logo

On the Security of Password Managers

ID: 203848e8-4027-585c-8984-115bcf88402d

STIX ID: report--203848e8-4027-585c-8984-115bcf88402d

Feed Name: Schneier on Security

Threat Score
60/100

Date Published: 2026-02-23

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

The blog post links to research revealing that server-side control or compromise of major password managers (Bitwarden, Dashlane, LastPass) can allow data theft or decryption of user vaults in certain configurations—notably when account recovery, vault sharing, or grouping features are used—and suggests using local-only tools like Password Safe to avoid these risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.