Researchers at ETH Zurich recently identified critical vulnerabilities in three major password managers: Bitwarden, LastPass, and Dashlane. The study simulated a "malicious server" scenario, demonstrating that compromised infrastructure could allow attackers to access or alter user credentials.
Key Findings:
- Vulnerability: If a service's server is compromised, it can view and modify stored vault data.
- Obsolete Tech: Researchers noted that some platforms still rely on 1990s-era cryptographic standards that are now considered insecure.
- Current Status:
- Dashlane: Has already issued a fix for the identified issues.
- Bitwarden & LastPass: Both companies are currently working on patches to address the flaws.
Users are encouraged to keep their applications updated to ensure the latest security protocols are in place as these fixes roll out.


