Tag

Password Managers

All articles tagged with #password managers

CR Names the Best Password Managers to Safeguard Your Accounts
technology26 days ago

CR Names the Best Password Managers to Safeguard Your Accounts

Consumer Reports ranks top password managers, led by 1Password Families (tied with Dashlane Premium and Keeper Unlimited) and including Bitwarden Families/Free among its top picks; free built‑in options from Apple, Google and Samsung are available, while premium plans add features like shared vaults, VPNs, scam protection, and real-time security alerts across Windows, Mac, Android and iOS. Prices vary by plan and family size, roughly from about $1.65 to $6 per month.

Mac malware CrashStealer masquerades as Apple crash reporter to steal secrets
security1 month ago

Mac malware CrashStealer masquerades as Apple crash reporter to steal secrets

Jamf Threat Labs warns about CrashStealer, a macOS malware that pretends to be Apple’s crash reporting tool via a fake notarized app named Werkbit. It targets over 80 cryptocurrency wallet extensions and 14 password managers (such as 1Password, LastPass, and Dashlane), searches Documents and Downloads for data, and prompts for full-disk access and a system password to access the login keychain. The stolen data is encrypted with AES-256-GCM and sent to the attacker. Apple revoked Werkbit’s signing credentials, but the attack vector shows how notarization can be abused, and the threat could reappear; users should avoid apps that prompt for a password or claim to be CrashReporter.

Security researchers find critical flaws in mainstream password managers
technology6 months ago

Security researchers find critical flaws in mainstream password managers

An ETH Zurich team tested Bitwarden, LastPass, and Dashlane under a malicious-server threat model and demonstrated 12, 7, and 6 attacks respectively, showing that passwords could be accessed or altered and that end-to-end, zero-knowledge encryption promises may not hold. They found the attacks often only required routine user actions like logging in or syncing. The researchers propose updating cryptographic standards for new customers, providing migration paths for existing users, and increasing transparency via external audits, noting that many providers still rely on outdated crypto. Consumers should favor password managers that disclose vulnerabilities, are audited, and enable end-to-end encryption by default.

Zero-knowledge claims tested: researchers reveal multiple flaws in top password managers
security6 months ago

Zero-knowledge claims tested: researchers reveal multiple flaws in top password managers

Researchers from ETH Zurich and USI Lugano analyzed Bitwarden, Dashlane, and LastPass and uncovered multiple attack vectors that can enable a compromised or malicious server to read or even modify vaults, especially when account-recovery, group enrollment, key escrow, or backward-compatibility features are enabled. Some attacks could allow theft of entire vaults or selective item data, and even breach older encryption configurations. While vendors defend their security audits and ongoing patching, the study argues that the term “zero-knowledge” can be misleading and urges stronger threat models and resilience measures across password managers.

Researchers expose 25 recovery attacks against leading cloud password managers
security6 months ago

Researchers expose 25 recovery attacks against leading cloud password managers

A joint ETH Zurich/USI study identifies 25 distinct password-recovery/related attacks across major cloud password managers (Bitwarden, Dashlane, LastPass; with 1Password also noted for some flaws). Attacks span four categories: exploiting key escrow in account recovery, weaknesses in item-level encryption and metadata, vulnerabilities in sharing features, and downgrades due to legacy code. In total, 12 attacks hit Bitwarden, 7 LastPass, and 6 Dashlane; 1Password was linked to item-level and sharing flaws as known limitations. Vendors have issued patches or mitigations (e.g., Dashlane removing legacy crypto, Bitwarden remediation, LastPass hardening, 1Password using SRP), and there’s no evidence these issues have been exploited in the wild.

Ensuring Loved Ones Can Access Your Online Accounts After You're Gone
technology11 months ago

Ensuring Loved Ones Can Access Your Online Accounts After You're Gone

The article discusses the importance of planning for digital legacy by using password managers with inheritance features, such as Keeper, LogMeOnce, and NordPass, to ensure loved ones can access online accounts after death. It emphasizes the need for pre-arranged access, secure account management, and proper account shutdown procedures to protect privacy and simplify estate handling.

Critical Security Flaws in Password Managers Enable Data Theft
technology1 year ago

Critical Security Flaws in Password Managers Enable Data Theft

Several top password managers, including 1Password, Bitwarden, and LastPass, have been found vulnerable to a clickjacking flaw that allows hackers to steal login credentials, 2FA codes, and credit card information by overlaying invisible HTML elements, with all tested managers susceptible to at least one attack method. Users are advised to update their software and disable autofill until patches are released.

"Android Password Managers: A Critical Look at the AutoSpill Vulnerability"
technology2 years ago

"Android Password Managers: A Critical Look at the AutoSpill Vulnerability"

AutoSpill is a vulnerability in Android that can leak credentials from popular password managers. It occurs when a credential stored in a password manager is autofilled into a third-party app, exposing the credentials to that app. The affected password managers include Google Smart Lock, Dashlane, 1Password, LastPass, Enpass, Keepass2Android, and Keeper. However, the threat is limited to specific scenarios where the third-party app allows users to log in with different account credentials or when a malicious app exploits WebView content. AutoSpill does not pose a threat when autofilling credentials for accounts managed by the app developer or service.

Android Password Managers: A Security Warning
technology2 years ago

Android Password Managers: A Security Warning

Several popular Android password managers, including 1Password, LastPass, Enpass, Keeper, and Keepass2Android, are leaking user credentials due to a vulnerability in the autofill functionality of Android apps. The flaw, known as AutoSpill, allows credentials shared with WebView to also be shared with the app that requested the username and password. Even if the vulnerability was tested on older devices and software, it serves as a reminder to keep Android OS and installed apps up-to-date for better security.

Android Password Managers Expose User Data in Major Security Breach
cybersecurity2 years ago

Android Password Managers Expose User Data in Major Security Breach

Security researchers have discovered a major vulnerability, called AutoSpill, that affects the Android autofill function in popular password managers. The vulnerability allows hackers to bypass security mechanisms and expose credentials to the host app. Password managers such as 1Password, LastPass, Enpass, Keeper, and Keepass2Android are vulnerable to the exploit, along with DashLane and Google Smart Lock when a JavaScript injection method is enabled. While there is no evidence of exploitation in the wild, the researchers warn that the implications of AutoSpill are highly dangerous. The affected password managers and the Android security team have been informed, and fixes are being developed.

"Security Alert: Android Password Managers Vulnerable to AutoSpill Attack"
technology2 years ago

"Security Alert: Android Password Managers Vulnerable to AutoSpill Attack"

Researchers have discovered a new attack called AutoSpill that can steal account credentials from Android password managers during the autofill process. The attack exploits weaknesses in Android's autofill framework, allowing rogue apps to capture auto-filled credentials without detection. Most password managers on Android are vulnerable to AutoSpill, even without JavaScript injection. The researchers have disclosed their findings to impacted software vendors and Android's security team, but no details about fixing plans have been shared yet. Some password management providers, such as 1Password, LastPass, and Keeper, have acknowledged the issue and are working on fixes. Google recommends that third-party password managers implement best practices to distinguish between native views and WebViews and warns users when entering passwords for domains not owned by the hosting app.