A Security Analysis of Password Managers on Android

被引:1
|
作者
Sharma, Abhyudaya [1 ]
Mishra, Sweta [1 ]
机构
[1] Shiv Nadar Univ, Greater Noida, India
来源
INFORMATION SYSTEMS SECURITY, ICISS 2023 | 2023年 / 14424卷
关键词
password manager; android; security; reverse engineering;
D O I
10.1007/978-3-031-49099-6_1
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Password Managers are software tools designed to help users easily store and access credentials across devices while also reducing, if not eliminating, reuse of passwords across different service providers. Previous research has identified several security vulnerabilities with desktop and browser-based password managers; however, aside from research on possibilities of phishing, the security of password manager applications on mobile devices had never been investigated comprehensively prior to this paper. We present a study of three of the most popular password managers on the Google Play Store including but not limited to their password generators, vault and metadata storage, and autofill capabilities. By building upon past findings, we identify several weaknesses in password managers including generation of weak and statistically non-random passwords, unencrypted storage of metadata and application settings, and possibilities for credential phishing. In addition, we suggest several improvements to mobile password managers, other Android applications, and the Android operating system that can improve the user experience and security of password managers on Android devices. From our observations, we also determine areas for future research that can help improve the security of password managers.
引用
收藏
页码:3 / 22
页数:20
相关论文
共 50 条
  • [1] Android Password Managers and Vault Applications: Data Storage Security Issues Identification
    Sabev, P.
    Petrov, M.
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 67
  • [2] A Security Analysis of Two Commercial Browser and Cloud Based Password Managers
    Zhao, Rui
    Yue, Chuan
    Sun, Kun
    2013 ASE/IEEE INTERNATIONAL CONFERENCE ON SOCIAL COMPUTING (SOCIALCOM), 2013, : 448 - 453
  • [3] An Analysis of Password Managers' Password Checkup Tools
    Hutchinson, Adryana
    Munyendo, Collins W.
    Aviv, Adam J.
    Mayer, Peter
    EXTENDED ABSTRACTS OF THE 2024 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, CHI 2024, 2024,
  • [4] Exploiting a Bad User Practice to Retrieve Data Leakage on Android Password Managers
    Casati, Luca
    Visconti, Andrea
    INNOVATIVE MOBILE AND INTERNET SERVICES IN UBIQUITOUS COMPUTING, IMIS-2017, 2018, 612 : 952 - 958
  • [5] Usability, security and trust in password managers: A quest for user-centric properties and features
    Chaudhary, Sunil
    Schafeitel-Tahtinen, Tiina
    Helenius, Marko
    Berki, Eleni
    COMPUTER SCIENCE REVIEW, 2019, 33 : 69 - 90
  • [6] Password Security: Password Behavior Analysis at a Small University
    Awad, Mohammed
    Al-Qudah, Zakaria
    Idwan, Sahar
    Jallad, Abdul Halim
    2016 5TH INTERNATIONAL CONFERENCE ON ELECTRONIC DEVICES, SYSTEMS AND APPLICATIONS (ICEDSA), 2016,
  • [7] Does the layout of the Android unlock pattern affect the security and usability of the password?
    Zhang, Lei
    Guo, Yajun
    Guo, Xiaowei
    Shao, Xiaowei
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 62
  • [8] Android Remote Unlocking Service using Synthetic Password: A Hardware Security-preserving Approach
    Lee, Sungmin
    Jung, Yoonkyo
    Lee, Jaehyun
    Lee, Byoungyoung
    Kwon, Ted Taekyoung
    2021 IEEE SECURE DEVELOPMENT CONFERENCE (SECDEV 2021), 2021, : 63 - 70
  • [9] Security in iOS and Android: A Comparative Analysis
    Ignacio Galuppo, Raul
    Luna, Carlos
    Betarte, Gustavo
    2018 37TH INTERNATIONAL CONFERENCE OF THE CHILEAN COMPUTER SCIENCE SOCIETY (SCCC), 2018,
  • [10] An In-Depth Analysis of Password Managers and Two-Factor Authentication Tools
    Jubur, Mohammed
    Shrestha, Prakash
    Saxena, Nitesh
    ACM COMPUTING SURVEYS, 2025, 57 (05)