Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. 🚨 New research from ETH Zurich has found that popular password manager's zero-knowledge encryption claims don't fully hold up if their servers are compromised.

🚨 New research from ETH Zurich has found that popular password manager's zero-knowledge encryption claims don't fully hold up if their servers are compromised.

Scheduled Pinned Locked Moved Uncategorized
privacysecuritypasswordmanager
23 Posts 12 Posters 38 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • privacyguides@mastodon.neat.computerP This user is from outside of this forum
    privacyguides@mastodon.neat.computerP This user is from outside of this forum
    privacyguides@mastodon.neat.computer
    wrote last edited by
    #1

    🚨 New research from ETH Zurich has found that popular password manager's zero-knowledge encryption claims don't fully hold up if their servers are compromised. ⚠️

    πŸ”‘ LastPass, Dashlane & Bitwarden were identified as being affected, this is significant because cloud password managers commonly claim that their user's data would be unaffected if they were compromised. πŸ‘Ύ

    #privacy #security #passwordmanager

    Link Preview Image
    Password managers don’t protect secrets if pwned

    : Researchers demo weaknesses affecting some of the most popular options

    favicon

    (www.theregister.com)

    privacyguides@mastodon.neat.computerP D 2 Replies Last reply
    1
    0
    • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

      ☁️ Secure cloud password managers

      ➑️ For more info visit our site: https://www.privacyguides.org/en/passwords/#cloud-based

      #passwordmanager #security #privacyguides

      Link Preview Image
      privacyguides@mastodon.neat.computerP This user is from outside of this forum
      privacyguides@mastodon.neat.computerP This user is from outside of this forum
      privacyguides@mastodon.neat.computer
      wrote last edited by
      #2

      πŸ“ Secure local password managers

      ➑️ For more info visit our site: https://www.privacyguides.org/en/passwords/#local-storage

      #passwordmanager #security #privacyguides

      silhouette@dumbfuckingweb.siteS eist@hsnl.socialE 2 Replies Last reply
      1
      0
      • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

        βœ… Dashlane & Bitwarden promptly issued fixes.

        ❌ LastPass did not issue a fix and stated: "our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zürich team."

        πŸ’‘In 2022, LastPass experienced a breach that impacted 1.6 million users due to inadequately strong technical and security measures within their infrastructure.

        The best time to switch from LastPass was yesterday; the second best is today. πŸ—‘οΈ

        Here's what we recommend ⬇️

        #lastpass #security

        privacyguides@mastodon.neat.computerP This user is from outside of this forum
        privacyguides@mastodon.neat.computerP This user is from outside of this forum
        privacyguides@mastodon.neat.computer
        wrote last edited by
        #3

        ☁️ Secure cloud password managers

        ➑️ For more info visit our site: https://www.privacyguides.org/en/passwords/#cloud-based

        #passwordmanager #security #privacyguides

        Link Preview Image
        privacyguides@mastodon.neat.computerP 1 Reply Last reply
        0
        • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

          🚨 New research from ETH Zurich has found that popular password manager's zero-knowledge encryption claims don't fully hold up if their servers are compromised. ⚠️

          πŸ”‘ LastPass, Dashlane & Bitwarden were identified as being affected, this is significant because cloud password managers commonly claim that their user's data would be unaffected if they were compromised. πŸ‘Ύ

          #privacy #security #passwordmanager

          Link Preview Image
          Password managers don’t protect secrets if pwned

          : Researchers demo weaknesses affecting some of the most popular options

          favicon

          (www.theregister.com)

          privacyguides@mastodon.neat.computerP This user is from outside of this forum
          privacyguides@mastodon.neat.computerP This user is from outside of this forum
          privacyguides@mastodon.neat.computer
          wrote last edited by
          #4

          βœ… Dashlane & Bitwarden promptly issued fixes.

          ❌ LastPass did not issue a fix and stated: "our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zürich team."

          πŸ’‘In 2022, LastPass experienced a breach that impacted 1.6 million users due to inadequately strong technical and security measures within their infrastructure.

          The best time to switch from LastPass was yesterday; the second best is today. πŸ—‘οΈ

          Here's what we recommend ⬇️

          #lastpass #security

          privacyguides@mastodon.neat.computerP dazo@infosec.exchangeD dalias@hachyderm.ioD P aerion@nerdculture.deA 5 Replies Last reply
          0
          • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

            βœ… Dashlane & Bitwarden promptly issued fixes.

            ❌ LastPass did not issue a fix and stated: "our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zürich team."

            πŸ’‘In 2022, LastPass experienced a breach that impacted 1.6 million users due to inadequately strong technical and security measures within their infrastructure.

            The best time to switch from LastPass was yesterday; the second best is today. πŸ—‘οΈ

            Here's what we recommend ⬇️

            #lastpass #security

            dazo@infosec.exchangeD This user is from outside of this forum
            dazo@infosec.exchangeD This user is from outside of this forum
            dazo@infosec.exchange
            wrote last edited by
            #5

            @privacyguides A better name for LastPass is LostPass

            1 Reply Last reply
            0
            • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

              βœ… Dashlane & Bitwarden promptly issued fixes.

              ❌ LastPass did not issue a fix and stated: "our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zürich team."

              πŸ’‘In 2022, LastPass experienced a breach that impacted 1.6 million users due to inadequately strong technical and security measures within their infrastructure.

              The best time to switch from LastPass was yesterday; the second best is today. πŸ—‘οΈ

              Here's what we recommend ⬇️

              #lastpass #security

              dalias@hachyderm.ioD This user is from outside of this forum
              dalias@hachyderm.ioD This user is from outside of this forum
              dalias@hachyderm.io
              wrote last edited by
              #6

              @privacyguides This sounds like the kind of thing that cannot just be "fixed". As far as I can tell, *all three were lying* about their servers being dumb storage without access to your secrets. This is a problem of vendor integrity not a technical problem.

              h0m3@mastodon.socialH 1 Reply Last reply
              0
              • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

                βœ… Dashlane & Bitwarden promptly issued fixes.

                ❌ LastPass did not issue a fix and stated: "our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zürich team."

                πŸ’‘In 2022, LastPass experienced a breach that impacted 1.6 million users due to inadequately strong technical and security measures within their infrastructure.

                The best time to switch from LastPass was yesterday; the second best is today. πŸ—‘οΈ

                Here's what we recommend ⬇️

                #lastpass #security

                P This user is from outside of this forum
                P This user is from outside of this forum
                papaexmatrikulatus@mastodon.social
                wrote last edited by
                #7

                @privacyguides
                Do you have another source for Bitwarden havin fixed the issues? If i am not mistaking, i can't see where they say something explicit about Bitwarden fixing these issues in the linked article.

                timisch@mastodon.socialT 1 Reply Last reply
                0
                • dalias@hachyderm.ioD dalias@hachyderm.io

                  @privacyguides This sounds like the kind of thing that cannot just be "fixed". As far as I can tell, *all three were lying* about their servers being dumb storage without access to your secrets. This is a problem of vendor integrity not a technical problem.

                  h0m3@mastodon.socialH This user is from outside of this forum
                  h0m3@mastodon.socialH This user is from outside of this forum
                  h0m3@mastodon.social
                  wrote last edited by
                  #8

                  @dalias @privacyguides Self-host, some things are better of self hosted. And a password manager is one of them. And better without any internet access, your devices can sync when they are on your local network.

                  dalias@hachyderm.ioD 1 Reply Last reply
                  0
                  • h0m3@mastodon.socialH h0m3@mastodon.social

                    @dalias @privacyguides Self-host, some things are better of self hosted. And a password manager is one of them. And better without any internet access, your devices can sync when they are on your local network.

                    dalias@hachyderm.ioD This user is from outside of this forum
                    dalias@hachyderm.ioD This user is from outside of this forum
                    dalias@hachyderm.io
                    wrote last edited by
                    #9

                    @h0m3 @privacyguides It doesn't even need self-hosting. It just needs the storage backend to be a pure content-agnostic storage backend for opaque encrypted data, not having some control channel interaction that puts the vendor in a privileged position and locks you in to using their cloud infrastructure.

                    helloclippy@techhub.socialH 1 Reply Last reply
                    0
                    • dalias@hachyderm.ioD dalias@hachyderm.io

                      @h0m3 @privacyguides It doesn't even need self-hosting. It just needs the storage backend to be a pure content-agnostic storage backend for opaque encrypted data, not having some control channel interaction that puts the vendor in a privileged position and locks you in to using their cloud infrastructure.

