Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Darkly)
  • No Skin
Collapse
Brand Logo
  1. Home
  2. Uncategorized
  3. Contrary to what password managers say, a server compromise can mean game over.

Contrary to what password managers say, a server compromise can mean game over.

Scheduled Pinned Locked Moved Uncategorized
6 Posts 6 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Dan GoodinD This user is from outside of this forum
    Dan GoodinD This user is from outside of this forum
    Dan Goodin
    wrote last edited by
    #1

    Contrary to what password managers say, a server compromise can mean game over.

    https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/

    gentle colossusX StuT ozengO Chris HayesC LeelooL 5 Replies Last reply
    1
    0
    • Dan GoodinD Dan Goodin

      Contrary to what password managers say, a server compromise can mean game over.

      https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/

      gentle colossusX This user is from outside of this forum
      gentle colossusX This user is from outside of this forum
      gentle colossus
      wrote last edited by
      #2

      @dangoodin cool cool just remember that contrary to what Ars says, their articles aren't written by people

      1 Reply Last reply
      0
      • Dan GoodinD Dan Goodin

        Contrary to what password managers say, a server compromise can mean game over.

        https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/

        StuT This user is from outside of this forum
        StuT This user is from outside of this forum
        Stu
        wrote last edited by
        #3

        @dangoodin Interesting article. Always good to know the trade-offs of cloud vaults vs local, etc.

        As a Bitwarden user, are there any mitigating actions one might take? Or is this more of a "know your threat model" sort of thing?

        1 Reply Last reply
        0
        • Dan GoodinD Dan Goodin

          Contrary to what password managers say, a server compromise can mean game over.

          https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/

          ozengO This user is from outside of this forum
          ozengO This user is from outside of this forum
          ozeng
          wrote last edited by
          #4

          @dangoodin bloody hard to do security well. Seems like the more “advanced” features have taken some shortcuts

          1 Reply Last reply
          0
          • Dan GoodinD Dan Goodin

            Contrary to what password managers say, a server compromise can mean game over.

            https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/

            Chris HayesC This user is from outside of this forum
            Chris HayesC This user is from outside of this forum
            Chris Hayes
            wrote last edited by
            #5

            @dangoodin and it really is game over if your password manager is also doing 2FA codes and passkeys. I love the convenience, but I feel like I'm totally defeating the security of both by having my password manager handle everything.

            Maybe selectively using external 2FA methods for high-risk logins is better tradeoff.

            1 Reply Last reply
            0
            • Dan GoodinD Dan Goodin

              Contrary to what password managers say, a server compromise can mean game over.

              https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/

              LeelooL This user is from outside of this forum
              LeelooL This user is from outside of this forum
              Leeloo
              wrote last edited by
              #6

              @dangoodin
              You mean cloud password managers?

              Using a desktop password manager, I don't see how any server would see my password except through some spyware.

              1 Reply Last reply
              0
              • R ActivityRelay shared this topic
              Reply
              • Reply as topic
              Log in to reply
              • Oldest to Newest
              • Newest to Oldest
              • Most Votes


              • Login

              • Don't have an account? Register

              • Login or register to search.
              Powered by NodeBB Contributors
              • First post
                Last post
              0
              • Categories
              • Recent
              • Tags
              • Popular
              • World
              • Users
              • Groups