Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. 🚨 New research from ETH Zurich has found that popular password manager's zero-knowledge encryption claims don't fully hold up if their servers are compromised.

🚨 New research from ETH Zurich has found that popular password manager's zero-knowledge encryption claims don't fully hold up if their servers are compromised.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
privacysecuritypasswordmanager
23 Indlæg 12 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • privacyguides@mastodon.neat.computerP This user is from outside of this forum
    privacyguides@mastodon.neat.computerP This user is from outside of this forum
    privacyguides@mastodon.neat.computer
    wrote sidst redigeret af
    #1

    🚨 New research from ETH Zurich has found that popular password manager's zero-knowledge encryption claims don't fully hold up if their servers are compromised. ⚠️

    🔑 LastPass, Dashlane & Bitwarden were identified as being affected, this is significant because cloud password managers commonly claim that their user's data would be unaffected if they were compromised. 👾

    #privacy #security #passwordmanager

    https://www.theregister.com/2026/02/16/password_managers/

    privacyguides@mastodon.neat.computerP D 2 Replies Last reply
    0
    • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

      ✅ Dashlane & Bitwarden promptly issued fixes.

      ❌ LastPass did not issue a fix and stated: "our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zürich team."

      💡In 2022, LastPass experienced a breach that impacted 1.6 million users due to inadequately strong technical and security measures within their infrastructure.

      The best time to switch from LastPass was yesterday; the second best is today. 🗑️

      Here's what we recommend ⬇️

      #lastpass #security

      privacyguides@mastodon.neat.computerP This user is from outside of this forum
      privacyguides@mastodon.neat.computerP This user is from outside of this forum
      privacyguides@mastodon.neat.computer
      wrote sidst redigeret af
      #2

      ☁️ Secure cloud password managers

      ➡️ For more info visit our site: https://www.privacyguides.org/en/passwords/#cloud-based

      #passwordmanager #security #privacyguides

      privacyguides@mastodon.neat.computerP 1 Reply Last reply
      0
      • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

        ☁️ Secure cloud password managers

        ➡️ For more info visit our site: https://www.privacyguides.org/en/passwords/#cloud-based

        #passwordmanager #security #privacyguides

        privacyguides@mastodon.neat.computerP This user is from outside of this forum
        privacyguides@mastodon.neat.computerP This user is from outside of this forum
        privacyguides@mastodon.neat.computer
        wrote sidst redigeret af
        #3

        📍 Secure local password managers

        ➡️ For more info visit our site: https://www.privacyguides.org/en/passwords/#local-storage

        #passwordmanager #security #privacyguides

        silhouette@dumbfuckingweb.siteS eist@hsnl.socialE 2 Replies Last reply
        0
        • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

          🚨 New research from ETH Zurich has found that popular password manager's zero-knowledge encryption claims don't fully hold up if their servers are compromised. ⚠️

          🔑 LastPass, Dashlane & Bitwarden were identified as being affected, this is significant because cloud password managers commonly claim that their user's data would be unaffected if they were compromised. 👾

          #privacy #security #passwordmanager

          https://www.theregister.com/2026/02/16/password_managers/

          privacyguides@mastodon.neat.computerP This user is from outside of this forum
          privacyguides@mastodon.neat.computerP This user is from outside of this forum
          privacyguides@mastodon.neat.computer
          wrote sidst redigeret af
          #4

          ✅ Dashlane & Bitwarden promptly issued fixes.

          ❌ LastPass did not issue a fix and stated: "our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zürich team."

          💡In 2022, LastPass experienced a breach that impacted 1.6 million users due to inadequately strong technical and security measures within their infrastructure.

          The best time to switch from LastPass was yesterday; the second best is today. 🗑️

          Here's what we recommend ⬇️

          #lastpass #security

          privacyguides@mastodon.neat.computerP dazo@infosec.exchangeD dalias@hachyderm.ioD P aerion@nerdculture.deA 5 Replies Last reply
          0
          • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

            ✅ Dashlane & Bitwarden promptly issued fixes.

            ❌ LastPass did not issue a fix and stated: "our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zürich team."

