Get all your news in one place.
100’s of premium titles.
One app.
Start reading
Windows Central
Windows Central
Technology
Cale Hunt

"The majority of the attacks allow recovery of passwords" — New research suggests your favorite password manager might not be as secure as you thought

The logo for online password manager service "LastPass" is reflected on the internal discs of a hard drive.

I've long been someone concerned about data security and privacy. I grew up in a time when your passwords were kept securely in your own organic memory if not jotted down on a page somewhere, so the rise of password managers felt like a godsend.

A place to securely store all passwords (and more) for all accounts? Accessible across your devices? Too convenient to pass up. And yet, I still didn't trust my password manager with the "big" credentials; those, I kept tucked away in my head.

Despite some obvious trepidation, I've never been shy about recommending a password manager to help keep your data secure. It's otherwise impossible to have a secure, different password for all accounts.

At least, that's how it used to be.

According to a new study published by security researchers from ETH Zurich and Università della Svizzera Italiana, password managers might not be as secure as once imagined.

These attacks work even when proper authenticated encryption is used. They are possible because of insufficient key separation in vaults with complex structures and/or a lack of cryptographic binding between data and metadata.

Matteo Scarlata, Giovanni Torrisi, Matilda Backendal, Kenneth G. Paterson

The most popular password managers, like Bitwarden, LastPass, and Dashlane, which together have more than 60 million customers, have all seemingly adopted a stance known as "Zero Knowledge Encryption."

Largely based on nothing technical, it's a term designed to create peace-of-mind for users by conveying the idea that what is stored on password manager servers can't be read by the companies. If the company hosting your encrypted passwords can't read it, surely no one else who breaks in can, either.

Wrong.

The security researchers discovered several vulnerabilities after hitting these services with "a cornucopia of practical attacks," noting that these attacks allowed them to "downgrade security guarantees, violate security expectations, and even fully compromise users' accounts."

In one example, researchers were able to compromise entire accounts using a vulnerability in account sharing and key escrow utilities. In another example, a lack of ciphertext integrity resulted in keys being swapped out in order to attack vaults.

What's worse is that the endgame of the majority of these attacks allowed researchers to recover passwords, something that password managers explicitly say they defend against.

Researchers have shared their findings with vulnerable password management companies, and it's stated that "remediation is underway."

(via Ars Technica)

Windows Central's advice

Hardware-based authentication, like this USB solution from YubiKey, can help protect your data.

I'm always happy for an opportunity to remind people that password security is only getting more important. And despite these research findings suggesting that password managers are, in some ways, vulnerable, they're still the best way for most people to manage different credentials for each account.

What you should do, however, is consider a switch to a local-only option that doesn't store data in the cloud. You might also consider switching to hardware-based two-factor authentication. We've covered YubiKey in the past as a solid option.

If you are sticking with a standard cloud-based manager, be sure to segment your passwords into several vaults, ensuring your entire digital life isn't compromised if one should go down.

👉 Microsoft finally makes passkeys viable thanks to Edge on Windows 11 — you can finally sync them across devices

Share your thoughts about password managers

Will you continue using a password manager as usual despite these findings? What is your alternative? Let me know in the comments section!


Join us on Reddit at r/WindowsCentral to share your insights and discuss our latest news, reviews, and more.


Sign up to read this article
Read news from 100’s of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.