Password Managers Expose Hidden Vulnerabilities in Latest Study
Password managers, long touted as a reliable solution for securely managing online credentials, are facing new vulnerabilities. A study by ETH Zurich and USI Lugano security researchers has revealed that even widely-used password managers like Bitwarden, Dashlane, and LastPass may not be as secure as previously thought. The study highlights potential flaws in their cryptographic systems, particularly in cloud-based services that sync data across devices. These flaws could allow malicious actors—whether insiders or hackers—to gain access to users’ password vaults, or even alter them. Although password managers often market ‘zero knowledge’ systems, claiming they can’t access user data, the researchers uncovered weaknesses in these systems that could undermine the security of users’ sensitive information. The vulnerabilities were found to be associated with key escrow systems, which allow password recovery, and could be exploited if certain features are enabled. While the flaws were found to vary between services, the study suggests that the problem may extend beyond the three managers examined. Users are advised to carefully evaluate the security of their password manager, as the threat of data breaches continues to grow.
