6 ms·
Password managers less secure than promised
- mjamil 7mo agoHas there been a similar evaluation of 1Password?
- rorylawless 7mo ago1Password wrote a response to the paper: https://1password.com/blog/eth-zurich-zero-knowledge-malicious-server-review https://1password.com/blog/eth-zurich-zero-knowledge-malicio...
- herczegzsolt 7mo agoI am bit disappointed they did not immediately jump on implementing the two straightforward recommendations: > PROPOSED MITIGATION. A straightforward mitigation is to have the client sign vault keys using the RSA private key in the keyset before encrypting them with the RSA public key. > PROPOSED MITIGATION. [...] it would be easy for 1Password to prevent it entirely: the secret key can be used (with proper key derivation) to authenticate the KDF parameters with a cryptographic MAC. To be fair, these issues are not really impacting long-time users. I have hundreds if not thousands of items in my vaults, there's no way i'm not noticing if they dissappear (which would be a side effect of these attacks). Overall, I think 1password can be proud of their architecture and product quality, but i'd love to see these improvements - and maybe something like a "signal verification code" for sharing?
- tempay 7mo agoIt seems like 1Password is significantly more secure given the ratio of its market share to the number of articles I’ve seen like this one.
- kenniskrag 7mo ago> Much like the other products we analyse, 1Password lacks authentication of public keys. This trivially enables sharing attacks similar to BW09, LP07 and DL02, something that the 1Password whitepaper... > IMPACT. Complete compromise of vault confidentiality and integrity. The adversary can read and decrypt all vault con- tents encrypted after the attack, including passwords, credit card information, secure notes, and other sensitive data stored in the vault. Similarly, they can inject new items into the vault after the attack. REQUIREMENTS. The client fetches key material from the server, for example due to the user logging in on a new device. If executed on a non-empty vault, the attack results in the client losing access to all items already in their vault, while leaking any new items added to the vault after the attack took place. If the attack is executed at the time of vault creation, the attack is effectively undetectable by the client, since it cannot distinguish between a ciphertext it created and the ciphertext created by the server during the attack. PROPOSED MITIGATION. A straightforward mitigation is to have the client sign vault keys using the RSA private key in the keyset before encrypting them with the RSA public key. Ideally, two different key pairs would be used for... from the paper: https://eprint.iacr.org/2026/058.pdf https://eprint.iacr.org/2026/058.pdf
- deleted 7mo ago[deleted]
- deleted 7mo ago[deleted]
- loeg 7mo agoSee https://zkae.io/ https://zkae.io/
- baal80spam 7mo agoThat's why KeePass is still the king. Offline vault > online vault.
- spacebuffer 7mo agoWhat to do if my house catches on fire, including my computer where the passwords are stored?
- judofyr 7mo agoIt’s just an encrypted file on disk. You’d depend on whatever backup solution you already have in place.
- deleted 7mo ago[deleted]
- wps 7mo agoWell, the same issue exists for your BitWarden recovery keys or 2fa method. You need to have proper and redundant off site backups for anything valuable.
- fullstop 7mo agoNot exactly. I need to have those offsite, but they are not modified at the same frequency as passwords.
- Telaneo 7mo agoHow often do your change your passwords? Assuming they are decently long and all that, why would you change them at all other than when a site gets breached? The only reason my Keepass database changes is because I make new accounts on sites every now and then, and that's a fairly rare thing these days. And if I get so ungodly unlucky that my house burns down before my off-site database is updated to have that new account listed, I'll still have access to the email that account is associated with, so I can still recover the account either way.
- jmclnx 7mo ago>cloud-based password managers The main issue with these managers. I use an encrypted text file and Emacs, nothing on the cloud for me.
- setopt 7mo agoThat doesn’t fit all use cases though. For example, how to fill passwords in mobile apps on the go, or how to share a subset of your passwords with your family (including syncing password changes with them).
- Biganon 7mo ago"Why do people need this tool? I use a much more rudimentary solution that doesn't do half the things a password manager does"
- Sytten 7mo agoWe will see when the attacks are public, a lot of the malicious server attacks we have seen in the past were kinda of overblown. Not discounting OP but it is very easy to get into clickbait territory.
- doubled112 7mo agoI’m not sure why anybody is surprised. Eventually, everything is proven to be less secure than promised, especially once they are online. There are certain types of data I prefer to have complete control over. Passwords, no matter how encrypted they claim to be, are top of the list.
- mberger 7mo agoSave you the click. The researchers demonstrated 12 attacks on Bitwarden, 7 on LastPass and 6 on Dashlane
- bstsb 7mo agoa better summary from the site: > We examine the extent to which security against a fully malicious server holds true for three leading vendors who make the Zero Knowledge Encryption claim: Bitwarden, LastPass and Dashlane [...] The attacks range in severity, from integrity violations of targeted user vaults to the complete compromise of all the vaults associated with an organisation.
- bstsb 7mo agocaveat not properly addressed in the blog post: all "attacks" are assuming full takeover of web servers, which is certainly a scenario that should be protected against, but isn't really a vulnerability unless chained with something else. almost all online services would be "vulnerable" in this way - take almost any login system. an RCE on a system hosting a login page would obviously be vulnerable to account takeover better link here (the technical details): https://zkae.io/ https://zkae.io/
- kenniskrag 7mo agoNot if the advertise zero knowledge encryption. As far as I understand the password sharing / collaboration feature is often the problem. Second: The provider can get the passwords with a simple server change.
