29
views
0
recommends
+1 Recommend
0 collections
    0
    shares
      • Record: found
      • Abstract: found
      • Article: found
      Is Open Access

      That Was Then, This Is Now: A Security Evaluation of Password Generation, Storage, and Autofill in Thirteen Password Managers

      Preprint
      ,

      Read this article at

      Bookmark
          There is no author summary for this article yet. Authors can add summaries to their articles on ScienceOpen to make them more accessible to a non-specialist audience.

          Abstract

          Password managers have the potential to help users more effectively manage their passwords and address many of the concerns surrounding password-based authentication, however prior research has identified significant vulnerabilities in existing password managers. Since that time, five years has passed, leaving it unclear whether password managers remain vulnerable or whether they are now ready for broad adoption. To answer this question, we evaluate thirteen popular password managers and consider all three stages of the password manager lifecycle--password generation, storage, and autofill. Our evaluation is the first analysis of password generation in password managers, finding several non-random character distributions and identifying instances where generated passwords were vulnerable to online and offline guessing attacks. For password storage and autofill, we replicate past evaluations, demonstrating that while password managers have improved in the half-decade since those prior evaluations, there are still significant issues, particularly with browser-based password managers; these problems include unencrypted metadata, unsafe defaults, and vulnerabilities to clickjacking attacks. Based on our results, we identify password managers to avoid, provide recommendations on how to improve existing password managers, and identify areas of future research.

          Related collections

          Most cited references12

          • Record: found
          • Abstract: not found
          • Conference Proceedings: not found

          A large-scale study of web password habits

            Bookmark
            • Record: found
            • Abstract: not found
            • Conference Proceedings: not found

            The Quest to Replace Passwords: A Framework for Comparative Evaluation of Web Authentication Schemes

              Bookmark
              • Record: found
              • Abstract: not found
              • Conference Proceedings: not found

              The Science of Guessing: Analyzing an Anonymized Corpus of 70 Million Passwords

                Bookmark

                Author and article information

                Journal
                08 August 2019
                Article
                1908.03296
                e4a2c34e-54af-4d40-bc91-54a5eb306ddf

                http://arxiv.org/licenses/nonexclusive-distrib/1.0/

                History
                Custom metadata
                draft, under submission
                cs.CR

                Security & Cryptology
                Security & Cryptology

                Comments

                Comment on this article