                      helloclippy@techhub.socialH This user is from outside of this forum
                      helloclippy@techhub.socialH This user is from outside of this forum
                      helloclippy@techhub.social
                      wrote last edited by
                      #10

                      @dalias @h0m3 @privacyguides KeePass is the best option if you don't need cloud sync

                      dalias@hachyderm.ioD 1 Reply Last reply
                      0
                      • helloclippy@techhub.socialH helloclippy@techhub.social

                        @dalias @h0m3 @privacyguides KeePass is the best option if you don't need cloud sync

                        dalias@hachyderm.ioD This user is from outside of this forum
                        dalias@hachyderm.ioD This user is from outside of this forum
                        dalias@hachyderm.io
                        wrote last edited by
                        #11

                        @helloclippy @h0m3 @privacyguides Cloud sync is good, but only if it's *your choice* of storage and the storage provider doesn't have backdoor access to the password manager.

                        h0m3@mastodon.socialH 1 Reply Last reply
                        0
                        • dalias@hachyderm.ioD dalias@hachyderm.io

                          @helloclippy @h0m3 @privacyguides Cloud sync is good, but only if it's *your choice* of storage and the storage provider doesn't have backdoor access to the password manager.

                          h0m3@mastodon.socialH This user is from outside of this forum
                          h0m3@mastodon.socialH This user is from outside of this forum
                          h0m3@mastodon.social
                          wrote last edited by
                          #12

                          @dalias @helloclippy @privacyguides Yes. Bitwarden allows you to cloud sync to your instance, even using an alternative server application like vaultwarden. Thats the most important feature for me and i would abandon them if they choose to remove it in the future.

                          "Its open source but you can only connect to our proprietary servers" is a no-go to me

                          simonzerafa@infosec.exchangeS 1 Reply Last reply
                          0
                          • em0nm4stodon@infosec.exchangeE em0nm4stodon@infosec.exchange shared this topic
                          • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

                            🚨 New research from ETH Zurich has found that popular password manager's zero-knowledge encryption claims don't fully hold up if their servers are compromised. ⚠️

                            πŸ”‘ LastPass, Dashlane & Bitwarden were identified as being affected, this is significant because cloud password managers commonly claim that their user's data would be unaffected if they were compromised. πŸ‘Ύ

                            #privacy #security #passwordmanager

                            Link Preview Image
                            Password managers don’t protect secrets if pwned

                            : Researchers demo weaknesses affecting some of the most popular options

                            favicon

                            (www.theregister.com)

                            D This user is from outside of this forum
                            D This user is from outside of this forum
                            drathir@mastodon.social
                            wrote last edited by
                            #13

                            @privacyguides same old story and yet ppl still not convinced to local only password managers like keepassxc...

                            1 Reply Last reply
                            0
                            • P papaexmatrikulatus@mastodon.social

                              @privacyguides
                              Do you have another source for Bitwarden havin fixed the issues? If i am not mistaking, i can't see where they say something explicit about Bitwarden fixing these issues in the linked article.

                              timisch@mastodon.socialT This user is from outside of this forum
                              timisch@mastodon.socialT This user is from outside of this forum
                              timisch@mastodon.social
                              wrote last edited by
                              #14

                              @Papaexmatrikulatus @privacyguides

                              Link Preview Image
                              Security through transparency: ETH Zurich audits Bitwarden cryptography against malicious server scenarios | Bitwarden

                              A new in-depth security report is available, continuing the Bitwarden commitment to transparency and trusted open source security. The audit, conducted by the prestigious Applied Cryptography Group at ETH Zurich, proactively tested Bitwarden core cryptography operations against the hypothetical event of a maliciously compromised server. All issues identified in the report have been addressed by the Bitwarden team and have been included in the attached cryptography report for full transparency.

                              favicon

                              Bitwarden (bitwarden.com)

                              P 1 Reply Last reply
                              0
                              • timisch@mastodon.socialT timisch@mastodon.social

                                @Papaexmatrikulatus @privacyguides

                                Link Preview Image
                                Security through transparency: ETH Zurich audits Bitwarden cryptography against malicious server scenarios | Bitwarden

                                A new in-depth security report is available, continuing the Bitwarden commitment to transparency and trusted open source security. The audit, conducted by the prestigious Applied Cryptography Group at ETH Zurich, proactively tested Bitwarden core cryptography operations against the hypothetical event of a maliciously compromised server. All issues identified in the report have been addressed by the Bitwarden team and have been included in the attached cryptography report for full transparency.

