Report: Most Password Managers Not Secure
Security researchers say some major password manager tools could be flawed. But they also say it's still sensible to use them, just with a degree of caution.
It's a fact that using the same password for multiple sites is a massive security risk. That's because if one site gets hacked, it could mean that hackers can use the same password on another website to gain access to potentially sensitive information, resulting in identity theft or financial loss.
Password manager tools (such as Roboform and Dashlane) aim to overcome two big dilemmas with online passwords - which is keeping passwords unique, and trying to remember them. Remembering unique passwords becomes incredibly difficult, especially considering most users use around 20 or more websites requiring credentials on a regular basis.
The most common setup for a password manager is to act like a vault that holds all the passwords. The vault is then password protected with a master password, which can be entered by the user or unlocked using biometrics (such as a finger print sensor). Typically, the software company that develops the password manager does not have access to the passwords themselves, and the passwords are usually stored in an encrypted form.
Windows Programs At Risk
An organization known as the Independent Security Evaluators examined several major password manager services to see they followed sensible security practices. They looked at standalone Windows apps, rather than the type of password manager that requires you to login to a website (such as Dashlane).
One thing they looked at was how the computer handled password data when the apps were locked: in other words, when the user wasn't actively retrieving a password to use on a site. They discovered that with four major password managers (including: 1Password, Dashlane, KeePass, and Last Pass), passwords were sometimes left in the computer's memory.
In two cases (including: 1Password and Last Pass), researchers discovered that the master password could be exposed. (Source: securityevaluators.com)
Each of the password manager companies have given a mixed response to the report, with some saying they will continue to look for ways to tighten up potential security issues. Other claim that the potential security breaches are simply a limitation due to the way that Windows works.
Password Managers Still Worth Using
It's not necessarily a major security disaster. For a hacker to take advantage of this flaw, they'd first need either remote or physical access to a computer.
Tech experts note it's an example of security being about degrees rather than absolutes. The Washington Post uses the analogy of a seatbelt not preventing all damage in auto accidents, but is still worth using. (Source: washingtonpost.com)
It does mean users of password managers should take three steps to boost their protection and mitigate against risks:
- Close down password manager apps completely rather than leave them running, even in
"locked" mode.
- Continue to use adequate security software to protect a computer against remote hacking.
- Consider not using the password manager for the most critical login details such as email accounts and online banking.
- If in doubt, hire a professional to do a security audit of your system and/or setup your password management program properly. Dennis Faas can provide you with these services - contact link here.
What's Your Opinion?
Do you use a password manager? Does this news put you off using them? Does the public have a good understanding of levels of risk in computer security?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.
Comments
Incomplete analysis
The problems reported are only exposed if you have already been infiltrated with some other sort of exposure.
Once you have been infiltrated all security is pointless.
Online Managers vs. Private Datastore
Because of the massive security breaches perpetrated in the last decade, with millions and millions of user names and their data exposed, I have a difficult time trusting such online password managers as RoboForm and OnePass.
I am still using the password manager I began using before any of these became popular, KeePass. I don't like it a lot because it is not customizable (font size, etc.), but it uses 256-bit AES encryption, and will keep its data store wherever I want.
I DO like it a lot because it allows me to write as much in the COMMENTS field as I like, so for example, in the entry for my credit card (which I use to copy and paste the number when buying online), I can also put a list of the companies that automatically charge that card, so when I get a replacement card with a new number, I can easily see which businesses I need to log into and change the payment data.
ALSO, I keep the (encrypted) datastore file in a DropBox folder on my hard drive, and so I can get to my passwords wherever I am - desktop, laptop, tablet, or smartphone.
And finally, the price is right for this program - free.
Others may disagree, but this works for me.
Adding Additional Security to Online Password Managers
If you're concerned about the password manager site being hacked, you can add an addition layer of protection by simply adding the same few characters to each password
E.g. OmG[password1], OmG[password2]
Roboform master password could be exposed???
In your article, you state that "In three cases (including: 1Password, Last Pass and Roboform), researchers discovered that the master password could be exposed. (Source: securityevaluators.com)"
I read the article at securityevaluators.com and as you stated elsewhere in your article, 1Password, Dashlane, KeePass, and Last Pass were discussed.
Did you mean to include RoboForm in your article? It was not discussed at securityevaluators.com.
Source seems to have changed
The source for the info seems to have changed and this article has been updated.