A Security Analysis of Password Managers on Android

被引:1
作者
Sharma, Abhyudaya [1 ]
Mishra, Sweta [1 ]
机构
[1] Shiv Nadar Univ, Greater Noida, India
来源
INFORMATION SYSTEMS SECURITY, ICISS 2023 | 2023年 / 14424卷
关键词
password manager; android; security; reverse engineering;
D O I
10.1007/978-3-031-49099-6_1
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Password Managers are software tools designed to help users easily store and access credentials across devices while also reducing, if not eliminating, reuse of passwords across different service providers. Previous research has identified several security vulnerabilities with desktop and browser-based password managers; however, aside from research on possibilities of phishing, the security of password manager applications on mobile devices had never been investigated comprehensively prior to this paper. We present a study of three of the most popular password managers on the Google Play Store including but not limited to their password generators, vault and metadata storage, and autofill capabilities. By building upon past findings, we identify several weaknesses in password managers including generation of weak and statistically non-random passwords, unencrypted storage of metadata and application settings, and possibilities for credential phishing. In addition, we suggest several improvements to mobile password managers, other Android applications, and the Android operating system that can improve the user experience and security of password managers on Android devices. From our observations, we also determine areas for future research that can help improve the security of password managers.
引用
收藏
页码:3 / 22
页数:20
相关论文
共 37 条
[1]   Users are not the enemy [J].
Adams, A ;
Sasse, MA .
COMMUNICATIONS OF THE ACM, 1999, 42 (12) :41-46
[2]  
Android Developers, 2021, Autofill framework
[3]  
Android Developers, 2021, Application fundamentals
[4]  
Android Developers, 2022, Android keystore system
[5]  
[Anonymous], 2012, Consumer survey: Password habits
[6]   Phishing Attacks on Modern Android [J].
Aonzo, Simone ;
Merlo, Alessio ;
Tavella, Giulio ;
Fratantonio, Yanick .
PROCEEDINGS OF THE 2018 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'18), 2018, :1788-1801
[7]  
Bakry T.H., 2020, Popular iPhone and iPad apps snooping on the pasteboard
[8]  
Bitwarden Inc, 2021, How BitwardenWorks
[9]  
Broida R., 2021, Need a LastPass alternative? This is the best free password manager we've found
[10]  
Business Wire Inc, 2021, Bitwarden Selected as Best Password Manager by US News & World Report