• Millions of people use password managers. They make accessing online services and bank accounts easy and simplify credit card payments.
  • Many providers promise absolute security – the data is said to be so encrypted that even the providers themselves cannot access it.
  • However, researchers from ETH Zurich have shown that it is possible for hackers to view and even change passwords.
you are viewing a single comment's thread
view the rest of the comments
[–] 9 points 6 months ago (3 children)

Is there a reason why these attacks were on cloud based pw managers?

  • source
  • parent
  • hideshow 6 child comments
  • [–] 16 points 6 months ago (1 child)

    From what I scanned, there was no reason given on why they only attacked cloud based providers.

    My guess is that these are paid ones and thus have a 'market share', easier to attack etc.

    If you attack a 'keepass' password the attack vector is more crypto / memory based as far as my limited knowledge goes and not some funky inbetween attack.

    Also, if you attack a cloud base provides, you will most likely have multiple victims per breach / exploit, whilst offline are targeted and thus not so interesting in most cases unless we're talking about a person of interest

  • source
  • parent
  • hideshow 2 child comments