When Server-Side Control Breaks Password Manager Security: What This Week's Research Really Means
When Server-Side Control Breaks Password Manager Security: What This Week’s Research Really Means
You know that moment when someone challenges something you’ve always believed to be true? That’s exactly what happened to me reading Bruce Schneier’s latest post about password manager security research. We’ve all been telling users that password managers with zero-knowledge architecture are bulletproof – that even if the company gets compromised, your data stays safe. Turns out, it’s more complicated than that.