• 114 Posts
  • 1.09K Comments
Joined 5 months ago
cake
Cake day: June 21st, 2024

help-circle















  • There is no way to be 100% sure, but:

    • bitwarden and ente have open source clients that ecrypt all data locally in a way that the provider can’t restore data
    • nextcloud isn’t optimal, while you can encypt data at rest, the provider might be able to spy on you
    • With mail providers it is difficult, but mailbox.org has my (personal) trust by building their business model on data protection and open source


  • The blog post contains an interesting tineline. Apparently, the first fix was not sufficient. So if you have updated Vaultwaren before November 18, update it again.

    Copy of the timeline:

    • End of October 2024: ERNW assesses Vaultwarden for the customer.
    • November 08, 2024: ERNW discloses the vulnerabilities to the Vaultwarden team.
    • November 10, 2024: Fix and release of Vaultwarden v1.32.4.
    • November 11, 2024: ERNW retests the software and identifies that the fix is not sufficient.
    • November 11, 2024: Public merge with fix and request for feedback by the Vaultwarden team.
    • November 12, 2024: ERNW acknowledges that the fix is complete.
    • November 18, 2024: Release of Vaultwarden v1.32.5.