Researchers uncover 27 attack scenarios targeting cloud password managers

1 min read
Source: Infosecurity Magazine
Researchers uncover 27 attack scenarios targeting cloud password managers
Photo: Infosecurity Magazine
TL;DR Summary

Swiss researchers disclosed 27 attack scenarios across Bitwarden, LastPass, Dashlane and 1Password that could let attackers view or modify vaults, challenging the science of end-to-end encryption and exploiting issues in onboarding, key escrow, and item-level encryption. A notable attack demonstrated is ‘malicious auto-enrolment’ against Bitwarden, which could allow a server-controlled attacker to hijack a vault during organization onboarding. Vendors are patching (Bitwarden, LastPass, Dashlane) while 1Password defends its SRP-based design. The paper recommends stronger authentication, key separation and ciphertext integrity. Users should check remediation status with providers and ask for audits.)

Share this article

Reading Insights

Total Reads

1

Unique Readers

3

Time Saved

6 min

vs 7 min read

Condensed

93%

1,23691 words

Want the full story? Read the original article

Read on Infosecurity Magazine