            💡In 2022, LastPass experienced a breach that impacted 1.6 million users due to inadequately strong technical and security measures within their infrastructure.

            The best time to switch from LastPass was yesterday; the second best is today. 🗑️

            Here's what we recommend ⬇️

            #lastpass #security

            dazo@infosec.exchangeD This user is from outside of this forum
            dazo@infosec.exchangeD This user is from outside of this forum
            dazo@infosec.exchange
            wrote sidst redigeret af
            #5

            @privacyguides A better name for LastPass is LostPass

            1 Reply Last reply
            0
            • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

              ✅ Dashlane & Bitwarden promptly issued fixes.

              ❌ LastPass did not issue a fix and stated: "our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zürich team."

              💡In 2022, LastPass experienced a breach that impacted 1.6 million users due to inadequately strong technical and security measures within their infrastructure.

              The best time to switch from LastPass was yesterday; the second best is today. 🗑️

              Here's what we recommend ⬇️

              #lastpass #security

              dalias@hachyderm.ioD This user is from outside of this forum
              dalias@hachyderm.ioD This user is from outside of this forum
              dalias@hachyderm.io
              wrote sidst redigeret af
              #6

              @privacyguides This sounds like the kind of thing that cannot just be "fixed". As far as I can tell, *all three were lying* about their servers being dumb storage without access to your secrets. This is a problem of vendor integrity not a technical problem.

              h0m3@mastodon.socialH 1 Reply Last reply
              0
              • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

                ✅ Dashlane & Bitwarden promptly issued fixes.

                ❌ LastPass did not issue a fix and stated: "our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zürich team."

                💡In 2022, LastPass experienced a breach that impacted 1.6 million users due to inadequately strong technical and security measures within their infrastructure.

                The best time to switch from LastPass was yesterday; the second best is today. 🗑️

                Here's what we recommend ⬇️

                #lastpass #security

                P This user is from outside of this forum
                P This user is from outside of this forum
                papaexmatrikulatus@mastodon.social
                wrote sidst redigeret af
                #7

                @privacyguides
                Do you have another source for Bitwarden havin fixed the issues? If i am not mistaking, i can't see where they say something explicit about Bitwarden fixing these issues in the linked article.

                timisch@mastodon.socialT 1 Reply Last reply
                0
                • dalias@hachyderm.ioD dalias@hachyderm.io

                  @privacyguides This sounds like the kind of thing that cannot just be "fixed". As far as I can tell, *all three were lying* about their servers being dumb storage without access to your secrets. This is a problem of vendor integrity not a technical problem.

                  h0m3@mastodon.socialH This user is from outside of this forum
                  h0m3@mastodon.socialH This user is from outside of this forum
                  h0m3@mastodon.social
                  wrote sidst redigeret af
                  #8

                  @dalias @privacyguides Self-host, some things are better of self hosted. And a password manager is one of them. And better without any internet access, your devices can sync when they are on your local network.

                  dalias@hachyderm.ioD 1 Reply Last reply
                  0
                  • h0m3@mastodon.socialH h0m3@mastodon.social

                    @dalias @privacyguides Self-host, some things are better of self hosted. And a password manager is one of them. And better without any internet access, your devices can sync when they are on your local network.

                    dalias@hachyderm.ioD This user is from outside of this forum
                    dalias@hachyderm.ioD This user is from outside of this forum
                    dalias@hachyderm.io
                    wrote sidst redigeret af
                    #9

                    @h0m3 @privacyguides It doesn't even need self-hosting. It just needs the storage backend to be a pure content-agnostic storage backend for opaque encrypted data, not having some control channel interaction that puts the vendor in a privileged position and locks you in to using their cloud infrastructure.

                    helloclippy@techhub.socialH 1 Reply Last reply
                    0
                    • dalias@hachyderm.ioD dalias@hachyderm.io

                      @h0m3 @privacyguides It doesn't even need self-hosting. It just needs the storage backend to be a pure content-agnostic storage backend for opaque encrypted data, not having some control channel interaction that puts the vendor in a privileged position and locks you in to using their cloud infrastructure.

