可以看看这个
https://bitwarden.com/help/security-faqs/#q-what-happens-if-bitwarden-gets-hacked这里面链接了
https://bitwarden.com/help/what-encryption-is-used/ 中提到:
“Bitwarden always encrypts and/or hashes your data on your local device before anything is sent to cloud servers for storage. Bitwarden servers are only used for storing encrypted data.”
大概意思是服务器(包括数据库)不存储你的明文密码和解密密钥,只存储加密后的数据。
“Vault data can only be decrypted using the key derived from your master password. Bitwarden is a zero knowledge encryption solution, meaning you are the only party with access to your key and the ability to decrypt your vault data.”
大概意思是解密的关键就是你的主密码,只要主密码不泄漏,数据就是安全的。
所以可以说即便你用公开仓库存放 data (当然最好也别这么做),密码也不会泄漏。
浏览器插件是不是安全同样可以在 security-faqs 里找到:
https://bitwarden.com/help/security-faqs/#q-how-does-bitwarden-secure-browser-extensions“Extensions are safe to use if they are developed correctly. Due to the nature of how browser extensions work there is always a chance for a bug to arise. We take extreme care and caution when we are developing our extensions and add-ons, we keep our eyes and ears out for anything going on in the industry, and we conduct security audits to keep many eyes on everything.”
大概意思是说在没有 bug 或漏洞的情况下,理论上是安全的,这个实现机制不会有安全方面的硬伤,加上他们的实时舆情监控以及快速响应处置,应该可以让 bitwarden 的插件持续可靠。
这类专业的密码管理(浏览器内置的不算)大多只把解密的数据存在内存里,进程结束或会话过期数据就会被清除,所以一般低级的攻击不会造成密码泄露。
但安全都是相对的,假如你的系统已经被攻成筛子了,完全被攻击者监控起来和随意访问内存数据了,密码该泄露还是会泄露。一切安全都是建立在你在可信的环境下,使用可信的操作系统、可信的浏览器的基础上的。