sponsors
usenix conference policies
You are here
The Emperor’s New Password Manager: Security Analysis of Web-based Password Managers
Zhiwei Li, Warren He, Devdatta Akhawe, and Dawn Song, University of California, Berkeley
We conduct a security analysis of five popular web-based password managers. Unlike “local” password managers, web-based password managers run in the browser. We identify four key security concerns for web-based pass- word managers and, for each, identify representative vul- nerabilities through our case studies. Our attacks are se- vere: in four out of the five password managers we stud- ied, an attacker can learn a user’s credentials for arbi- trary websites. We find vulnerabilities in diverse features like one-time passwords, bookmarklets, and shared pass- words. The root-causes of the vulnerabilities are also di- verse: ranging from logic and authorization mistakes to misunderstandings about the web security model, in ad- dition to the typical vulnerabilities like CSRF and XSS. Our study suggests that it remains to be a challenge for the password managers to be secure. To guide future de- velopment of password managers, we provide guidance for password managers. Given the diversity of vulner- abilities we identified, we advocate a defense-in-depth approach to ensure security of password managers.
Open Access Media
USENIX is committed to Open Access to the research presented at our events. Papers and proceedings are freely available to everyone once the event begins. Any video, audio, and/or slides that are posted after the event are also free and open to everyone. Support USENIX and our commitment to Open Access.
author = {Zhiwei Li and Warren He and Devdatta Akhawe and Dawn Song},
title = {The {Emperor{\textquoteright}s} New Password Manager: Security Analysis of Web-based Password Managers},
booktitle = {23rd USENIX Security Symposium (USENIX Security 14)},
year = {2014},
isbn = {978-1-931971-15-7},
address = {San Diego, CA},
pages = {465--479},
url = {https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/li_zhiwei},
publisher = {USENIX Association},
month = aug
}
connect with us