That Was Then, This Is Now: A Security Evaluation of Password Generation, Storage, and Autofill in Browser-Based Password Managers
Sean Oesch, Scott Ruoti
摘要
Password managers have the potential to help users more effectively manage their passwords and address many of the concerns surrounding password-based authentication, however prior research has identified significant vulnerabilities in existing password managers. Since that time, five years has passed, leaving it unclear whether password managers remain vulnerable or whether they are now ready for broad adoption. To answer this question, we evaluate thirteen popular password managers and consider all three stages of the password manager lifecycle--password generation, storage, and autofill. Our evaluation is the first analysis of password generation in password managers, finding several non-random character distributions and identifying instances where generated passwords were vulnerable to online and offline guessing attacks. For password storage and autofill, we replicate past evaluations, demonstrating that while password managers have improved in the half-decade since those prior evaluations, there are still significant issues, particularly with browser-based password managers; these problems include unencrypted metadata, unsafe defaults, and vulnerabilities to clickjacking attacks. Based on our results, we identify password managers to avoid, provide recommendations on how to improve existing password managers, and identify areas of future research.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper24
- They Would do Better if They Worked Together: The Case of Interaction Problems Between Password Managers and WebsitesNicolas Huaman, Sabrina Amft, Marten Oltrogge, Yasemin Acar 等S&P 2021 · 被引用 37 次
- Automated Detection of Password Leakage from Public GitHub RepositoriesRunhan Feng, Ziyang Yan, Shiyan Peng, Yuanyuan ZhangICSE 2022 · 被引用 36 次
- "It Basically Started Using Me: " An Observational Study of Password Manager UsageSean Oesch, Scott Ruoti, James Simmons, Anuj GautamCHI 2022 · 被引用 21 次
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- The Double Edged Sword: Identifying Authentication Pages and their Fingerprinting BehaviorAsuman Senol, Alisha Ukani, Dylan Cutler, Igor BilogrevicWWW 2024 · 被引用 14 次
它引用的顶会 Paper4
- zxcvbn: Low-Budget Password Strength EstimationDaniel Lowe WheelerUSENIX Security 2016 · 被引用 243 次
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib 等CCS 2017 · 被引用 168 次
- Better managed than memorized? Studying the Impact of Managers on Password Strength and ReuseSanam Ghorbani Lyastani, Michael Schilling, Sascha Fahl, Michael Backes 等USENIX Security 2018 · 被引用 63 次
- How to End Password Reuse on the WebKe Coby Wang, Michael K. ReiterNDSS 2019 · 被引用 49 次
相关 Paper
- Vault Raider: Stealthy UI-based Attacks Against Password Managers in Desktop EnvironmentsAndrea Infantino, Mir Masood Ali, Kostas Solomos, Jason PolakisNDSS 2026 · 被引用 1 次
- Security Analysis of Master-Password-Protected Password Management ProtocolsYihe Duan, Ding Wang, Yanduo FuS&P 2025
- A Large-Scale Survey of Password Entry Practices on Non-Desktop DevicesJohn Sadik, Scott RuotiUbiComp 2025 · 被引用 2 次
- Passwords and FIDO2 Are Meant To Be Secret: A Practical Secure Authentication Channel for Web BrowsersAnuj Gautam, Tarun Kumar Yadav, Garrett Smith, Kent E. Seamons 等CCS 2025
- Phishing Attacks against Password Manager Browser ExtensionsClaudio Anliker, Daniele Lain, Srdjan CapkunUSENIX Security 2025
