Gnarly Vulnerabilities in 3 Password Managers

Summary:

Full paper:

For Bitwarden, most of these assume server-side compromise, but that’s an important aspect of the threat model.

Post title alludes to Bitwarden, Dashlane, and LastPass, but worth highlighting known vulnerabilities with 1Password:

The study also found that 1Password, another popular password manager, is vulnerable to both item-level vault encryption and sharing attacks. However, 1Password has opted to treat them as arising from already known architectural limitations.

Summary of attacks (BW stands for Bitwarden, LP for LastPass, and DL for Dashlane)

When reached for comment, Jacob DePriest, Chief Information Security Officer and Chief Information Officer at 1Password, told The Hacker News that the company’s security reviewed the paper in detail and found no new attack vectors beyond those already documented in its publicly available Security Design White Paper.

2 Likes

I’m not surprised that this is the case with the password managers.

I think there’s always the good old reasonable considerations apply:

Enforce Multi-factor authentication with a HSM (Hardware Security Module)
Limit recovery level vault permissions to a limited number of people
Review permissions
Segment Sensitive Credentials
Enable activity Logging and alerts, monitor alerts for unusual vault modifications, permission changes, or login patterns.

An example of a notification:

This goes to the ‘Security’ channel so i can easily see activity, and access the link to 1password to view devices and browsers. For self, this is the most helpful, because I can listen for an audible notification that should be within a few seconds of signing in. “digital sound provides a lot more options, including music, melodies, tonal sequences, or real recorded objects.” 99 percent invisible- Mini-Stories: Volume 4

From what I see in the field especially with small businesses is that there is so much co-mingling of data, and connections to services that the sprawl of logins, and unpredictable login mechanisms between websites is overburdening for the average user that they generally do not care, unless that is enforced by an Administrator.