Particle.news
Download on the App Store

Swiss Study Says Server Compromise Can Undermine ‘Zero‑Knowledge’ Promises in Major Password Managers

The study, built on simulated provider takeovers, prompts calls for modern cryptography alongside clearer guarantees.

Overview

  • Researchers from ETH Zürich and Università della Svizzera italiana demonstrated 12 attacks against Bitwarden, 7 against LastPass, and 6 against Dashlane that could expose or alter vault contents under lab conditions.
  • The scenarios assume a fully compromised provider server and often some user interaction, and no exploitation in the wild has been reported.
  • Vendors responded after responsible disclosure: Bitwarden says all identified issues are resolved with some design choices retained, Dashlane distributed fixes in its browser extension, and LastPass has patched icon/URL handling with broader changes in progress.
  • The paper is public and slated for presentation at Usenix Security 2026 after a 90‑day disclosure window that began in January, with remediation timelines varying by provider.
  • The team attributes many weaknesses to legacy cryptography and complex codebases, while Germany’s BSI still advises using password managers and characterizes practical risk as medium to low under the stated conditions.