                      helloclippy@techhub.socialH This user is from outside of this forum
                      helloclippy@techhub.socialH This user is from outside of this forum
                      helloclippy@techhub.social
                      wrote sidst redigeret af
                      #10

                      @dalias @h0m3 @privacyguides KeePass is the best option if you don't need cloud sync

                      dalias@hachyderm.ioD 1 Reply Last reply
                      0
                      • helloclippy@techhub.socialH helloclippy@techhub.social

                        @dalias @h0m3 @privacyguides KeePass is the best option if you don't need cloud sync

                        dalias@hachyderm.ioD This user is from outside of this forum
                        dalias@hachyderm.ioD This user is from outside of this forum
                        dalias@hachyderm.io
                        wrote sidst redigeret af
                        #11

                        @helloclippy @h0m3 @privacyguides Cloud sync is good, but only if it's *your choice* of storage and the storage provider doesn't have backdoor access to the password manager.

                        h0m3@mastodon.socialH 1 Reply Last reply
                        0
                        • dalias@hachyderm.ioD dalias@hachyderm.io

                          @helloclippy @h0m3 @privacyguides Cloud sync is good, but only if it's *your choice* of storage and the storage provider doesn't have backdoor access to the password manager.

                          h0m3@mastodon.socialH This user is from outside of this forum
                          h0m3@mastodon.socialH This user is from outside of this forum
                          h0m3@mastodon.social
                          wrote sidst redigeret af
                          #12

                          @dalias @helloclippy @privacyguides Yes. Bitwarden allows you to cloud sync to your instance, even using an alternative server application like vaultwarden. Thats the most important feature for me and i would abandon them if they choose to remove it in the future.

                          "Its open source but you can only connect to our proprietary servers" is a no-go to me

                          simonzerafa@infosec.exchangeS 1 Reply Last reply
                          0
                          • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

                            🚨 New research from ETH Zurich has found that popular password manager's zero-knowledge encryption claims don't fully hold up if their servers are compromised. ⚠️

                            🔑 LastPass, Dashlane & Bitwarden were identified as being affected, this is significant because cloud password managers commonly claim that their user's data would be unaffected if they were compromised. 👾

                            #privacy #security #passwordmanager

                            https://www.theregister.com/2026/02/16/password_managers/

                            D This user is from outside of this forum
                            D This user is from outside of this forum
                            drathir@mastodon.social
                            wrote sidst redigeret af
                            #13

                            @privacyguides same old story and yet ppl still not convinced to local only password managers like keepassxc...

                            1 Reply Last reply
                            0
                            • P papaexmatrikulatus@mastodon.social

                              @privacyguides
                              Do you have another source for Bitwarden havin fixed the issues? If i am not mistaking, i can't see where they say something explicit about Bitwarden fixing these issues in the linked article.

                              timisch@mastodon.socialT This user is from outside of this forum
                              timisch@mastodon.socialT This user is from outside of this forum
                              timisch@mastodon.social
                              wrote sidst redigeret af
                              #14

                              @Papaexmatrikulatus @privacyguides

                              https://bitwarden.com/blog/security-through-transparency-eth-zurich-audits-bitwarden-cryptography/

                              P 1 Reply Last reply
                              0
                              • timisch@mastodon.socialT timisch@mastodon.social

                                @Papaexmatrikulatus @privacyguides

                                https://bitwarden.com/blog/security-through-transparency-eth-zurich-audits-bitwarden-cryptography/

                                P This user is from outside of this forum
                                P This user is from outside of this forum
                                papaexmatrikulatus@mastodon.social
                                wrote sidst redigeret af
                                #15

                                @timisch @privacyguides Thank you!

                                1 Reply Last reply
                                0
                                • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

                                  ✅ Dashlane & Bitwarden promptly issued fixes.

                                  ❌ LastPass did not issue a fix and stated: "our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zürich team."

                                  💡In 2022, LastPass experienced a breach that impacted 1.6 million users due to inadequately strong technical and security measures within their infrastructure.

