CRMar 4, 2020

Revisiting Security Vulnerabilities in Commercial Password Managers

arXiv:2003.01985v20.00
AI Analysis25

This work addresses security risks for users of commercial password managers, though it is incremental as it builds on prior vulnerability analyses.

The researchers analyzed five commercial password managers for security vulnerabilities, finding a mix of fixed and persisting issues from past disclosures and identifying four new vulnerabilities, including one that allows malicious app impersonation to steal passwords in two out of five managers.

In this work we analyse five popular commercial password managers for security vulnerabilities. Our analysis is twofold. First, we compile a list of previously disclosed vulnerabilities through a comprehensive review of the academic and non-academic sources and test each password manager against all the previously disclosed vulnerabilities. We find a mixed picture of fixed and persisting vulnerabilities. Then we carry out systematic functionality tests on the considered password managers and find four new vulnerabilities. Notably, one of the new vulnerabilities we identified allows a malicious app to impersonate a legitimate app to two out of five widely-used password managers we tested and as a result steal the user's password for the targeted service. We implement a proof-of-concept attack to show the feasibility of this vulnerability in a real-life scenario. Finally, we report and reflect on our experience of responsible disclosure of the newly discovered vulnerabilities to the corresponding password manager vendors.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes