• Millions of people use password managers. They make accessing online services and bank accounts easy and simplify credit card payments.
  • Many providers promise absolute security – the data is said to be so encrypted that even the providers themselves cannot access it.
  • However, researchers from ETH Zurich have shown that it is possible for hackers to view and even change passwords.
you are viewing a single comment's thread
view the rest of the comments
[–] 44 points 6 months ago (4 children)

For people interested there were 3 cloud based password managers tested and this is what they found

The researchers demonstrated 12 attacks on Bitwarden, 7 on LastPass and 6 on Dashlane.

  • source
  • hideshow 8 child comments
  • [–] 9 points 6 months ago (3 children)

    Is there a reason why these attacks were on cloud based pw managers?

  • source
  • parent
  • hideshow 6 child comments
  • [–] 16 points 6 months ago (1 child)

    From what I scanned, there was no reason given on why they only attacked cloud based providers.

    My guess is that these are paid ones and thus have a 'market share', easier to attack etc.

    If you attack a 'keepass' password the attack vector is more crypto / memory based as far as my limited knowledge goes and not some funky inbetween attack.

    Also, if you attack a cloud base provides, you will most likely have multiple victims per breach / exploit, whilst offline are targeted and thus not so interesting in most cases unless we're talking about a person of interest

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 6 months ago* (last edited 6 months ago)

    What I am wondering myself: Do the different amount of attacks mean the attack surface was greater or had more vulnerabilities or what made them only do 6 on Dashlane vs 12 on Bitwarden?

    Edit:
    In another article it was total identified vulnerabilities.

  • source
  • parent