ETH Zurich Bombshell: Bitwarden, LastPass, and Dashlane All Show Major Security Flaws

Post date: April 2, 2026 · Discovered: April 18, 2026 · 4 posts, 32 comments

ETH Zurich researchers successfully demonstrated twenty-five security flaws across three major cloud password managers: Bitwarden, LastPass, and Dashlane.

The takes are sharply split on digital safety. A segment dismisses cloud managers entirely, with ThunderComplex calling them 'scams' due to ceded data control. Meanwhile, others defend these services out of practical necessity, citing the need to accommodate non-technical family members, as noted by DahGangalang and MalReynolds. On the LLM front, the discussion centers on risk: while markz sounds the alarm over the widespread, unvetted practice of using AI for passwords, Ephera counters that LLMs aren't doomed, stating they require explicit tool-calling, like calling `pwgen`, to achieve genuine randomness.

The core consensus points to extreme user caution. For maximum security, users are leaning toward decentralized, high-maintenance personal solutions like KeePassXC/Syncthing. The established vulnerability of major cloud players, combined with LLMs' predictive text bias, creates a clear mandate: users must bypass mainstream tools for genuine protection.

Key Points

OPPOSE

Major cloud password managers are compromised.

ETH Zurich researchers found demonstrable flaws across Bitwarden, LastPass, and Dashlane.

OPPOSE

LLMs are inherently bad for passwords.

markz expressed alarm over the public's tendency to use LLMs for unvetted password generation.

SUPPORT

LLMs can be made secure with correct prompting.

Ephera detailed that LLMs only fail because they default to token prediction; tool-calling like `pwgen` solves the issue.

OPPOSE

Cloud password managers represent a loss of control.

ThunderComplex labeled these services 'scams' due to giving providers total data control.

SUPPORT

High-security users favor local, complex setups.

The general consensus favors decentralized tools like KeePassXC/Syncthing, despite their complexity.

Source Discussions (4)

This report was synthesized from the following Lemmy discussions, ranked by community score.

91
points
Vibe Password Generation: Predictable by Design
[email protected]·17 comments·4/2/2026·by technocrit·irregular.com
19
points
Weak passwords lead to hacked Silicon Valley crosswalk buttons
[email protected]·1 comments·3/18/2026·by yogthos·nbcbayarea.com
10
points
Password managers less secure than promised
[email protected]·10 comments·2/17/2026·by cm0002·ethz.ch
7
points
How to Pick Your Password Manager
[email protected]·5 comments·2/26/2026·by sabreW4K3·eff.org