LingVo.club
Level
Study finds flaws in cloud password managers — Level A2 — a combination combination lock attached to a fence

Study finds flaws in cloud password managersCEFR A2

24 Feb 2026

Adapted from ETH Zurich, Futurity CC BY 4.0

Photo by Stan Hutter, Unsplash

Level A2 – High beginner / Elementary
3 min
174 words

Many people use password managers because most users have between 100 and 200 passwords and cannot remember them all. Cloud-based managers let users reach their passwords from different devices and share them with family members. Security is critical because these services store sensitive data, including online banking and credit card logins, in encrypted vaults.

Researchers from the Applied Cryptography Group at ETH Zurich studied three popular cloud-based password managers. They set up servers that acted like hacked servers and tested a malicious server threat model. The team demonstrated several attacks that could let an attacker see or change users' passwords. The attacks often used simple actions users normally perform, such as logging in, opening the vault, viewing passwords, or synchronising data.

The researchers followed responsible disclosure and contacted providers before publishing, and they gave the companies 90 days to fix the vulnerabilities. Recommendations include updating systems, offering migration choices for existing customers, and being transparent. Users should prefer managers that undergo external audits and have end-to-end encryption enabled by default.

Difficult words

  • password managerA tool that stores many login details.
    password managers
  • cloud-basedA service that runs on internet servers.
  • encryptTo change data so others cannot read.
    encrypted
  • vaultA secure place to keep digital passwords.
    vaults
  • vulnerabilityA weakness that attackers could use.
    vulnerabilities
  • synchroniseTo make the same data on different devices.
    synchronising

Tip: hover, focus or tap highlighted words in the article to see quick definitions while you read or listen.

Discussion questions

  • Do you use a password manager? Why or why not?
  • What would make you trust a cloud-based password manager?
  • How many passwords do you have, and how do you remember them?

Related articles

Why Rechargeable Batteries Lose Performance — Level A2
20 Dec 2025

Why Rechargeable Batteries Lose Performance

Researchers found that repeated charging and discharging makes batteries expand and contract, causing tiny shape changes and stress. This “chemomechanical degradation” and spreading strain reduce performance and shorten battery life, and imaging revealed how it happens.