Comment on Password managers are less secure than promised

irate944@piefed.social ⁨10⁩ ⁨hours⁩ ago

Copy pasting a comment that I saw on Reddit

——

Link to the original study (with a less sensationalized title):

https://zkae.io

A few important notes:

No need to panic: all of our attacks presume a malicious server. We have no reason to believe that the password manager vendors are currently malicious or compromised, and as long as things stay that way, your passwords are safe. That said, password managers are high-value targets, and breaches do happen.

You can ask your provider the following questions:

  1. ⁠Do you offer end-to-end encryption? What security do you provide in case your server infrastructure were to be compromised?

  2. How do you check that public keys and public-key ciphertexts are authentic?

  3. How do you authenticate security-critical settings, such as the KDF type and the iteration count?

  4. Do you provide integrity guarantees for a user’s vault as a whole? Can a malicious server add items to your vault?

You can also ask your favourite password manager to commission an audit checking for our attacks in their products.

source
Sort:hotnewtop