• Sign in
  • Sign up
Elektrine
EN
  • EN English
  • 中 中文
Log in Register
Modes
Overview Search Chat Timeline Communities Gallery Lists Friends Email Vault VPN
Back to Timeline
  • Open on infosec.exchange

Wladimir Palant

@WPalant@infosec.exchange
mastodon 4.6.0-alpha.5+glitch

Software developer and security researcher, browser extensions expert. / searchable

#infosec #cybersecurty #cryptography #privacy

0 Followers
0 Following
Joined August 21, 2018
Website:
https://palant.info/
Pronouns:
He/him

Posts

WPalant
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable # infosec # cybersecurty # cryptography # privacy

infosec.exchange
Wladimir Palant
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable # infosec # cybersecurty # cryptography # privacy

infosec.exchange
@WPalant@infosec.exchange · Mar 02, 2026

Google sent me a mail to tell me how my website was doing. Took me a moment to realize that this wasn’t a glitch in their data.

View on infosec.exchange
6
0
1
0
WPalant
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable # infosec # cybersecurty # cryptography # privacy

infosec.exchange
Wladimir Palant
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable # infosec # cybersecurty # cryptography # privacy

infosec.exchange
@WPalant@infosec.exchange · Feb 18, 2026

Note how LastPass PR offloaded a ton of buzzwords here that don’t actually mean anything. They turned this kind of responses into an art. https://arstechnica.com/security/2026/02/password-managers-promise-that-they-cant-see-your-vaults-isnt-always-true/

Bitwarden at least admits that a fully compromised server isn’t part of their threat model. It’s the same for LastPass, and in the past they’ve rejected vulnerability submissions based on that – there are a number of very simple ways in which a compromised server is able to access your “secure” vault. But they won’t admit it, hoping instead that the message will drown in the noise they produce.

For the sake of completeness: Dashlane’s response is merely generic. 1Password’s response is correct from what I can tell: the “compromised server” scenario has been considered and the risks arising from it are documented, nothing new here.

#LastPass #infosec

View on infosec.exchange
27
0
20
0
WPalant
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable # infosec # cybersecurty # cryptography # privacy

infosec.exchange
Wladimir Palant
Wladimir Palant
@WPalant@infosec.exchange

Software developer and security researcher, browser extensions expert. / searchable # infosec # cybersecurty # cryptography # privacy

infosec.exchange
@WPalant@infosec.exchange · Feb 18, 2026

RE: @soatok@furry.engineer

This is old news for some but way too many people didn’t get the memo: do not trust Matrix crypto. It’s not that they have issues (who doesn’t), it’s their approach which is the opposite of taking security seriously.

#Matrix #MatrixMessenger #infosec

View on infosec.exchange
8
0
6
0

Media

313k7r1n3

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • VPN Policy

Email Settings

IMAP: imap.elektrine.com:993

POP3: pop.elektrine.com:995

SMTP: smtp.elektrine.com:465

SSL/TLS required

Support

  • support@elektrine.com
  • Report Security Issue

Connect

Tor Hidden Service

khav7sdajxu6om3arvglevskg2vwuy7luyjcwfwg6xnkd7qtskr2vhad.onion
© 2026 Elektrine. All rights reserved. • Server: 13:26:06 UTC