this post was submitted on 17 Feb 2026
214 points (89.1% liked)
Technology
81373 readers
4883 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
they ran the test on those pw managers because they were open source. that allowed the testers to implement a "dummy" provider on their own "compromised server." so the results of failing the tests are based on the hypothetical situation of "what if bitwarden (or whoever) had an entire server taken over by hackers". while the chances of that happening are greater than zero, it would take a lot for someone to completely hijack a server like that
edit to add-- these tests are one of the reasons these pw managers choose to be open source: to allow 3rd party tests like this to find vulnerabilities, so they can be fixed
nothing is 100% guaranteed safe, but if you don't want to remember or write down dozens or hundreds of unique strong passwords, i still would recommend a pw manager
Oh okay so they probably delivered malicious code to the user entering their passwords... Well even an offline pw manager can be compromised in the code.