                                favicon

                                Bitwarden (bitwarden.com)

                                P This user is from outside of this forum
                                P This user is from outside of this forum
                                papaexmatrikulatus@mastodon.social
                                wrote last edited by
                                #15

                                @timisch @privacyguides Thank you!

                                1 Reply Last reply
                                0
                                • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

                                  βœ… Dashlane & Bitwarden promptly issued fixes.

                                  ❌ LastPass did not issue a fix and stated: "our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zürich team."

                                  πŸ’‘In 2022, LastPass experienced a breach that impacted 1.6 million users due to inadequately strong technical and security measures within their infrastructure.

                                  The best time to switch from LastPass was yesterday; the second best is today. πŸ—‘οΈ

                                  Here's what we recommend ⬇️

                                  #lastpass #security

                                  aerion@nerdculture.deA This user is from outside of this forum
                                  aerion@nerdculture.deA This user is from outside of this forum
                                  aerion@nerdculture.de
                                  wrote last edited by
                                  #16

                                  @privacyguides
                                  Lastpass is an absolutely AWFUL company.

                                  After LogMeIn got their hands on them the prices skyrocketed from $12 to $24 to $36 to $48 a year for their premium plan.

                                  I switched to Bitwarden, who have kept their premium plan at just $10 a year, for many years now.

                                  With ownership of Lastpass now in the hands of not one, but two investment companies, one really has to question where Lastpass's priorities lie.

                                  1 Reply Last reply
                                  0
                                  • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

                                    πŸ“ Secure local password managers

                                    ➑️ For more info visit our site: https://www.privacyguides.org/en/passwords/#local-storage

                                    #passwordmanager #security #privacyguides

                                    silhouette@dumbfuckingweb.siteS This user is from outside of this forum
                                    silhouette@dumbfuckingweb.siteS This user is from outside of this forum
                                    silhouette@dumbfuckingweb.site
                                    wrote last edited by
                                    #17

                                    @privacyguides keep assium

                                    1 Reply Last reply
                                    0
                                    • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

                                      πŸ“ Secure local password managers

                                      ➑️ For more info visit our site: https://www.privacyguides.org/en/passwords/#local-storage

                                      #passwordmanager #security #privacyguides

                                      eist@hsnl.socialE This user is from outside of this forum
                                      eist@hsnl.socialE This user is from outside of this forum
                                      eist@hsnl.social
                                      wrote last edited by
                                      #18

                                      @privacyguides what do you recommend for self-hosting a password manager?

                                      privacyguides@mastodon.neat.computerP 1 Reply Last reply
                                      0
                                      • h0m3@mastodon.socialH h0m3@mastodon.social

                                        @dalias @helloclippy @privacyguides Yes. Bitwarden allows you to cloud sync to your instance, even using an alternative server application like vaultwarden. Thats the most important feature for me and i would abandon them if they choose to remove it in the future.

                                        "Its open source but you can only connect to our proprietary servers" is a no-go to me

                                        simonzerafa@infosec.exchangeS This user is from outside of this forum
                                        simonzerafa@infosec.exchangeS This user is from outside of this forum
                                        simonzerafa@infosec.exchange
                                        wrote last edited by
                                        #19

                                        @h0m3 @dalias @helloclippy @privacyguides

                                        Bitwarden has EU based servers which I would recommend.

                                        The cost for a year of service is very good value IMHO πŸ™‚

                                        dalias@hachyderm.ioD 1 Reply Last reply
                                        0
                                        • simonzerafa@infosec.exchangeS simonzerafa@infosec.exchange

                                          @h0m3 @dalias @helloclippy @privacyguides

                                          Bitwarden has EU based servers which I would recommend.

                                          The cost for a year of service is very good value IMHO πŸ™‚

                                          dalias@hachyderm.ioD This user is from outside of this forum
                                          dalias@hachyderm.ioD This user is from outside of this forum
                                          dalias@hachyderm.io
                                          wrote last edited by
                                          #20

                                          @simonzerafa @h0m3 @helloclippy @privacyguides Where the servers are located doesn't matter if the encryption is done right.

                                          simonzerafa@infosec.exchangeS 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups