Your passwords are not as safe as you think

Published March 2, 2026
— Courtesy The Star
— Courtesy The Star

GENEVA: Keeping track of password requirements such as a mix of upper and lower case letters, numbers, special characters and more — not only to be remembered but to be changed every few months — is a tall order, not least as platforms urge users to ensure each password is unique.

This headache has opened the door to password manager services promising users secure cloud-based storage for their many login credentials behind one password-protected gateway, usually an encrypted “vault.”

But now these password managers have been found to be “less secure than promised,” according to the Federal Institute of Technology (ETH) Zurich, where researchers worked with colleagues from Università della Svizzera italiana in Lugano to test three popular platforms. The team found “serious security vulnerabilities” that meant they were “able to view and even make changes to stored passwords.”

Some of the systems appeared to rely on 1990s-era cryptography, potentially making them easy prey for hackers using up-to-date software.

“Such attacks do not require particularly powerful computers or servers — just small programmes capable of impersonating the server,” said ETH’s Matteo Scarlata.

“Due to the large amount of sensitive data they contain, password managers are likely targets for experienced hackers who are capable of penetrating the servers and launching attacks from there,” said Kenneth Paterson, professor of computer science at ETH Zurich.

The researchers said they contacted the providers to give them 90 days to fix the newly discovered vulnerabilities before publishing their findings. Some of the platforms appeared hesitant about updating their protections for fear they could cut their customers — which include thousands of companies as well as individuals — off from their passwords amid such revamps.

“For the most part, the providers were cooperative and appreciative, but not all were as quick when it came to fixing the security vulnerabilities,” said Paterson.—The Star (Malaysia)/ANN

Published in Dawn, March 2nd, 2026

Opinion

A long week

A long week

There’s some wariness about the excitement surrounding this moment of international glory.

Editorial

Unlearnt lessons
Updated 28 Apr, 2026

Unlearnt lessons

THE US is undoubtedly the world’s top military and economic power at this time. Yet as the Iran quagmire has ...
Solar vision?
28 Apr, 2026

Solar vision?

THE recent imposition of certain regulatory requirements for small-scale solar systems, followed by the reversal of...
Breaking malaria’s grip
28 Apr, 2026

Breaking malaria’s grip

FOR the first time in decades, defeating malaria in our lifetime is possible, according to WHO. Yet in Pakistan,...
Pathways to peace
Updated 27 Apr, 2026

Pathways to peace

NEGOTIATIONS to hammer out the 2015 Iran nuclear agreement took nearly two years before a breakthrough was achieved....
Food-insecure nation
27 Apr, 2026

Food-insecure nation

A NEW UN-backed report has listed Pakistan among 10 countries where acute food insecurity is most concentrated. This...
Migration toll
27 Apr, 2026

Migration toll

THE world should not be deceived by a global migration count lower than the highest annual statistics on record —...