Does login password travel over LAN in clear text? #5724
Unanswered
optimist555
asked this question in
Q&A
Replies: 1 comment
-
The password is never sent over the connection between the client and the server. If you'd like to understand the Bitwarden security model, spend a few minutes reading their whitepaper. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
If vaultwarden is hosted on one instance, and in another instance is a reverse proxy. Both reside on the same LAN subnet. The reverse proxy serves vaultwarden over HTTPS, and the traffic on LAN is plain HTTP. Would it be possible for an attacker that have compromised a computer that reside on LAN to retrieve the login passwords or the data if analyzing the network traffic? Is the traffic encrypted between the Bitwarden clients/VW web UI and the vaultwarden server even though TLS terminates at the reverse proxy?
Beta Was this translation helpful? Give feedback.
All reactions