25 Vulnerabilities Found in Cloud Password Managers, Exposing Users to Unauthorized Access and Changes
Recent research conducted by the Applied Cryptography Group at ETH Zurich has uncovered critical security vulnerabilities in three major cloud-based password managers: Bitwarden, LastPass, and Dashlane. Together, these platforms serve approximately 60…
Recent research conducted by the Applied Cryptography Group at ETH Zurich has uncovered critical security vulnerabilities in three major cloud-based password managers: Bitwarden, LastPass, and Dashlane. Together, these platforms serve approximately 60 million users. The study challenges the prevailing industry assumption that providers cannot access user data, even in the event of server compromise.
The researchers, led by Professor Kenneth Paterson, operated under a "malicious server threat model." They simulated a compromised service provider to evaluate how client applications, such as web browser extensions, would respond to unexpected server behavior.
The study identified a total of 25 distinct attack vectors:
Bitwarden: 12 vulnerabilities LastPass: 7 vulnerabilities Dashlane: 6 vulnerabilities
These vulnerabilities enable unauthorized access and modification of user vaults, ranging from targeted integrity violations to complete compromise within an organization. A significant cause of these issues is the complexity of the code required to support user-friendly features.
The study challenges the prevailing industry assumption that providers cannot access user data, even in the event of server compromise.
Target Vendor Vulnerabilities Detected Impact Type Threat Model
Bitwarden 12 Vault Access & Modification Malicious Server
LastPass 7 Vault Access & Modification Malicious Server
Dashlane 6 Vault Access & Modification Malicious Server
The vulnerabilities identified have significant implications for the "zero-knowledge" security model, which posits that data is encrypted on the device before reaching the cloud. The research demonstrated that a sophisticated hacker with server access could manipulate data streams to decrypt sensitive information.
Following standard responsible disclosure protocols, the researchers informed the affected vendors and provided a 90-day remediation period before publishing their findings. Although cooperative, vendors varied in their speed and willingness to implement fixes.
Recommendations for users include selecting password managers that undergo external audits and provide transparency regarding their security architecture. Additionally, vendors are encouraged to offer a migration path to modern cryptographic systems rather than continually patching legacy code.
Based on reporting by GBHackers.
