cross-posted from: https://infosec.pub/post/42164102

Researchers demo weaknesses affecting some of the most popular options Academics say they found a series of flaws affecting three popular password managers, all of which claim to protect user credentials in the event that their servers are compromised.…

  • floofloof@lemmy.caOP
    link
    fedilink
    English
    arrow-up
    67
    arrow-down
    1
    ·
    edit-2
    23 hours ago

    Well the specific point here is that these companies claim that a server hack won’t reveal your passwords since they’re encrypted and decrypted on your local device so the server only sees the encrypted version. Apparently this isn’t completely true.

    • Auli@lemmy.ca
      link
      fedilink
      English
      arrow-up
      2
      ·
      9 hours ago

      Well if you decrypt the blob on the server they can see it.

    • philpo@feddit.org
      link
      fedilink
      English
      arrow-up
      13
      ·
      14 hours ago

      At the point someone pulls off a valid MIM attack - which is basically a requirement here unless the whole BW/Vaultwarden server gets compromised- that is the least of someones problems. MIMs are incredibily hard these days.