As detailed in The Hacker News, a recent study has revealed that several popular cloud-based password managers, including Bitwarden, Dashlane, and LastPass, are susceptible to password recovery attacks under specific circumstances. These vulnerabilities could allow attackers to compromise user vaults.Researchers from ETH Zurich and Università della Svizzera italiana identified 12 attacks against Bitwarden, seven against LastPass, and six against Dashlane, targeting the zero-knowledge encryption (ZKE) promises of these services. The attacks, which assume a malicious server, range from integrity violations to complete organizational vault compromise, with the majority enabling password recovery. Vulnerabilities were found in key escrow mechanisms, item-level encryption with flawed metadata handling, sharing features, and backward compatibility with legacy code. 1Password was also found vulnerable to similar, though already known, issues.While the vendors have begun implementing countermeasures, this research highlights potential weaknesses in common password manager designs and cryptographic misconceptions. Although no exploitation in the wild has been reported, the study prompts a re-evaluation of the security assurances provided by password management solutions serving over 60 million users and nearly 125,000 businesses globally.Source: The Hacker News
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds





