Английская Википедия:Bitwarden

Материал из Онлайн справочника
Перейти к навигацииПерейти к поиску

Шаблон:Advert Шаблон:Use dmy dates Шаблон:Short description Шаблон:Infobox software Bitwarden is a freemium open-source password management service that stores sensitive information, such as website credentials, in an encrypted vault. The platform offers a variety of client applications, including a web interface, desktop applications, browser extensions, mobile apps, and a command-line interface.[1] Bitwarden offers a free US or European cloud-hosted service as well as the ability to self-host.[2][3][4]

Desktop applications are available for Windows, MacOS, and Linux.[5] Browser extensions include Chrome, Firefox, Safari, Edge, Opera, Vivaldi, Arc, Brave and Tor.[5] Mobile apps for Android, iPhone, and iPad are available.[5]

Client functionalities include 2FA login, passwordless login, biometric unlock, passkey management, random password generator, password strength testing tool, login/form/app autofill, syncing across unlimited platforms and devices, storing unlimited number of items, sharing credentials, and storing a variety of information including credit cards.

Features

Шаблон:Prose

Overall security
Vault storage
Availability
Items
  • Items types such as logins, secure notes, credit cards, and identitiesШаблон:Emdashwhich free version can store in an unlimited number.[5][18]
  • Passkey registration/login from browser extension[19]
  • Items can be organized into folders[10]
  • Customizable fields for login/auto-fill[5][10][20]
  • 1GB encrypted file attachments and sharing for paid versions[5][10][21][17]
TOTP / Authenticator function
  • TOTP key storage for free version, plus code generator and automatic fill-in for paid customers[10][22]
Imports/Exports
Access
Sharing
  • Secure sharing of any texts (free version) including credentials, and files (paid versions) with others via "Send", i.e. sending a URL, via any means, that retrieves the sent information that can have expiration/deletion time, maximum access limit, and password[10][33]
  • Use an organization (such as family) and permission-based collections to securely share vault entries: 2 users + 2 collections for free and premium versions, and 6 users + unlimited collections for family plan.[10][17][34]
  • Designation of Bitwarden users as emergency contacts (for paid versions) that can request for account access in an emergency[10][35]
Tools
Others

Reception

In January 2021, in its first password-protection program comparison, U.S. News & World Report selected Bitwarden as "Best Password Manager".[49] In February, with competitor LastPass about to drop a feature in its free version, CNET recommended Bitwarden as the best free app for password synchronization across multiple devices,[50] while Lifehacker recommended it as "the best password manager for most people."[51]

Critics have praised the features offered in the software's free version, and the low price of the premium tier compared to other managers.[50][52][53][54] The product was named the best "budget pick" in a Wirecutter password manager comparison.[37] Bitwarden's secure open-source implementation was also praised by reviewers.[52][55]

However, the software was criticized for its lack of additional features,[52][56] and some reviewers noted its basic and less intuitive interface compared to other password managers.[53]

History

2016-2017

Bitwarden debuted in August 2016 with an initial release of mobile applications for iOS and Android, browser extensions for Chrome and Opera, and a web vault. The browser extension for Firefox was later launched in February 2017.[57] In February 2017, the Brave web browser began including the Bitwarden extension as an optional replacement password manager.[58]

In September 2017, Bitwarden launched a bug bounty program at HackerOne.[11][7]

2018

In January 2018, the Bitwarden browser extension was adapted to and released for Apple's Safari browser through the Safari Extensions Gallery.[59]

In February 2018, Bitwarden debuted as a stand-alone desktop application for macOS, Linux, and Windows. It was built as a web app variant of the browser extension and delivered on top of Electron.[60] The Windows app was released alongside the Bitwarden extension for Microsoft Edge in the Microsoft Store a month later.[61][62]

In March 2018, Bitwarden's web vault was criticized for embedding unconstrained third-party JavaScript from BootstrapCDN, Braintree, Google, and Stripe. These embedded scripts could pose as an attack vector to gain unauthorized access to Bitwarden users' passwords.[63] These third-party scripts were removed as part of the Bitwarden 2.0 Web Vault update, released in July 2018.[64]

In May 2018, Bitwarden released a command-line application enabling users to write scripted applications using data from their Bitwarden vaults.[1][65][66]

In June 2018, Cliqz performed a privacy and security review of the Bitwarden for Firefox browser extension and concluded that it would not negatively impact their users. Following the review, Bitwarden was made available as an optional password manager in the Cliqz web browser.[67]

In October 2018, Bitwarden completed a security assessment, code audit, and cryptographic analysis from third-party security auditing firm Cure53.[68][69][70][71]

2020

In July 2020, Bitwarden completed another security audit from security firm Insight Risk Consulting to evaluate the security of the Bitwarden network perimeter as well as penetration testing and vulnerability assessments against Bitwarden web services and applications.

