Zero-knowledge claims tested: researchers reveal multiple flaws in top password managers

1 min read
Source: Ars Technica
Zero-knowledge claims tested: researchers reveal multiple flaws in top password managers
Photo: Ars Technica
TL;DR Summary

Researchers from ETH Zurich and USI Lugano analyzed Bitwarden, Dashlane, and LastPass and uncovered multiple attack vectors that can enable a compromised or malicious server to read or even modify vaults, especially when account-recovery, group enrollment, key escrow, or backward-compatibility features are enabled. Some attacks could allow theft of entire vaults or selective item data, and even breach older encryption configurations. While vendors defend their security audits and ongoing patching, the study argues that the term “zero-knowledge” can be misleading and urges stronger threat models and resilience measures across password managers.

Share this article

Reading Insights

Total Reads

0

Unique Readers

2

Time Saved

17 min

vs 17 min read

Condensed

97%

3,39291 words

Want the full story? Read the original article

Read on Ars Technica