                                  The best time to switch from LastPass was yesterday; the second best is today. 🗑️

                                  Here's what we recommend ⬇️

                                  #lastpass #security

                                  aerion@nerdculture.deA This user is from outside of this forum
                                  aerion@nerdculture.deA This user is from outside of this forum
                                  aerion@nerdculture.de
                                  wrote sidst redigeret af
                                  #16

                                  @privacyguides
                                  Lastpass is an absolutely AWFUL company.

                                  After LogMeIn got their hands on them the prices skyrocketed from $12 to $24 to $36 to $48 a year for their premium plan.

                                  I switched to Bitwarden, who have kept their premium plan at just $10 a year, for many years now.

                                  With ownership of Lastpass now in the hands of not one, but two investment companies, one really has to question where Lastpass's priorities lie.

                                  1 Reply Last reply
                                  0
                                  • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

                                    📍 Secure local password managers

                                    ➡️ For more info visit our site: https://www.privacyguides.org/en/passwords/#local-storage

                                    #passwordmanager #security #privacyguides

                                    silhouette@dumbfuckingweb.siteS This user is from outside of this forum
                                    silhouette@dumbfuckingweb.siteS This user is from outside of this forum
                                    silhouette@dumbfuckingweb.site
                                    wrote sidst redigeret af
                                    #17

                                    @privacyguides keep assium

                                    1 Reply Last reply
                                    0
                                    • privacyguides@mastodon.neat.computerP privacyguides@mastodon.neat.computer

                                      📍 Secure local password managers

                                      ➡️ For more info visit our site: https://www.privacyguides.org/en/passwords/#local-storage

                                      #passwordmanager #security #privacyguides

                                      eist@hsnl.socialE This user is from outside of this forum
                                      eist@hsnl.socialE This user is from outside of this forum
                                      eist@hsnl.social
                                      wrote sidst redigeret af
                                      #18

                                      @privacyguides what do you recommend for self-hosting a password manager?

                                      privacyguides@mastodon.neat.computerP 1 Reply Last reply
                                      0
                                      • h0m3@mastodon.socialH h0m3@mastodon.social

                                        @dalias @helloclippy @privacyguides Yes. Bitwarden allows you to cloud sync to your instance, even using an alternative server application like vaultwarden. Thats the most important feature for me and i would abandon them if they choose to remove it in the future.

                                        "Its open source but you can only connect to our proprietary servers" is a no-go to me

                                        simonzerafa@infosec.exchangeS This user is from outside of this forum
                                        simonzerafa@infosec.exchangeS This user is from outside of this forum
                                        simonzerafa@infosec.exchange
                                        wrote sidst redigeret af
                                        #19

                                        @h0m3 @dalias @helloclippy @privacyguides

                                        Bitwarden has EU based servers which I would recommend.

                                        The cost for a year of service is very good value IMHO 🙂

                                        dalias@hachyderm.ioD 1 Reply Last reply
                                        0
                                        • simonzerafa@infosec.exchangeS simonzerafa@infosec.exchange

                                          @h0m3 @dalias @helloclippy @privacyguides

                                          Bitwarden has EU based servers which I would recommend.

                                          The cost for a year of service is very good value IMHO 🙂

                                          dalias@hachyderm.ioD This user is from outside of this forum
                                          dalias@hachyderm.ioD This user is from outside of this forum
                                          dalias@hachyderm.io
                                          wrote sidst redigeret af
                                          #20

                                          @simonzerafa @h0m3 @helloclippy @privacyguides Where the servers are located doesn't matter if the encryption is done right.

                                          simonzerafa@infosec.exchangeS 1 Reply Last reply
                                          0
                                          Svar
                                          • Svar som emne
                                          Login for at svare
                                          • Ældste til nyeste
                                          • Nyeste til ældste
                                          • Most Votes


                                          • Log ind

                                          • Har du ikke en konto? Tilmeld

                                          • Login or register to search.
                                          Powered by NodeBB Contributors
                                          Graciously hosted by data.coop
                                          • First post
                                            Last post
                                          0
                                          • Hjem
                                          • Seneste
                                          • Etiketter
                                          • Populære
                                          • Verden
                                          • Bruger
                                          • Grupper