In order to register new devices on fewer than 20 accounts and obtain their encrypted password vaults, attackers brute-forced Dashlane’s 2FA method. Users who use weak passwords run the danger of offline cracking, but the vaults are still secured with master passwords that Dashlane never keeps. Dashlane revealed on Sunday that an external attacker successfully circumvented 2FA safeguards on less than 20 personal plan user accounts and downloaded copies of their encrypted password vaults by launching a brute-force attack against ...