Settings

Theme

Hunting for Bitwarden master passwords stored in memory

redmaple.tech

27 points by markuta 2 years ago · 2 comments

Reader

donmcronald 2 years ago

I wonder if there's any difference if you use the option to sign in with Windows Hello using a TPM. What about logout vs lock?

tentacleuno 2 years ago

I'm guessing they've built the desktop client in JavaScript. One disadvantage of the language (and all similar ones!) is that the GC isn't deterministic. Without access to Node's gc() API, it's very hard to ensure the credentials are wiped from memory after locking.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection