Full Breakdown
Vulnerabilities in Popular Password Managers Exposed by New Study
2/17/2026, 2:32:43 AM
Overview of Findings
A recent study conducted by researchers from ETH Zurich and Università della Svizzera italiana has revealed significant vulnerabilities in several popular cloud-based password managers, including Bitwarden, LastPass, Dashlane, and 1Password. The research indicates that these platforms, which collectively serve over 60 million users, are susceptible to password recovery attacks that could compromise user data. The study highlights that the promise of "zero-knowledge encryption" (ZKE) made by these services may not be as secure as claimed.
Attack Mechanisms
The researchers identified 12 distinct attacks against Bitwarden, seven against LastPass, and six against Dashlane. These attacks exploit various weaknesses, including flaws in the key escrow account recovery mechanisms, item-level encryption, sharing features, and backward compatibility with legacy code. The attacks range from integrity violations affecting specific user vaults to the complete compromise of all vaults within an organization. Notably, the study demonstrated that attackers could retrieve and even modify passwords through routine user interactions, such as logging in or synchronizing data.
Vendor Responses and Mitigations
In response to the findings, Bitwarden, LastPass, and Dashlane have implemented countermeasures to address the identified vulnerabilities. Bitwarden reported that seven of the issues have been resolved or are in active remediation, while LastPass is enhancing its integrity guarantees. Dashlane has already patched a significant vulnerability that could have allowed a downgrade of its encryption model. 1Password acknowledged the vulnerabilities but stated they stem from known architectural limitations, emphasizing their commitment to strengthening security against advanced threats.
Criticism and Industry Implications
Kenneth Paterson, a professor at ETH Zurich, expressed surprise at the severity of the vulnerabilities, noting that password managers had not undergone extensive academic scrutiny until now. He emphasized the need for vendors to adopt modern cryptographic standards and to communicate security guarantees transparently to users. The researchers warned that the same vulnerabilities could potentially affect other password management solutions across the industry.
Official Statements
- "We have now shown that this is not the case," said Matilda Backendal, one of the researchers, regarding the security promises of password managers.
- "We want our work to help bring about change in this industry," stated Paterson, advocating for clearer communication of security guarantees by providers.
What's Next
The study's findings may prompt further investigations into the security architectures of other password managers. As the industry grapples with these vulnerabilities, users are advised to choose password managers that are transparent about security risks and undergo regular external audits.
Verbatim Quotes
- "The majority of our attacks require simple interactions which users or their clients perform routinely." — Matteo Scarlata, Researcher
- "We were surprised by the severity of the security vulnerabilities." — Kenneth Paterson, Professor of Computer Science
- "Bitwarden has never been breached and believes third-party security assessments are critical." — Bitwarden Statement
- "Our Security team is grateful for the opportunity to engage with ETH Zurich." — LastPass Spokesperson
This study underscores the importance of rigorous security assessments in the password management industry, highlighting the need for ongoing vigilance and improvement in user data protection.
