Credential Extraction Attacks Against Compromised Credential Checking Services of Password Managers
Yihe Duan, Ding Wang, Yutong Li
摘要
Password managers (PMs) are highly recommended by security standards and experts to assist users in managing their login credentials. In response to the increasingly serious threat of credential leakages, more and more leading PMs start to leverage third-party compromised credential checking (C3) services, aiming to help users check whether their credentials in the vault have been leaked. C3 services (e.g., Have I Been Pwned) generally maintain extensive datasets of leaked credentials and provide APIs for compromised credential checking. Queries to C3 services comply with -anonymity security properties, designed to limit information leakage about credentials. However, these queries are deterministic, indicating that identical credentials consistently generate the same query. We find that PMs exhibit identifiable query patterns, such as automatically checking all credentials associated with a single user, and periodically checking users' credentials. We, for the first time, demonstrate that the query patterns of PMs can be effectively exploited by an honest-but-curious C3 server to identify PM users and extract credentials. We propose a novel credential extraction attack framework based on query pattern leakage to C3 services, and implement attack algorithms targeting PMs' query patterns. Our empirical attacks successfully identify of PM users. Furthermore, this query pattern leakage enables attackers to significantly increase the password guessing success rates by with one guess, compared to attacks without leveraging this leakage. We evaluate 14 leading PMs, and find that 10 are vulnerable to our attacks. We have disclosed our findings along with recommendations to affected vendors for being aware of (and mitigating) these vulnerabilities.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper18
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan 等CCS 2016 · 被引用 385 次
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib 等CCS 2017 · 被引用 168 次
- Protecting accounts from credential stuffing with password breach alertingKurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan 等USENIX Security 2019 · 被引用 154 次
- Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksBijeeta Pal, Tal Daniel, Rahul Chatterjee, Thomas RistenpartS&P 2019 · 被引用 100 次
- Protocols for Checking Compromised CredentialsLucy Li, Bijeeta Pal, Junade Ali, Nick Sullivan 等CCS 2019 · 被引用 80 次
相关 Paper
- Might I Get Pwned: A Second Generation Compromised Credential Checking ServiceBijeeta Pal, Mazharul Islam, Marina Sanusi Bohuk, Nick Sullivan 等USENIX Security 2022
- Breach Extraction Attacks: Exposing and Addressing the Leakage in Second Generation Compromised Credential Checking ServicesDario Pasquini, Danilo Francati, Giuseppe Ateniese, Evgenios M. KornaropoulosS&P 2024 · 被引用 3 次
- Security Analysis of Master-Password-Protected Password Management ProtocolsYihe Duan, Ding Wang, Yanduo FuS&P 2025
- Exploiting Leakage in Password Managers via Injection AttacksAndrés Fábrega, Armin Namavari, Rachit Agarwal, Ben Nassi 等USENIX Security 2024 · 被引用 1 次
- Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password ManagersMatteo Scarlata, Giovanni Torrisi, Matilda Backendal, Kenneth G. PatersonUSENIX Security 2026
