Bitwarden v1.1.0
What's Changed
- Fix insecure use of SecureString when using ConvertTo-SecureString with plaintext by @kevinstsauveur in #7
- Deleted default value for mandatory parameter by @kevinstsauveur in #11
- Fix exposition of SecureString's sensitive information when sending password in parameters by @kevinstsauveur in #13
- Fix code style and security issues by @kevinstsauveur in #14
- Remove vault from code by @kevinstsauveur in #16
Full Changelog: v1.0.0...v1.1.0
Extra notes
There's no need to follow additional installation instructions or download extra software. The script is ready to backup!
Embedded software:
- Bitwarden cli - Version 1.22.0
- KeePass - 2.50
- KPScript - 2.50
- SDelete - 2.04
KeePass
Encryption
The provided KeyPass Vault uses the following encryption parameter:
- Database file encryption algorithm: ChaCha20 (256-bit key, RFC 7539)
Key transformation
The provided KeePass Vault may not use the perfect Key transformation parameters that fits your needs. The provided one is created with these following parameters:
- Key derivation function: Argon2d
- Iterations: 10
- Memory: 512 MB
- Parallelism: 4
It generally takes ~1s to open/save KeePass.
There's more details the way these parameters impact the security on KeePass's website in the Protection against Dictionary Attacks section.
Integrity & Authenticity validation
💾 SHA-256 checksums of release artifacts for checking the integrity of your download:
69389e63abf126a0213ccf51bb7cb26b1c765cc38d57d81ea2b0c72172d6e426 ./BitwardenBackup_v1.1.0.zip
afc53f184d33b7709fd7830bf1610d59fe4f8ecdfacec0caaa8b0ff9510a8a0b ./BitwardenBackup_v1.1.0.zip.asc
3808fb7ee3015eb18eab6c73dd29a86b707707f811ffe226e78d0827aa22b5db ./BitwardenBackup_v1.1.0.exe
d1e0ef85facc3a7c1e8e33a50396b10796e7eda06ceacb465e8535d7de172b1b ./BitwardenBackup_v1.1.0.exe.asc
fbf74e9e43cbe43bb5a3d15b4448c0c32b669415e9c1721d8959aa63f6cb5c2b ./sha256sum.txt
5267ba3c197feb2302893746397ede9db47396fa2f857642e353772ee27e7b88 ./sha256sum.txt.asc
🔑 PGP Public key: Use it for the verification of GPG Signature
5C6C14A1508F520D8D74AC7772277F7529880D6D