#PasswordManagers

The Malwarebytes post is based on research from February 16:

ETH Zurich: Password managers less secure than promised ethz.ch/en/news-and-events/eth

Malwarebytes (sales pitch included): Password managers keep your passwords safe, unless… malwarebytes.com/blog/news/202 #infosec #passwordmanagers

Ronald RaadsenRonaldRaadsen
2026-02-23

I never liked the idea of using cloud-based password managers. There are news stories all the time about some type of data breach. Each additional person having their passwords on a server makes the payout incrementally more attractive, more valuable.

arstechnica.com/security/2026/

Samuel Björkeringsamuelbjo
2026-02-20

Password managers
I’ve tried several password managers and Bitwarden still stands out. It stores payment cards, identity, SSH keys and more. It's hosted un EU and open source! The best part: a strong master password protects everything, while you can use a simple PIN for daily access. It has a Linux app, Firefox extension, Android app and more.

Marcus "MajorLinux" Summersmajorlinux@toot.majorshouse.com
2026-02-19

And this puts me one step closer to migrating my cloud vault in-house...

Password managers' promise that they can't see your vaults isn't always true

arstechnica.com/security/2026/

#PasswordManagers #ZeroKnowledge #Security #Privacy #Vulnerabilities #Tech

2026-02-18

this concludes my reading of eprint.iacr.org/2026/058

what a paper. warmly recommended to read.

#crypto #passwordmanagers #bitwarden #lastpass #dashlane

14/n

2026-02-18

Ars Technica: Password managers’ promise that they can’t see your vaults isn’t always true. “The researchers reverse-engineered or closely analyzed Bitwarden, Dashlane, and LastPass and identified ways that someone with control over the server—either administrative or the result of a compromise—can, in fact, steal data and, in some cases, entire vaults. The researchers also devised […]

https://rbfirehose.com/2026/02/18/ars-technica-password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/
Ars Technica Newsarstechnica@c.im
2026-02-17

Password managers' promise that they can't see your vaults isn't always true arstechni.ca/M3dw #endtoendencryption #passwordmanagers #zeroknowledge #Features #Security #Biz&IT

Martin ReitsmaMartin63
2026-02-17

Password managers’ promise that they can’t see your vaults isn’t always true
Password managers’ promise that they can’t see your vaults isn’t always true

opr.news/2ad7d727260217en_us?l

Download Now
opr.as/share

2026-02-17

25 recovery-based attack vectors found in major password managers.

Bitwarden, LastPass, Dashlane & 1Password affected.

Worst case: full vault compromise via crypto & recovery flaws.
technadu.com/major-cloud-passw

#PasswordManagers #Crypto #InfoSec #CloudSecurity

Major Cloud Password Managers Vulnerable to Recovery Attacks: Bitwarden, LastPass, and Dashlane
2026-02-13

Exactly what I came here to say @joernsmock. Long strings of random characters are no harder for computers to guess than equally long strings made up of dictionary words. Epecially obscure or non-English words.

Claiming they are is a sales pitch for password managers vendors, not a security fact. Current passphrase advice reflects that XKCD comic, and suggests passphrases be long, memorable, and changed as infrequently as possible.

#PasswordManagers #passphrases

2026-02-07

Besides #ProtonPass what other #PasswordManagers are good ?

#AskFedi #AskMastodon

My solution for syncing keepass between Linux and iPhone (works with KeePassDX on Android too) using Nextcloud:

My Linux computer is running Incus, and one container is my Nextcloud server.

I have created a folder ~/nextcloud where my keepass.kdbx is located.

KeePassXC is using this file directly and since it's a local file it's always accessible.

I have mounted ~/nextcloud inside the Incus Nextcloud container as /data.

In Nextcloud I have monuted /data as a folder for my Nextcloud user.

In KeePassium in iPhone I have set it up to use WebDAV to my Nextcloud server and then choosen the keepass.kdbx file.

(This way I can also easily share any file between Linux and iPhone)
(I know there are other ways to do this, but since I want to always have access to keepass.kdbx on Linux even if Nextcloud is not running this solution best fits my needs)

#KeePass #KeePassXC #KeePassDX #KeePassium #Incus #Nextcloud #Linux #iPhone #Android #WebDAV #PasswordManager #PasswordManagers #Passwords
Marcel Bootsmanmbootsman@toot.re
2026-01-16

2FA only works if the factors are separate.

If your password manager holds both your passwords AND your 2FA seeds/backup codes, your "second factor" is not really separate anymore.

What I changed (and a checklist):
marcelbootsman.nl/two-factor-a

#2FA #Security #PasswordManagers

Ruhani Rabinruhani
2026-01-14

Unlike some password managers that overwhelm users with features, Proton Pass keeps things straightforward, making it easy to manage your passwords without a steep learning curve.

Read more 👉 lttr.ai/AnH5M

Paul O'Brienpwob
2026-01-05

I’ve published a new article looking at how hardware security keys work with Proton Pass, including YubiKey support.

It covers:
• what security keys actually protect against
• how they fit into Proton Pass
• when they’re worth using (and when they’re not)

If you’re thinking about stronger account security without adding unnecessary friction, this may help.

🔗 paulobrien.com/proton-pass-yub

2025-12-16

7 Tips & Hacks for Ultimate Password Manager Security

apertatube.net/w/sqvNig6Z5McML

Steve Dustcircle 🌹dustcircle
2025-12-10

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst