Credential Extraction Attacks Against Compromised Credential Checking Services of Password Managers
Yihe Duan, Ding Wang, Yutong Li
Abstract
Password managers (PMs) are highly recommended by security standards and experts to assist users in managing their login credentials. In response to the increasingly serious threat of credential leakages, more and more leading PMs start to leverage third-party compromised credential checking (C3) services, aiming to help users check whether their credentials in the vault have been leaked. C3 services (e.g., Have I Been Pwned) generally maintain extensive datasets of leaked credentials and provide APIs for compromised credential checking. Queries to C3 services comply with -anonymity security properties, designed to limit information leakage about credentials. However, these queries are deterministic, indicating that identical credentials consistently generate the same query. We find that PMs exhibit identifiable query patterns, such as automatically checking all credentials associated with a single user, and periodically checking users' credentials. We, for the first time, demonstrate that the query patterns of PMs can be effectively exploited by an honest-but-curious C3 server to identify PM users and extract credentials. We propose a novel credential extraction attack framework based on query pattern leakage to C3 services, and implement attack algorithms targeting PMs' query patterns. Our empirical attacks successfully identify of PM users. Furthermore, this query pattern leakage enables attackers to significantly increase the password guessing success rates by with one guess, compared to attacks without leveraging this leakage. We evaluate 14 leading PMs, and find that 10 are vulnerable to our attacks. We have disclosed our findings along with recommendations to affected vendors for being aware of (and mitigating) these vulnerabilities.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c20b6014-a4f4-4831-941c-9c7f0e3971e2Builds on18
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan et al.CCS 2016 · 385 citations
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib et al.CCS 2017 · 168 citations
- Protecting accounts from credential stuffing with password breach alertingKurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan et al.USENIX Security 2019 · 154 citations
- Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksBijeeta Pal, Tal Daniel, Rahul Chatterjee, Thomas RistenpartS&P 2019 · 100 citations
- Protocols for Checking Compromised CredentialsLucy Li, Bijeeta Pal, Junade Ali, Nick Sullivan et al.CCS 2019 · 80 citations
Related papers
- Might I Get Pwned: A Second Generation Compromised Credential Checking ServiceBijeeta Pal, Mazharul Islam, Marina Sanusi Bohuk, Nick Sullivan et al.USENIX Security 2022
- Breach Extraction Attacks: Exposing and Addressing the Leakage in Second Generation Compromised Credential Checking ServicesDario Pasquini, Danilo Francati, Giuseppe Ateniese, Evgenios M. KornaropoulosS&P 2024 · 3 citations
- Security Analysis of Master-Password-Protected Password Management ProtocolsYihe Duan, Ding Wang, Yanduo FuS&P 2025
- Exploiting Leakage in Password Managers via Injection AttacksAndrés Fábrega, Armin Namavari, Rachit Agarwal, Ben Nassi et al.USENIX Security 2024 · 1 citation
- Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password ManagersMatteo Scarlata, Giovanni Torrisi, Matilda Backendal, Kenneth G. PatersonUSENIX Security 2026
