#passwordmanagers

2026-03-05

MakeUseOf: 3 free password managers that are actually better than the paid ones. “Turns out, not all free apps are stripped-down tools that only try to get you to subscribe to higher tiers. The following three free password managers are actually great to use, and offer solid features, transparency, and trust.”

https://rbfirehose.com/2026/03/05/makeuseof-3-free-password-managers-that-are-actually-better-than-the-paid-ones/
KillBaitkillbait
2026-02-28

Password Managers Expose Hidden Vulnerabilities in Latest Study

📰 Original title: Password Managers Share a Hidden Weakness

🤖 IA: It's not clickbait ✅
👥 Usuarios: It's not clickbait ✅

View full AI summary: killbait.com/en/password-manag

KillBaitkillbait
2026-02-28

Password Managers Expose Hidden Vulnerabilities in Latest Study

📰 Original title: Password Managers Share a Hidden Weakness

🤖 IA: It's not clickbait ✅
👥 Usuarios: It's not clickbait ✅

View full AI summary: killbait.com/posts/post/0b8442

Benjamin Carr, Ph.D. 👨🏻‍💻🧬BenjaminHCCarr@hachyderm.io
2026-02-27

#Passwordmanagers’ promise that they can’t see your vaults isn’t always true
Contrary to what password managers say, a server compromise can mean game over.
The team executed 27 successful attacks against industry leaders #Bitwarden, #LastPass, and# Dashlane (12 against Bitwarden, 7 against LastPass, and 6 against Dashlane), proving that if a server is compromised by a sophisticated actor, your vault can be unlocked with surprising ease.
arstechnica.com/security/2026/
May just be fear-mongering or FUD

「ʀᴏʙᴇʀᴛ」robertklep@c.im
2026-02-25

I've been running Bitwarden with a self-hosted Vaultwarden instance for a few weeks now, and it certainly looks like it can replace 1Password for me.

Although it doesn't have "AI-powered item naming”... #worldssmallestviolin

github.com/dani-garcia/vaultwa

#passwordmanagers #1password #bitwarden #vaultwarden

「ʀᴏʙᴇʀᴛ」robertklep@c.im
2026-02-24

Wow, #1Password are increasing their prices by 20% 😱

Good thing I was already checking out alternatives, because I don’t care about any of the things that they say are causing the price increase (“AI-powered item naming”, really?).

#passwordmanagers

Ronald RaadsenRonaldRaadsen
2026-02-23

I never liked the idea of using cloud-based password managers. There are news stories all the time about some type of data breach. Each additional person having their passwords on a server makes the payout incrementally more attractive, more valuable.

arstechnica.com/security/2026/

Samuel Björkeringsamuelbjo
2026-02-20

Password managers
I’ve tried several password managers and Bitwarden still stands out. It stores payment cards, identity, SSH keys and more. It's hosted un EU and open source! The best part: a strong master password protects everything, while you can use a simple PIN for daily access. It has a Linux app, Firefox extension, Android app and more.

Marcus "MajorLinux" Summersmajorlinux@toot.majorshouse.com
2026-02-19

And this puts me one step closer to migrating my cloud vault in-house...

Password managers' promise that they can't see your vaults isn't always true

arstechnica.com/security/2026/

#PasswordManagers #ZeroKnowledge #Security #Privacy #Vulnerabilities #Tech

2026-02-18

this concludes my reading of eprint.iacr.org/2026/058

what a paper. warmly recommended to read.

#crypto #passwordmanagers #bitwarden #lastpass #dashlane

14/n

2026-02-18

Ars Technica: Password managers’ promise that they can’t see your vaults isn’t always true. “The researchers reverse-engineered or closely analyzed Bitwarden, Dashlane, and LastPass and identified ways that someone with control over the server—either administrative or the result of a compromise—can, in fact, steal data and, in some cases, entire vaults. The researchers also devised […]

https://rbfirehose.com/2026/02/18/ars-technica-password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/
Ars Technica Newsarstechnica@c.im
2026-02-17

Password managers' promise that they can't see your vaults isn't always true arstechni.ca/M3dw #endtoendencryption #passwordmanagers #zeroknowledge #Features #Security #Biz&IT

Martin ReitsmaMartin63
2026-02-17

Password managers’ promise that they can’t see your vaults isn’t always true
Password managers’ promise that they can’t see your vaults isn’t always true

opr.news/2ad7d727260217en_us?l

Download Now
opr.as/share

2026-02-17

25 recovery-based attack vectors found in major password managers.

Bitwarden, LastPass, Dashlane & 1Password affected.

Worst case: full vault compromise via crypto & recovery flaws.
technadu.com/major-cloud-passw

#PasswordManagers #Crypto #InfoSec #CloudSecurity

Major Cloud Password Managers Vulnerable to Recovery Attacks: Bitwarden, LastPass, and Dashlane
2026-02-13

Exactly what I came here to say @joernsmock. Long strings of random characters are no harder for computers to guess than equally long strings made up of dictionary words. Epecially obscure or non-English words.

Claiming they are is a sales pitch for password managers vendors, not a security fact. Current passphrase advice reflects that XKCD comic, and suggests passphrases be long, memorable, and changed as infrequently as possible.

#PasswordManagers #passphrases

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst