As usual, the actual best option (keepass in this case) gets no publicity.
post
To be fair, it's worth noting that the majority (all?) of the flaws were found around organization management, SSO, vault sharing and compatibility features. All of which severely expand the attack surface of any password manager, and hence should be avoided like a plague.
Also worth noting that the actual whitepaper (also linked in the article) is much better written than the article, and it was an interesting and easily understandable read. Give it a go.
And thanks for sharing!
Since end-to-end encryption is still relatively new in commercial services, it seems that no one had ever examined it in detail before...
Source
Oh really?! Tell me about it!
In addition to KeePass, some may find "Pass" interesting, that is based on GnuPG - https://www.passwordstore.org/
I think there is an important distinction that all of the attacks are against the client connection to the compromised server, they're not able to decrypt the data at rest.
Hopefully each organization hardens against these discoveries.
Nice article. I've been using Keepass for many years but, as someone whose been looking to switch to Linux, this is very intriguing.
all 15 comments