🚨 New research from ETH Zurich has found that popular password manager's zero-knowledge encryption claims don't fully hold up if their servers are compromised. ⚠️

πŸ”‘ LastPass, Dashlane & Bitwarden were identified as being affected, this is significant because cloud password managers commonly claim that their user's data would be unaffected if they were compromised. πŸ‘Ύ

#privacy #security #passwordmanager

https://www.theregister.com/2026/02/16/password_managers/

You probably can't trust your password manager if it's compromised

: Researchers demo weaknesses affecting some of the most popular options

The Register

βœ… Dashlane & Bitwarden promptly issued fixes.

❌ LastPass did not issue a fix and stated: "our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zürich team."

πŸ’‘In 2022, LastPass experienced a breach that impacted 1.6 million users due to inadequately strong technical and security measures within their infrastructure.

The best time to switch from LastPass was yesterday; the second best is today. πŸ—‘οΈ

Here's what we recommend ⬇️

#lastpass #security

@privacyguides
Do you have another source for Bitwarden havin fixed the issues? If i am not mistaking, i can't see where they say something explicit about Bitwarden fixing these issues in the linked article.
Security through transparency: ETH Zurich audits Bitwarden cryptography against malicious server scenarios | Bitwarden

A new in-depth security report is available, continuing the Bitwarden commitment to transparency and trusted open source security. The audit, conducted by the prestigious Applied Cryptography Group at ETH Zurich, proactively tested Bitwarden core cryptography operations against the hypothetical event of a maliciously compromised server. All issues identified in the report have been addressed by the Bitwarden team and have been included in the attached cryptography report for full transparency.

Bitwarden