GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    guisso :v_term: (guisso@bolha.one)'s status on Sunday, 01-Mar-2026 19:57:29 JST guisso :v_term: guisso :v_term:

    Pesquisadores encontraram falhas graves em gerenciadores de senha populares, LastPass, Bitwarden e Dashlane.

    O LastPass se destaca pelo pior histórico: vazamentos em 2015, 2021 e 2022... e agora novas vulnerabilidades. Para piorar, o e-mail dos pesquisadores foi parar no **spam** da empresa.

    Se você ainda usa LastPass: sai de lá agora.

    1Password parece o melhor até o momento, mas ainda tem seus problemas. Bitwarden é open source, então rezo para um fix o quanto antes. E apesar de ter seus problemas tb, KeePassXC continua bem tb.

    Link do paper: https://eprint.iacr.org/2026/058

    #gerenciadoresdesenha

    In conversation about 7 months ago from bolha.one permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Parked at Loopia
    2. Domain not in remote thumbnail source whitelist: eprint.iacr.org
      Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password Managers
      Zero Knowledge Encryption is a term widely used by vendors of cloud-based password managers. Although it has no strict technical meaning, the term conveys the idea that the server, who stores encrypted password vaults on behalf of users, is unable to learn anything about the contents of those vaults. The security claims made by vendors imply that this should hold even if the server is fully malicious. This threat model is justified in practice by the high sensitivity of vault data, which makes password manager servers an attractive target for breaches (as evidenced by a history of attacks). We examine the extent to which security against a fully malicious server holds true for three leading vendors who make the Zero Knowledge Encryption claim: Bitwarden, LastPass and Dashlane. Collectively, they have more than 60 million users and 23% market share. We present 12 distinct attacks against Bitwarden, 7 against LastPass and 6 against Dashlane. The attacks range in severity, from integrity violations of targeted user vaults to the complete compromise of all the vaults associated with an organisation. The majority of the attacks allow recovery of passwords. We have disclosed our findings to the vendors and remediation is underway. Our attacks showcase the importance of considering the malicious server threat model for cloud-based password managers. Despite vendors’ attempts to achieve security in this setting, we uncover several common design anti-patterns and cryptographic misconceptions that resulted in vulnerabilities. We discuss possible mitigations and also reflect more broadly on what can be learned from our analysis by developers of end-to-end encrypted systems.

    Feeds

    • Activity Streams
    • RSS 2.0
    • Atom
    • Help
    • About
    • FAQ
    • TOS
    • Privacy
    • Source
    • Version
    • Contact

    GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

    Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.