- Someone1234 7mo agoI use Bitwarden, and I like them, but I still disagree. One of the things Bitwarden's design is MEANT to offer is "zero knowledge" meaning that it is an AES-256 encrypted database "blob", with PBKDF2 derived master password. So "compromised" server absolutely IS something the DESIGN should protect against. If compromising Bitwarden's servers lets them extract what they say they can extract, then the whole "zero knowledge" assurance is dead in the water. Plus, Bitwarden themselves don't even need to be compromised, we could have a DNS redirect into a server the bad-guys (inc. national-state) control. Then leverage that into complete compromise of your database.
- fullstop 7mo agoDoes't TLS pinning alleviate the DNS attack?
- tptacek 7mo agoNo, the whole point of these systems is that you can trust them even if their servers are compromised. If you exclude that possibility from your threat model, you might as well not bother encrypting at all; just send your passwords to the server in an HTTPS POST.
- drnick1 7mo ago> cloud-based password managers. Enough said. This kind of stuff should be offline only. If you need to access your password database on multiple devices, set up a LAN and/or a Wireguard tunnel for remote access.
- adamm255 7mo agoHard agree, but Average Joes have no idea what any of those words mean let alone the means to do it.
- Someone1234 7mo agoAt least a KeePass file via Cloud Storage seems like a somewhat sane tradeoff between security and convenience. What you're proposing where you're adding a backdoor to your home network (via Wireguard) that needs to be maintained/hardened, and then still needing a LAN hosting solution for the actual database running 24-hour, is neither convenient nor secure (least of all because of layer 1 / fire / theft). This is a fragile solution which isn't solving any particular problem; but certainly introducing multiple new exciting potential problems.
- drnick1 7mo ago> What you're proposing where you're adding a backdoor to your home network (via Wireguard) that needs to be maintained/hardened I have been doing this for years, and it is both convenient and secure. No maintenance or hardening is required, as Wireguard was intentionally designed not to require any tinkering. The setup is literally one config file with the public keys of the devices allowed to access the network. I run this directly on my firewall, which happens to be an x86 PC, but you could run easily run this on a router with OpenWrt. It's hard to imagine a more secure setup than this, since you manage your own keys and no third party is involved.
- frm88 7mo agoYou can use your KeePass off of a mobile device like a thumb drive. I have my USB stick attached to my keys (house, bike etc.) which allows me to access my passwords from everywhere. Cloud based is always a risk.
- lofaszvanitt 7mo agoWhat a sane idea to store all your secrets in one place.... for attackers to get ahold of them in one move.
- wps 7mo agoWhy does the federal reserve keep all that gold in one place? It’s far better to have a ridiculously secure store than it is to have to reuse passwords across a hundred sites (nobody here can remember a hundred unique high entropy passwords). I trust the cryptography far more than my brain to handle these things.
- lofaszvanitt 7mo agoYour argument is flawed. And you know it. For a starter, one gold bar there is around 12.5 kgs.
- wps 7mo agoIt doesn’t perfectly map, but it gets a visual point across. I cannot be convinced that it’s better for the average person to maintain a couple permutations of a primary password for a hundred different sites than it is for them to store it in a vetted and audited password manager. Even with the vulnerabilities mentioned in the paper you are far better off with a password manager and thus 100 fully unique passwords then without.
- lofaszvanitt 7mo agoYeah, but if you use the shack once per year, then why put the shack key amongst the ones you frequently use?
- burnt-resistor 7mo agoEducate us how then many unique secrets "should" be managed.
- 7mo ago
- 63 7mo agoThe article is nearly useless for users of the software who want to know how their data may have been affected. The researchers' website is more descriptive, especilly wrt specific findings. https://zkae.io/ https://zkae.io/
- loeg 7mo ago1Password comes out looking relatively good here.
- fullstop 7mo agoBitwarden's response [1] is interesting. "All issues have been addressed by Bitwarden. Seven of which have been resolved or are in active remediation by the Bitwarden team. The remaining three issues have been accepted as intentional design decisions necessary for product functionality." They don't expand on what those three are. 1. https://bitwarden.com/blog/security-through-transparency-eth-zurich-audits-bitwarden-cryptography/ https://bitwarden.com/blog/security-through-transparency-eth...
- hleszek 7mo agoyou can see them in the report at the bottom, but I counted four. See my post above.
- OutOfHere 7mo agoNo matter how compromised a server gets, ideally the client should never be able to provide it unencrypted data, or data is encrypted in a way such that the server can decrypt it. It is unclear if Bitwarden has fixed this core issue or not.
- tptacek 7mo agoFor clarity, one of the "Accepted" vulnerabilities is that attackers who control the Bitwarden servers can set the PBKDF iteration count to "1". They set the severity of this to "low". They've also "accepted" a vulnerability --- BW01 from the paper, I believe --- that allows a malicious server to read all vault items from a user as soon as they accept any invitation (real or not) to an "organization".
- cromka 7mo agoSomeone on Reddit says they reported some of those Bitwarden issues to them 4 years ago and they were ignored: https://www.reddit.com/r/Bitwarden/s/LsJWCaQ6YD https://www.reddit.com/r/Bitwarden/s/LsJWCaQ6YD
- DrammBA 7mo agoThe reddit link mentions that they only reported what is now issue #9 and bitwarden has said it's working as intended, so that's why they were "ignored" 4 years ago.
- snowhale 7mo ago[dead]
- politelemon 7mo agoOnline password managers is the distinction here.
- burnt-resistor 7mo agoI only want to know if BW01-05, 07, 10-12 and have been addressed. 06 is very minor and known, and 08-09 only appear to apply to organization accounts.
- Melatonic 7mo agoKeePass ftw Just make sure you have backups