Case Study: Hacking Password Managers

Article note: Interesting. Some of those are reasonably low-hanging problems, most are way past the sophistication of anything but a serious targeted attack. The relatively good performance of KeePass does provide further evidence for my "I want my password manager to have as little surface area as possible" principle. You can't have network and plugin leaks if the features aren't there.
