Research Reveals Vulnerabilities in Bitwarden, LastPass, and Dashlane Password Managers
- Securityish
- Privacy & Personal Security
Quick Summary
The Securityish Brief
Academics from ETH Zurich and Università della Svizzera italiana examined the security of three widely used password managers: Bitwarden, LastPass, and Dashlane. They found that all three platforms could potentially expose user passwords if their servers were compromised, undermining the promise of zero-knowledge encryption. This research highlights a critical gap in the security of password managers, which are often considered safe.
The researchers identified 12 successful attacks against Bitwarden, 7 against LastPass, and 6 against Dashlane. These attacks were not based on exploiting weaknesses but rather on testing the platforms’ abilities to protect user secrets in the event of a server compromise. For instance, 7 of the 12 attacks on Bitwarden led to password disclosure, while only 3 of LastPass’s attacks had the same outcome.
None of the vendors clearly outline the specific threats their password managers protect against, which raises questions about the transparency of their security claims. The researchers noted that many of the successful attacks required routine user interactions, such as logging in or synchronizing data, suggesting that users may unknowingly expose themselves to risks.
Professor Kenneth Paterson from ETH Zurich expressed surprise at the severity of the vulnerabilities found. He emphasized the need for password manager providers to communicate more clearly about the security guarantees their products offer. The researchers recommend that vendors ensure new users are onboarded with the latest cryptographic standards to enhance security.
Dashlane responded positively to the findings, stating they had fixed a significant issue related to the disclosure of passwords. Bitwarden also acknowledged the importance of third-party security assessments, while LastPass indicated they are taking steps to address the identified risks.
The researchers believe that similar vulnerabilities may exist in other password managers, potentially exposing a broader range of users to risks. This situation underscores the importance of ongoing scrutiny and improvement in the security of password management solutions.
- Bitwarden: Found to be the most susceptible with 12 successful attacks against its security.
- LastPass: Experienced 7 distinct attacks that could lead to password disclosure.
- Dashlane: Had 6 successful attacks, with one issue already addressed by the vendor.
Key Takeaways
- Evaluate your current password manager’s security features and claims regarding zero-knowledge encryption.
- Consider switching to a password manager that uses the latest cryptographic standards for enhanced security.
- Regularly update your password manager to ensure you have the latest security patches and features.
- Be cautious of routine actions like logging in or synchronizing data, as these may expose you to risks.
- Stay informed about security vulnerabilities in password managers and adjust your usage accordingly.
Key Terms & Concepts
- Zero-Knowledge Encryption: In this article, zero-knowledge encryption refers to a method where user passwords are encrypted on their device, ensuring that even if the server is compromised, attackers cannot access the credentials.
- Password Manager: A password manager is a tool that helps users store and manage their passwords securely, often using encryption to protect sensitive information.
- Cryptographic Standards: Cryptographic standards are guidelines that dictate how encryption should be implemented to ensure data security and integrity.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.