere?
This old trope about "someone else's computer" is getting a bit old. You have got to trust someone with your data, and avoiding "The Cloud" is going to get harder and harder. Deal with it, and take appropriate measures to make sure you are not the low hanging fruit. Such as using unique and decent pass phrases, and U2F. And taking extra precautions with things that are extra sensitive (like where you keep your money).
Control your data
...run your own Bitwarden server.
This is the only way to ensure you are in control. It also means that you need to know what you are doing.
Unfortunately, most people have absolutely no clue what they are doing when it involves computers (or, for that matter, most technology). They are consumers and don't care how stuff works. It is not something that would come up in their minds. They are nothing more than consuming users.
As with all security and privacy issues, you need to know what you are doing and actively control everything you do. It is a continual process that needs to be adhered to for all time.
So is this an option for the majority of people? No.
Is it a solution for the knowledgeable? Maybe or not because they already know what to do and how to do it and may do their own thing anyway.
Don't rely on a single password
BitWarden has the same flaw as LastPass: it relies on a single password and anyone that has access to your vault is only a password away. Spoiler: you're a terrible password generator and you can't remember cryptographically strong passwords.
Instead, use a password manager that has a second factor. You can use 1Password which also has a secret that 1Password itself doesn't know. Or you can put a Keepass database on Google Drive and lock it with both a password and a key file, and not store the keyfile on Google Drive.
Both of the above ensure that if someone gets your encrypted database from the cloud, they'll have a very hard time cracking it.
Re: Don't rely on a single password
Maybe I misunderstand how Bitwarden works, but when I log in, it uses MFA, so it needs both my master password and a one time token.
Is that just for the Bitwarden site and not the underlying vault data?
Re: Don't rely on a single password
Unfortunately it's just for the initial login, unless you tell it to sign in and out (with associated MFA prompt) every time you view a password.
Trust
"Maybe you trust your brother. Me? I'm not so trusting." As usual, the question is not whether you trust your brother, but whether you trust everyone he trusts. And everyone they trust...
see the register article, redlinked in this post, log me in spun off LastPass – after this breach
Why not share via Bitwarden?
@author: Why?
>> You can also share passwords with this plan. Do not, I repeat, do not do this.
Why are you adamantly against sharing passwords via Bitwarden?
IMHO there are good reasons to do so (think: parents sharing password for their wifi router or mutual email account) in order to keep >2 individuals ready to work.
Or do you assume that even Bitwarden can't do this securely?
Re: Why not share via Bitwarden?
Completely agree - there are lots of password I want to share with a limited set of users. Like the password for the online newspaper subscription, passwords for various accounts at webshops that the whole family uses etc.
Re: Why not share via Bitwarden?
Why are you adamantly against sharing passwords
Because when a secret is known by more than one, it isn't a secret anymore.
Re: Why not share via Bitwarden?
Yes but some information must be both shared and still secured. If you can setup shared access with separate authentication mechanisms that is best but not always possible.
Financial institutions with badly designed web access and aging parents is one situation where this crops up for me.
Keepasses and Syncthing works well
I've used Keepass for years since a (now former) employer who handled stuff for a bunch of very security aware clients made us standardise on it. And taking a leaf out of their book, I don't put all passwords in the same file.
Example
Mobile file has everything you may need to access from a device while out and about. This is synchronized to all devices and desktop using Syncthing. No cloud involved, and any updates while away also get synchronized back home too.
Home file has everything else, lives solely on desktop (with backup) and never goes anywhere near a mobile device.
For the really paranoid you could use an Offline file on removable storage for really important passwords that you don't use frequently if you don't think your deskop is secure enough.
Most likely issue for me is mobile broken or gets lost / stolen, in which case if somebody gets into it they have a chance to crack Keepass and be rewarded with a bunch of low value passwords. I suspect you'd make much more money from selling the knowledge on how to crack Keepass than cashing in some almost-expired airline and hotel points...
Of course the strength of your master passwords / fingerprint reader is still a weakness. And if you're truly paranoid you'd not be using a fingerprint reader as your frontline security method would you?
...and not as paranoid as I am.
Don't believe me? Check your email address or phone number on HaveIbeenPwned...
Wanna be paranoid? Don't check online, don't send your password to anyone, including HIBP, you've just given your password away. Download from [1]here , or download a list of passes from (eg) a [2]latest file from HIBP and check locally.
[1] https://www.troyhunt.com/downloading-pwned-passwords-hashes-with-the-hibp-downloader/
[2] https://downloads.pwnedpasswords.com/passwords/pwned-passwords-sha1-ordered-by-count-v8.7z.torrent
Re: ...and not as paranoid as I am.
At least downloading files never resulted in any security breaches...
Someone else's computer
If you want your credentials to remain confidential, keep them to yourself. I have nothing against password manager tools (provided they have adequately secure access mechanisms themselves) but keep them local. Putting all your passwords on a remote server over which you have no control just does not make sense if you want to keep them secret. I know it's a convenient option, but does that outweigh losing the lot one day?
It's no more sensible than handing all the private and copyright content you generate to [1]some "cloud service" with a vested interest in it , but rather more dangerous.
[1] https://www.theregister.com/2023/01/07/adobe_ai_training/
Re: Someone else's computer
>Putting all your passwords on a remote server over which you have no control ..
I would think that putting all your passwords on a remote server over which you do have control is just as much a security risk. Unless you are a top security expert or believe security through obscurity helps.
Re: Someone else's computer
Unless you are prompted for a password each and every time you need to access your secrets... They really aren't any safer locally than in the cloud. https://www.upsightsecurity.com/post/data-protection-api-or-now-you-have-two-problems
Had bitwarden for years
..one day I will remember the master password and unlock it :(
+1 for Bitwarden
There was a thread on here many years ago that convinced me to get a premium subscription and I've never looked back. The UI is great, straight to point with no unnecessary bloat, particularly the iOS apps... a rare thing these days! The LastPass debacle is making me think I should switch to my own server too. Anyhow... +1 for Bitwarden