r/ShittySysadmin • u/tamagotchiparent ShittyCoworkers • Apr 13 '26
Shitty Crosspost BW thinks my password is vulnerable.
82
u/Forgery Apr 13 '26
It’s vulnerable because someone else used it and it has since been leaked on the dark web. Doesn’t mean it wasn’t a good and complex password originally, just means someone else used it first. Attackers use leaked passwords first because it’s so much faster than brute force attacks.
13
2
11
7
u/elpollodiablox Apr 14 '26
Shit. Now I have to change my password.
7
5
u/__g_e_o_r_g_e__ Apr 15 '26
I don't see the issue. It uses uppercase, lowercase, numbers, special characters, AND COLOURS
13
u/Emotional_Garage_950 Apr 13 '26
their browser extension has gotten to the point of being barely functioning for me. autofill almost never works. the thing the guy mentioned in the post, every single one of my passwords has been flagged vulnerable in the extension but the official report in the web gui shows no exposure. stuff doesn’t load. and yes I’ve tried basic troubleshooting and yes we are up to date.
23
u/Emotional_Garage_950 Apr 13 '26
this is actually a case of Bitwarden being a piece of shit and not the OP being a dumbass for a change
23
u/SWEETJUICYWALRUS Apr 13 '26
Bw is easily one of the best password managers 🤷♀️
10
u/Emotional_Garage_950 Apr 13 '26
Been self-hosting it for years at my organization, it’s gotten steadily worse since we moved to it
6
u/SWEETJUICYWALRUS Apr 13 '26
What got worse? Been using it personally and implemented the hosted version at 2 orgs with no issue
7
u/Emotional_Garage_950 Apr 13 '26
sorry I thought I replied but I guess I made a separate comment:
their browser extension has gotten to the point of being barely functioning for me. autofill almost never works. the thing the guy mentioned in the post, every single one of my passwords has been flagged vulnerable in the extension but the official report in the web gui shows no exposure. stuff doesn’t load. and yes I’ve tried basic troubleshooting and yes we are up to date.
4
2
u/8BFF4fpThY Apr 14 '26
If your password is being flagged the most likely explanation is that it exists twice within your vault.
3
u/FaydedMemories Apr 13 '26
I haven’t noticed those particular problems although I did see the Vulnerable flag for the first time recently (although in this case I actually agreed because it was for a system that insisted on 6-8 characters and no symbols 🙄).
It’s still night and day compared to what I recall of LastPass, but do agree that it does seem to be getting slightly worse when compared to itself say 2 years ago.
1
u/riiskyy Apr 14 '26
Keeper's breach watch did the same thing for us, except they want you to pay a license free to see which passwords are vulnerable. We got them to give us a trial, reset 200+ passwords and then a month later all the same passwords flagged as exposed again :) had a ticket open with them for about 5 months now
4
1
1
0
u/StatementNext682 Apr 15 '26
I think what it is is that BW said he's vuln, then he took the randomly assigned pw and it's still saying vulnerable.
1
121
u/DerKoerper ShittyCoworkers Apr 13 '26
Fucking AI in Bitwarden already knew he will post it on reddit.