this post was submitted on 18 Feb 2026
17 points (87.0% liked)

Privacy

4077 readers
154 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 2 years ago
MODERATORS
 

Researchers demo weaknesses affecting some of the most popular options Academics say they found a series of flaws affecting three popular password managers, all of which claim to protect user credentials in the event that their servers are compromised.…

you are viewing a single comment's thread
view the rest of the comments
[–] nous@programming.dev 4 points 1 week ago (3 children)

The companies responses are probably more important then the findings.

Dashlane published a comprehensive response, thanking the researchers, and said the infoseccers' decision to test using a malicious server model represented "a useful exercise."

The vendor also confirmed it had fixed the most serious issue

Which is what you want to hear. The worst of the issues has been fixed and they look like they want to improve things further.

Bitwarden, meanwhile, said in a post: "Bitwarden has never been breached and believes third-party security assessments like these are critical to continue providing state of the art security to individuals and organizations."

Is less encouraging although not damning. Would be nicer to hear they are hardening things in case of a breach rather than just relying on not being breached. They could still be doing that though.

A LastPass spokesperson told The Reg: "Our Security team is grateful for the opportunity to engage with ETH Zurich and benefit from their research. While our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zurich team, we take all reported security findings seriously. We have already implemented multiple near‑term hardening measures while also establishing plans to remediate or reinforce the relevant components of our service on a timeline commensurate with the assessed risk."

Is just terrible. Basically they don't think they have a problem and have done nothing more then a token effort to fix the easiest of things. I believe they have been breached before as well which is also a bad sign. They just don't seem to care about security at all. I would continue to recommend no one use last pass and everyone one switch away from it.

[–] Onomatopoeia@lemmy.cafe 5 points 1 week ago (1 children)

Well, Lastpass has been shit for years, I don't know why they exist anymore.

[–] lka1988@lemmy.dbzer0.com 2 points 1 week ago

Especially when KeePass and its many forks already exist.

[–] lka1988@lemmy.dbzer0.com 4 points 1 week ago

"We have already implemented multiple near‑term hardening measures while also establishing plans to remediate or reinforce the relevant components of our service on a timeline commensurate with the assessed risk."

Translation: "the board already knew last quarter but they wanted their bonuses first"

[–] Jakeroxs@sh.itjust.works 1 points 1 week ago

In the other article the researchers mentioned BW already fixed most of the issues and has plans for the others in future releases 🤷