Severe Vulnerabilities Uncovered In Popular Password Managers

Peter Reutemann <[email protected]>
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12Khv8kWut082L71HRCDVQrUAVgh7QXpY4CPRyvzARceBQ@mail.gmail.com>
Not sure whether this also applies to the Linux/cross-platform versions...

'Independent Security Evaluators (ISE) published an assessment on
Tuesday with the results of testing with several popular password
managers, including LastPass and KeePass. The team said that each
password management solution "failed to provide the security to
safeguard a user's passwords as advertised" and "fundamental flaws"
were found that "exposed the data they are designed to protect."

The vulnerabilities were found in software operating on Windows 10
systems. In one example, the master password which users need to use
to access their cache of credentials was stored in PC RAM in a
plaintext, readable format. ISE was able to extract these passwords
and other login credentials from memory while the password manager in
question was locked. It may be possible that malicious programs
downloaded to the same machine by threat actors could do the same.

The report has summarized the main findings based on each password
management solution. Here's what ISE had to say about LastPass and
KeePass -- two of the most popular password managers available:

"LastPass obfuscates the master password while users are typing in the
entry, and when the password manager enters an unlocked state,
database entries are only decrypted into memory when there is user
interaction. However, ISE reported that these entries persist in
memory after the software enters a locked state. It was also possible
for the researchers to extract the master password and interacted-with
password entries due to a memory leak."

"KeePass scrubs the master password from memory and is not
recoverable. However, errors in workflows permitted the researchers
from extracting credential entries which have been interacted with. In
the case of Windows APIs, sometimes, various memory buffers which
contain decrypted entries may not be scrubbed correctly."'

-- source: https://it.slashdot.org/story/19/02/21/070204

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list | [email protected]
Unsubscribe: https://list.waikato.ac.nz/mailman/listinfo/wlug
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.