Note how LastPass PR offloaded a ton of buzzwords here that donât actually mean anything. They turned this kind of responses into an art. https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/
Bitwarden at least admits that a fully compromised server isnât part of their threat model. Itâs the same for LastPass, and in the past theyâve rejected vulnerability submissions based on that â there are a number of very simple ways in which a compromised server is able to access your âsecureâ vault. But they wonât admit it, hoping instead that the message will drown in the noise they produce.
For the sake of completeness: Dashlaneâs response is merely generic. 1Passwordâs response is correct from what I can tell: the âcompromised serverâ scenario has been considered and the risks arising from it are documented, nothing new here.
#LastPass #infosec