Skip to content
Epic Fusion team with laptops at a high table discussing password security

New ETH Study shows: Password Managers offer less Security than promised

Xiomi Paulino Knowledge

An ETH study reveals security vulnerabilities in several password managers. What does this mean for users? An overview: Here is a summary.

Password Managers under the Microscope: ETH Study reveals Security Vulnerabilities and what Companies need to know now.

Researchers at ETH Zurich released a study yesterday showing that password managers offer less protection than promised. They recently examined several popular cloud-based password managers including Bitwarden, Dashlane, and LastPass. In tests, the ETH Zurich researchers were able to view and even modify stored passwords!

Many providers promise «zero-knowledge encryption.» This means that even they do not have access to the encrypted passwords. And even if someone gains access to the server, the security risk is said to be low because the data is encrypted and therefore unreadable. We will summarize for you what this means, how your company can address this, and what steps you should take.

Epic Fusion Trennlinie_pink_Brand Accent 3

 

What the ETH Researchers found.

  • The ETH researchers were able to demonstrate that, under certain conditions, an attacker can not only read encrypted passwords but also manipulate them.
  • The researchers demonstrated 12 attacks on Bitwarden, 7 on LastPass, and 6 on Dashlane. To do this, they set up their own servers that behaved like a hacked password manager server.
  • This was made possible through simulations in which an attacker controlled a password manager’s server and exploited typical user interactions.
  • The vulnerabilities stem, among other things, from complex, disorganized architecture and cryptographic mechanisms that are not robust enough against malicious server responses. Such attacks do not require particularly powerful computers or servers – only small programs that can be used to spoof the server’s identity.
  • The ETH study gave the providers 90 days to address the issues before publication. The providers were largely cooperative and grateful.


What ETH recommends.

  • Providers should communicate more clearly which security guarantees actually apply.
  • Systems should be upgraded to the latest cryptographic standards.
  • Users should choose password managers that are transparent, externally audited, and use end-to-end encryption by default.

«Since end-to-end encryption is still relatively new in commercial services, it seems no one had ever looked at it closely before.»

Kenneth Paterson, ETH Professor at the Department of Computer Science

Epic Fusion Trennlinie_pink_Brand Accent 3

 

Statement from LastPass: Response to the ETH Research.

The vendor LastPass has also responded by publishing an official statement in which it addresses the ETH findings and explains its actions.

  • LastPass welcomes security research and collaboration with ETH Zurich to strengthen systems.
  • LastPass emphasizes that there is no evidence that the identified vulnerabilities were actually exploited.
  • According to LastPass, the described issues require a highly privileged attacker with server-side control – not a typical usage scenario.

Specifically for LastPass, the reported issues can be divided into five major categories: 

Account Recovery (Admin Resets)

In companies, administrators reset accounts using public keys – the secure assignment of these keys remains the central challenge.

Sharing Passwords or Entries

When you share something with LastPass, it is encrypted with the person's public key. Problem: If the key is compromised, a server could intercept and read the information.

Structure of Vault Entries

Each vault entry consists of separately encrypted parts. Without validation, an attacker could move encrypted elements between entries.

Website Icons and URLs

LastPass sometimes loads website icons for better overview. If an entry has been manipulated, this would be displayed.

KDF Brute Force Attacks

LastPass allows changes to the number of derivations. If an attacker intercepts the connection, they could lower this number to guess weak passwords more quickly offline.

 

LastPass emphasizes that each of these scenarios assumes a sophisticated attacker with persistent access to its production infrastructure. They do not reflect LastPass’s normal operations or expected user behavior.

Measures LastPass is working on.

Already implemented in the short term:

  • Improved handling of website icons and URLs to mitigate the manipulation scenarios described.

Mid-term and planned updates:

  • Strengthening cryptographic parameter validation and preventing insecure configurations.
  • Improvements to account recovery and sharing workflows to ensure that cryptographic keys cannot be swapped or tampered with.
  • Enhanced integrity of Vault data to prevent encrypted components from being inadvertently swapped out.

 

Recommendation for Customers.

It is generally recommended to take the following steps to enhance security:

  1. Enablemulti-factor authentication (MFA) and/or SSO for administrative accounts.
  2. Limit the number of super admins and regularly review permissions. Also, restrict permissions for shares and shared folders.
  3. Ensure that all users are using the latest versions of the apps and browser extensions.
  4. Use a strong, unique master password.
  5. Always keep software and extensions up to date.
  6. Choose password managers with open auditing, transparent security policies, and strong encryption.

Epic Fusion Trennlinie_pink_Brand Accent 3

 

Epic Fusion is staying on top of Things.

Our customers do not need to take any action. We are closely monitoring all developments and remain in contact with the providers. Should there be any impact on operational processes or customer environments, we will inform you immediately and proactively.

Xiomi Paulino, Modern Workplace Engineer

Questions? Uncertainty?

If you or your users have any questions or uncertainties, we are always available to help.