Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's good to see companies making reports public to provide some confidence that they're having reviews done, but in this case the scoping of this job seems a little odd, not sure if that's a bad reporting template or something else.

Last page of the PDF indicates that they just did an external VA and pentest, but looking at their product set , I'd have expected (at least) a review of the web, desktop and mobile apps and the browser plugins for it to be a "thorough security assessment and penetration test" (as quoted in the blog).

Not to say external reviews have no value, but they're only part of what's needed.



The only PDF linked in the blogpost is "Bitwarden Network Security Assessment Report", and it does indeed only cover network related topics. Their earlier report from 2018 covers lots of web/desktop application assessments: https://cdn.bitwarden.com/misc/Bitwarden%20Security%20Assess...

So I wonder if they just forgot to mention that this second audit report doesn't cover that, or if there are more reports coming.


They did a code audit in 2018, and this is a network/pentest audit. They're two different things, that's all, and both are valuable.


Heh. You’re proposing around... well, ${a lot of money} worth of work.

When I was a pentester, I once ran the numbers and concluded that each pen test must have cost some absurd amount of money for us to be profitable. And they do, because it’s effective. But I wanted to point out a likely possibility: they wanted to do what you were saying, and concluded a million dollars spent on a pentest was beyond reach.

a review of the web, desktop and mobile apps and the browser plugins

If a million dollars sounds like an overestimate, you’re right to be skeptical. But $270k seems entirely reasonable; that’s $30k per app, for 9 apps.

So it might be tempting to feel like “it’s just a browser plugin though. How can the cost be anywhere comparable?”

Because pentests are billed in days, and a day on a plugin is a day on an app.


Yeah I'm fairly well aware how pentests are billed (I've been in testing for ~15 years as a buyer, seller and tester :) )

My point was, that there was a gap between how the blog appeared to be billing the test "thorough security assessment and penetration test" and the report's statements around scope.

Obviously companies can't always afford all the testing that they need to get as much coverage as they could, but when your major selling product is a downloadable application, a comprehensive review would usually at least touch on it as part of the work performed, for it to be called thorough.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: