Do you use Bitwarden, Lastpass, or Dashlane?

Researchers at ETH Zurich have discovered serious security vulnerabilities in three popular cloud-based password managers. In their tests, they were even able to see and change saved passwords.

Most password manager manufacturers advertise their products with the promise of “Zero-Knowledge Encryption.” In this way, they promise that stored passwords are encrypted and that the manufacturers themselves have no access to them.

See more articles from iGuRu.gr when you search for news on Google.

“The promise is that even if someone can access the server, this will not pose a risk to customer security because the data is encrypted and therefore unreadable,” says Matilda Backendal.

"We were able to prove that this is not true."

Backendal conducted the study together with Matteo Scarlata, Kenneth Paterson and Giovanni Torrisi from the Applied Cryptography Research Group at the Institute for Information Security at ETH Zurich. Backendal and Torrisi are currently working at the Università della Svizzera Italiana in Lugano.

The team took a closer look at the security architecture of three popular password manager providers: Bitwarden , Lastpass , and Dashlane.

The apps have around 60 million users worldwide and a 23% market share. The researchers carried out 12 attacks on Bitwarden, 7 on Lastpass and 6 on Dashlane. To do this, they set up their own servers, which behave in the same way as a hacked password manager server.

“We were surprised by how big the security vulnerabilities are,” Paterson said. When Matteo Scarlata, a doctoral student in the Applied Cryptography research group, began analyzing the code of the various managers, he encountered some very strange code architectures.

Companies try to offer their customers a user-friendly service, for example, the ability to recover passwords or share their own account with family members.

“This makes the code more complex, more confusing, and the attack sites for hackers to exploit increase,” Scarlata explains. Paterson’s team contacted the vendors of the affected systems before publishing the findings. They were given 90 days to patch the vulnerabilities.

“The providers were mostly cooperative and appreciative, but not all were so quick to resolve the security gaps,” says Paterson.

Password manager developers have been reluctant to update their apps for fear that their customers could lose access to their passwords or other personal data. In addition to millions of individuals, customers include thousands of companies that outsource their entire password management to these providers.

Imagine what would happen if they suddenly stopped having access to their data. That's why these companies have been using cryptographic technologies since the 1990s, even though they've been outdated for some time, Scarlata says.

The researchers made specific suggestions for application security.

Scarlata suggested updating the encryption of the systems for all new customers. Existing customers could choose for themselves whether they want to migrate to the new, more secure system and transfer their passwords there, or whether they remain on the old system – knowing the existing security vulnerabilities.

https://eprint.iacr.org/2026/058


Google preferences

Leave a Comment

Your email address will not be published. Required fields are marked *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).