← Back to list

Toughen Up Security Password Managers Are Told

Three of the leading password manager companies have been told to tough up their security after significant breach potentials were…

Kevin Tea · 2026-02-18 09:23 · 0 claps · 1.2 min read
#dashlane #bitwarden #lastpass #security-threat #password-manager
Open on Medium ↗

Toughen Up Security Password Managers Are Told

Three of the leading password manager companies have been told to tough up their security after significant breach potentials were identified. Security researchers from ETH Zurich studied the architecture of Bitwarden, LastPass, and Dashlane, which between them hold 23% of the password manager market.

Researchers demonstrated 12 attacks that would work on Bitwarden, seven on LastPass, and six on Dashlane, prompting calls for each to bolster defence capabilities. Scrutinising security capabilities, ETH created its own servers that would act as though they were hacked password manager servers. They found they could alter passwords, access vaults, and more.

Researchers urged password manager providers to use the most up-to-date cryptographic standards for all new customers, while existing customers could be offered the chance to migrate to updated systems or stick with older, compatible ones — providing they’re informed of the potential risks.

“We want our work to help bring about change in this industry,” ETH said. “The providers of password managers should not make false promises to their customers about security but instead communicate more clearly and precisely what security guarantees their solutions actually offer.”

This is another blow to LastPass which has a history of security breaches. The latest scare is that LastPass users are being subjected to phishing emails telling them to back up their system, something LastPass denies coming from them.

“Please remember that no one at LastPass will ever ask for your master password. Rest assured, we are working with our third-party partners to have this domain taken down as soon as possible,” said the firm.


메타데이터
post_id
ff8d4a1ce2ff
slug
toughen-up-security-password-managers-are-told-ff8d4a1ce2ff
url
https://medium.com/@kevinko_60193/toughen-up-security-password-managers-are-told-ff8d4a1ce2ff
canonical_url
https://medium.com/@kevinko_60193/toughen-up-security-password-managers-are-told-ff8d4a1ce2ff
author_url
https://medium.com/@kevinko_60193
status
ok
fetched_at
2026-06-26 21:52:29