In August 2020, Bitwarden achieved SOC 2 Type 2 and SOC 3 certification.[72][73]

In December 2020, Bitwarden announced that it was HIPAA compliant[74] in addition to already being GDPR, CCPA, and Privacy Shield[75] compliant.[76]

2021

In August 2021, Bitwarden announced that network assessment (security assessment and penetration testing) for 2021 had been completed by the firm Insight Risk Consulting.[10][77]

2022

In September 2022, the company announced $100M series B financing; the lead investor was PSG, with the existing investor, Battery Ventures, participating.[78][79] The investment would be used to accelerate product development and company growth to support its users and customers worldwide.[78][79]

2023

In January, Bitwarden announced the acquisition of Swedish startup Passwordless.dev for an undisclosed amount.[80] Passwordless.dev provided an open source solution allowing developers to easily implement passwordless authentication based on the standards WebAuthn and FIDO2.[80][81] Bitwarden also launched a beta software service allowing third-party developers the use of biometric sign-in technologies including Touch ID, Face ID and Windows Hello in their apps.[80]

In February, Bitwarden published network security assessment and security assessment reports that were conducted by Cure53 in May and October 2022 respectively.[82] The first related to penetration testing and security assessment across Bitwarden IPs, servers, and web applications.[83] The second related to penetration testing and source code audit against all Bitwarden password manager software components, including the core application, browser extension, desktop application, web application, and TypeScript library.[84] Ghacks reported that "No critical issues were discovered during the two audits. Two security issues that Cure53 rated high were discovered during the source code audit and penetration testing. These were fixed quickly by Bitwarden and the third-party HubSpot. All other issues were either rated low or informational only."[85]

See also

References

Шаблон:Reflist

External links

Шаблон:Password managers

  1. 1,0 1,1 1,2 Шаблон:Cite web
  2. Шаблон:Cite web
  3. 3,0 3,1 Шаблон:Cite web
  4. 4,0 4,1 Шаблон:Cite web
  5. 5,00 5,01 5,02 5,03 5,04 5,05 5,06 5,07 5,08 5,09 5,10 5,11 5,12 5,13 5,14 5,15 5,16 5,17 5,18 Шаблон:Cite web
  6. Шаблон:Cite web
  7. 7,0 7,1 7,2 Шаблон:Cite web
  8. 8,0 8,1 Шаблон:Cite web
  9. 9,0 9,1 Шаблон:Cite web
  10. 10,00 10,01 10,02 10,03 10,04 10,05 10,06 10,07 10,08 10,09 10,10 10,11 10,12 10,13 Шаблон:Cite web
  11. 11,0 11,1 Шаблон:Cite web
  12. Шаблон:Cite web
  13. Шаблон:Cite web
  14. Шаблон:Cite web
  15. Шаблон:Cite news
  16. Шаблон:Cite web
  17. 17,0 17,1 17,2 Шаблон:Cite web
  18. Шаблон:Cite web
  19. Шаблон:Cite web
  20. Шаблон:Cite web
  21. Шаблон:Cite web
  22. Шаблон:Cite web
  23. 23,0 23,1 Шаблон:Cite web
  24. Шаблон:Cite web
  25. Шаблон:Cite web
  26. Шаблон:Cite web
  27. Шаблон:Cite web
  28. Шаблон:Cite web
  29. Шаблон:Cite news
  30. Шаблон:Cite web
  31. Шаблон:Cite web
  32. Шаблон:Cite web
  33. Шаблон:Cite web
  34. Шаблон:Cite web
  35. Шаблон:Cite web
  36. Шаблон:Cite web
  37. 37,0 37,1 Шаблон:Cite news
  38. Шаблон:Cite web
  39. Шаблон:Cite web
  40. Шаблон:Cite news
  41. Шаблон:Cite web
  42. Шаблон:Cite web
  43. Шаблон:Cite web
  44. Шаблон:Cite news
  45. 45,0 45,1 Шаблон:Cite web
  46. Шаблон:Cite web
  47. Шаблон:Cite web
  48. Шаблон:Cite web
  49. Шаблон:Cite web
  50. 50,0 50,1 Шаблон:Cite web
  51. Шаблон:Cite web
  52. 52,0 52,1 52,2 Шаблон:Cite web
  53. 53,0 53,1 Шаблон:Cite news
  54. Шаблон:Cite web
  55. Шаблон:Cite web
  56. Шаблон:Cite web
  57. Шаблон:Cite web
  58. Шаблон:Cite web
  59. Шаблон:Cite news
  60. Шаблон:Cite web
  61. Шаблон:Cite web
  62. Шаблон:Cite web
  63. Шаблон:Cite web
  64. Шаблон:Cite web
  65. Шаблон:Cite web
  66. Шаблон:Cite web
  67. Шаблон:Cite web
  68. Шаблон:Cite news
  69. Шаблон:Cite web
  70. Шаблон:Cite web
  71. Шаблон:Cite web
  72. Шаблон:Cite web
  73. Шаблон:Cite web
  74. Шаблон:Cite web
  75. Шаблон:Cite web
  76. Шаблон:Cite web
  77. 78,0 78,1 Шаблон:Cite news
  78. 79,0 79,1 Шаблон:Cite web
  79. 80,0 80,1 80,2 Шаблон:Cite web
  80. Шаблон:Cite web
  81. Шаблон:Cite web
  82. Шаблон:Cite web
  83. Шаблон:Cite web
  84. Шаблон:Cite news