Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
_karie_
71 days ago
|
parent
|
context
|
favorite
| on:
The quiet renovation at Bitwarden
Any malware or LLM with user-level filesystem access can attack the outdated KDF [1] and/or wait for Firefox to be running with an unlocked credential store and read the decrypted passwords from Firefox's process memory.
[1]
https://bugzilla.mozilla.org/show_bug.cgi?id=973759
jcattle
71 days ago
[–]
Isn't it game over anyway once you have an adversary on your system capable of reading process memory?
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search:
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=973759