DEV Community

Cover image for Dashlane Discloses API Brute-Force Attack Resulting in Stolen Encrypted Vaults
BeyondMachines for BeyondMachines

Posted on • Originally published at beyondmachines.net

Dashlane Discloses API Brute-Force Attack Resulting in Stolen Encrypted Vaults

Summary

Dashlane confirmed that a brute-force attack on its device registration API allowed attackers to download encrypted password vaults from fewer than 20 personal accounts. The company implemented additional network filtering and verification layers to prevent future unauthorized device registrations.

Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)