I skimmed through the article because I wanted to see if 1Password was mentioned but didn’t see it. It was about LastPass, Bitwarden, and Dashlane.
I would’ve also liked to hear about password managers that do keep their promise, and if that includes 1Pass (which I believe it does).
TheKingOfTCGames on
Bitwarden? You mean the thing that was made specifically to have a backdoor the feds can use?
Because too many Iranians were using OSS disk encryption???
That bit warden??
conscami on
The researchers did show that there are vulnerabilities, but we should see how the companies actually respond and how fast they fix the issues.
jcstrat on
I’m shocked! Well not that shocked really.
darkhorsehance on
The headline is a little sensational. The attacks assume a malicious server, not just stolen vaults. That doesn’t make password managers broken, just means that “zero knowledge” marketing oversells what’s actually guaranteed once recovery, sharing and/or enterprise features are enabled.
kaishinoske1 on
Funny how all the people in r/cybersecurity were defending password managers when I would mention it’s just a giant vulnerability. I guess they can look forward to getting their shit rocked. Because no doubt they have their work passwords saved on any those number of password managers. They might as well start putting their things in a cardboard box at work.
Leave A Reply
Du musst angemeldet sein, um einen Kommentar abzugeben.
7 Kommentare
[deleted]
I skimmed through the article because I wanted to see if 1Password was mentioned but didn’t see it. It was about LastPass, Bitwarden, and Dashlane.
I would’ve also liked to hear about password managers that do keep their promise, and if that includes 1Pass (which I believe it does).
Bitwarden? You mean the thing that was made specifically to have a backdoor the feds can use?
Because too many Iranians were using OSS disk encryption???
That bit warden??
The researchers did show that there are vulnerabilities, but we should see how the companies actually respond and how fast they fix the issues.
I’m shocked! Well not that shocked really.
The headline is a little sensational. The attacks assume a malicious server, not just stolen vaults. That doesn’t make password managers broken, just means that “zero knowledge” marketing oversells what’s actually guaranteed once recovery, sharing and/or enterprise features are enabled.
Funny how all the people in r/cybersecurity were defending password managers when I would mention it’s just a giant vulnerability. I guess they can look forward to getting their shit rocked. Because no doubt they have their work passwords saved on any those number of password managers. They might as well start putting their things in a cardboard box at work.