The Bitwarden security team identified and contained a malicious package that was briefly distributed through the npm delivery path for @bitwarden/cli@2026.4.0 between 5:57 PM and 7:30 PM (ET) on April 22, 2026, in connection with a broader Checkmarx supply chain incident. Was I affected? If you use the Bitwarden command line interface and deploy using NPM, and downloaded the CLI between 5:57p ET and 7:30p ET on April 22, 2026, you may be affected. See remediation steps below. If you do not u...
If your assumption is that X509 is trash, does that mean you hold the same amount of distrust to TLS?
How do you propose the scaling of key management? Do you have a reasonable alternative to users blindly trusting every single key they come across?
Back to my original question: what prevents a VSCode extension from stealing a private signing key (as opposed to an API key) and causing the same issues described here?
TLS is fine with certificate pinning m
That still leaves two out of three questions unanswered. Most importantly the last one, which was addressed towards the original complaint.