Select your language

Cybersecurity: Critical flaws found in password managers

International. Even though security experts refrain from using password managers, a new report from Independent Security Evaluators (ISE) has found that several of the most popular applications have fundamental flaws that expose data that make them more secure than saving passwords on a network. plain text file.

The new report titled "Under the Hood of Secrets Management," revealed serious weaknesses with the top password managers: 1Password, Dashlane, KeePass, and LastPass. IsE researchers said they examined the underlying functionality of these products in Windows 10 to understand how users' secrets are stored even when the password manager is locked. The report indicates that more than 60 million individuals, 93,000 companies worldwide trust password managers.

"One hundred percent of the products ISE analyzed did not provide the security to safeguard users' passwords as advertised," said Stephen Bono, CEO. "Although password managers provide some utility for storing login/passwords and limit password reuse, these apps are a vulnerable target for mass collection of this data through malicious hacking campaigns."

One of the report's main findings was that, in certain cases, the master password resided in the computer's memory in a readable format of simple text: one method, which the report claims, is no more secure than storing it in a document or on the desktop as far as an adversary is concerned. Users believe the information is secure when the password manager is locked, the researchers argue. However, once the master password is available to the attacker, they can decrypt the password manager database, stored secrets, usernames, and passwords. ISE demonstrated that it is possible to extract master passwords and other login credentials from memory while the password manager was locked.

- Publicidad -

By using a proprietary reverse engineering tool, ISE analysts said they could quickly assess the handling of password managers' secrets in their locked state. ISE found that standard forensics memory can be used to extract the master password and secrets it is supposed to hold.

"Given the huge user base of people already using password managers, these vulnerabilities will prompt hackers to identify and steal data from these computers through malware attacks," said Adrian Bednarek, principal investigator at ISE. "Once they have your master password, the game is over."

"People believe that using password managers makes their data safer and more secure on their computer," said Ted Harrington, executive partner at ISE. "Our research provides a public service to the providers of these widely adopted products who must now mitigate attacks based on discovered security issues, as well as alert consumers who have a false sense of security about their effectiveness."

The report recommends that to keep secrets more secure until vendors troubleshoot the issues, password manager users should not leave the password manager running in the background, even in a locked state, and end the process entirely if they are using one of the affected password managers. .

The report, ISE said, is part of its ongoing research initiative to protect consumers and businesses and inform manufacturers about vulnerabilities that could expose their customers to risks. All vulnerabilities and relevant research findings have been responsibly disclosed to manufacturers, the company said.

Source: TechCentral.

Duván Chaverra Agudelo
Duván Chaverra AgudeloEmail: [email protected]
Editor Jefe
Jefe Editorial en Latin Press, Inc,. Comunicador Social y Periodista con experiencia de más de 13 años en medios de comunicación. Apasionado por la tecnología.

No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter