Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. 🚨 If you use Bitwarden, please immediately read: https://socket.dev/blog/bitwarden-cli-compromised

🚨 If you use Bitwarden, please immediately read: https://socket.dev/blog/bitwarden-cli-compromised

Scheduled Pinned Locked Moved Uncategorized
7 Posts 4 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • thomasfuchs@hachyderm.ioT This user is from outside of this forum
    thomasfuchs@hachyderm.ioT This user is from outside of this forum
    thomasfuchs@hachyderm.io
    wrote last edited by
    #1

    🚨 If you use Bitwarden, please immediately read: https://socket.dev/blog/bitwarden-cli-compromised

    odaeus@social.vivaldi.netO nflamel@hachyderm.ioN 2 Replies Last reply
    2
    0
    • thomasfuchs@hachyderm.ioT thomasfuchs@hachyderm.io

      🚨 If you use Bitwarden, please immediately read: https://socket.dev/blog/bitwarden-cli-compromised

      odaeus@social.vivaldi.netO This user is from outside of this forum
      odaeus@social.vivaldi.netO This user is from outside of this forum
      odaeus@social.vivaldi.net
      wrote last edited by
      #2

      @thomasfuchs I feel adding "CLI" is a pretty important distinction here so as not to cause undue stress to BW users (of which I am one, including the CLI!). We don't know if they've been further compromised... yet.

      shansterable@ohai.socialS 1 Reply Last reply
      0
      • odaeus@social.vivaldi.netO odaeus@social.vivaldi.net

        @thomasfuchs I feel adding "CLI" is a pretty important distinction here so as not to cause undue stress to BW users (of which I am one, including the CLI!). We don't know if they've been further compromised... yet.

        shansterable@ohai.socialS This user is from outside of this forum
        shansterable@ohai.socialS This user is from outside of this forum
        shansterable@ohai.social
        wrote last edited by
        #3

        @Odaeus @thomasfuchs
        I agree. I am scouring the article to find out whether passwords have been compromised. Couldn't they just lead with that?

        I had to look up what a "CLI" is. Even after finding the definition, it only made things more confusing.

        By the way, CLI = Command Line Interface, in case that helps anyone besides me.

        I try to do for initialisms and acronyms what alt text does for images.

        odaeus@social.vivaldi.netO 1 Reply Last reply
        0
        • thomasfuchs@hachyderm.ioT thomasfuchs@hachyderm.io

          🚨 If you use Bitwarden, please immediately read: https://socket.dev/blog/bitwarden-cli-compromised

          nflamel@hachyderm.ioN This user is from outside of this forum
          nflamel@hachyderm.ioN This user is from outside of this forum
          nflamel@hachyderm.io
          wrote last edited by
          #4

          @thomasfuchs I'm grateful that the version in Arch is apparently a couple of releases behind... but that was pretty scary for a moment.

          1 Reply Last reply
          0
          • shansterable@ohai.socialS shansterable@ohai.social

            @Odaeus @thomasfuchs
            I agree. I am scouring the article to find out whether passwords have been compromised. Couldn't they just lead with that?

            I had to look up what a "CLI" is. Even after finding the definition, it only made things more confusing.

            By the way, CLI = Command Line Interface, in case that helps anyone besides me.

            I try to do for initialisms and acronyms what alt text does for images.

            odaeus@social.vivaldi.netO This user is from outside of this forum
            odaeus@social.vivaldi.netO This user is from outside of this forum
            odaeus@social.vivaldi.net
            wrote last edited by
            #5

            @shansterable @thomasfuchs in this case, "Bitwarden CLI" is the name of the product from Bitwarden that was compromised. The message should be that if you don't know what it means you don't need to worry! Relatively few BW users use it.

            Even for those few people who have been compromised by using the infection version, current indications are that their vault was not specifically leaked because of the way the virus works. However, if they are a programmer (likely, given the specialist nature) then they now have a serious issue as it leaks sensitive data that it finds.

            Techies are concerned about this because it is a big red flag around BWs processes and could indicate they have also been compromised internally by their own tool. They say they've found no evidence of this though: https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127

            shansterable@ohai.socialS 1 Reply Last reply
            0
            • odaeus@social.vivaldi.netO odaeus@social.vivaldi.net

              @shansterable @thomasfuchs in this case, "Bitwarden CLI" is the name of the product from Bitwarden that was compromised. The message should be that if you don't know what it means you don't need to worry! Relatively few BW users use it.

              Even for those few people who have been compromised by using the infection version, current indications are that their vault was not specifically leaked because of the way the virus works. However, if they are a programmer (likely, given the specialist nature) then they now have a serious issue as it leaks sensitive data that it finds.

              Techies are concerned about this because it is a big red flag around BWs processes and could indicate they have also been compromised internally by their own tool. They say they've found no evidence of this though: https://community.bitwarden.com/t/bitwarden-statement-on-checkmarx-supply-chain-incident/96127

              shansterable@ohai.socialS This user is from outside of this forum
              shansterable@ohai.socialS This user is from outside of this forum
              shansterable@ohai.social
              wrote last edited by
              #6

              @Odaeus
              Thank you. My husband uses Bitwarden and I was worried.

              Especially since it took me years to convince him to use a password vault because he doesn't trust them.

              odaeus@social.vivaldi.netO 1 Reply Last reply
              0
              • shansterable@ohai.socialS shansterable@ohai.social

                @Odaeus
                Thank you. My husband uses Bitwarden and I was worried.

                Especially since it took me years to convince him to use a password vault because he doesn't trust them.

                odaeus@social.vivaldi.netO This user is from outside of this forum
                odaeus@social.vivaldi.netO This user is from outside of this forum
                odaeus@social.vivaldi.net
                wrote last edited by
                #7

                @shansterable you're welcome, I'm still working on getting mine to use it!

                1 Reply Last reply
                0
                • R relay@relay.mycrowd.ca shared this topic
                  System shared this topic
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups