top | item 47172439

A Comparative Security Analysis of Three Cloud-Based Password Managers

1 points| u1hcw9nx | 3 days ago |eprint.iacr.org

2 comments

order

u1hcw9nx|3 days ago

>We present 12 distinct attacks against Bitwarden, 7 against LastPass and 6 against Dashlane

They also discuss 1Password. no authentication of public keys, vulnerable to vault substitution attack (it does not authenticate vault keys) and KDF Parameter Downgrade (a malicious server can reduce the iteration count from the default 650,000 iterations to a minimal value of 10,000 iterations.)