Episode

Should you still trust your password manager?

Podcast
Safe Mode Podcast
Published
Feb 19, 2026
Duration seconds
2200
Processing state
not_requested
Canonical source
https://soundcloud.com/podcast-defensescoop-com/should-you-still-trust-your
Audio
https://feeds.soundcloud.com/stream/2269794779-podcast-defensescoop-com-should-you-still-trust-your.mp3
JSON
/v1/public/podcasts/safe-mode-podcast-6421323/episodes/should-you-still-trust-your-password-manager
Markdown
/podcast/safe-mode-podcast-6421323/should-you-still-trust-your-password-manager.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/safe-mode-podcast-6421323/episodes/should-you-still-trust-your-password-manager/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/safe-mode-podcast-6421323/should-you-still-trust-your-password-manager.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

In this episode, Greg explores the gap between password manager marketing claims of "Zero Knowledge Encryption" and the reality uncovered by Swiss researchers who found 25 attacks against Bitwarden, LastPass, and Dashlane. Professor Kenny Patterson joins Greg to discuss why the industry's "honest-but-curious" security model is dangerously inadequate compared to a "malicious server" threat model, diving into three critical vulnerability categories: account recovery mechanisms that allow attackers to swap encryption keys, seemingly innocent features like icon fetching that leak passwords, and "vault malleability" where individual item encryption lets attackers cut-and-paste data between vault fields. They also discuss how legacy code support and backwards compatibility create cryptographic hazards, and what non-negotiable features are needed to build a truly "provably secure" password manager from scratch.