Keep Your Memory Dump Shut: Unveiling Data Leaks in Password Managers


연구 분야: Strategies



학회: IFIP International Conference on ICT Systems Security and Privacy Protection


초록

Password management has long been a persistently challenging task. This led to the introduction of password management software, which has been around for at least 25 years in various forms, including desktop and browser-based applications. This work assesses the ability of two dozen password managers, 12 desktop applications, and 12 browser plugins, to effectively protect the confidentiality of secret credentials in six representative scenarios. Our analysis focuses on the period during which a Password Manager (PM) resides in the RAM. Despite the sensitive nature of these applications, our results show that across all scenarios, only three desktop PM applications and two browser plugins do not store plaintext passwords in the system memory. Oddly enough, at the time of writing, only two vendors recognized the exploit as a vulnerability, reserving CVE-2023-23349, while the rest chose to disregard or underrate the issue.


Author Profile
Efstratios Chatzoglou

University of the Aegean 83200 Karlovasi Greece

Greece
Author Profile
Vyron Kampourakis

Norwegian University of Science and Technology 2802 Gjøvik Norway

Andorra
Author Profile
Zisis Tsiatsikas

University of the Aegean 83200 Karlovasi Greece

Greece

📄 논문 정보

발행 연도 2024년
인용수 0
출판 국가 Italy, Greece, Andorra
사이트 Springer
좋아요 수 0

연관 논문 목록 (27건)