A Security Analysis of Password Managers on Android

被引:1
|
作者
Sharma, Abhyudaya [1 ]
Mishra, Sweta [1 ]
机构
[1] Shiv Nadar Univ, Greater Noida, India
来源
INFORMATION SYSTEMS SECURITY, ICISS 2023 | 2023年 / 14424卷
关键词
password manager; android; security; reverse engineering;
D O I
10.1007/978-3-031-49099-6_1
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Password Managers are software tools designed to help users easily store and access credentials across devices while also reducing, if not eliminating, reuse of passwords across different service providers. Previous research has identified several security vulnerabilities with desktop and browser-based password managers; however, aside from research on possibilities of phishing, the security of password manager applications on mobile devices had never been investigated comprehensively prior to this paper. We present a study of three of the most popular password managers on the Google Play Store including but not limited to their password generators, vault and metadata storage, and autofill capabilities. By building upon past findings, we identify several weaknesses in password managers including generation of weak and statistically non-random passwords, unencrypted storage of metadata and application settings, and possibilities for credential phishing. In addition, we suggest several improvements to mobile password managers, other Android applications, and the Android operating system that can improve the user experience and security of password managers on Android devices. From our observations, we also determine areas for future research that can help improve the security of password managers.
引用
收藏
页码:3 / 22
页数:20
相关论文
共 50 条
  • [21] Android Vulnerabilities and Security
    Yadav, Saurav
    Apurva, Aviral
    Ranakoti, Pranshu
    Tomer, Shashank
    Roy, Nihar Ranjan
    2017 INTERNATIONAL CONFERENCE ON COMPUTING AND COMMUNICATION TECHNOLOGIES FOR SMART NATION (IC3TSN), 2017, : 204 - 208
  • [22] ByPass: Reconsidering the Usability of Password Managers
    Stobert, Elizabeth
    Safaie, Tina
    Molyneaux, Heather
    Mannan, Mohammad
    Youssef, Amr
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS (SECURECOMM 2020), PT I, 2020, 335 : 446 - 466
  • [23] The Analysis of the Security of Android Application Components
    Li, Xiu
    Li, Dai-Ping
    INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND COMMUNICATION ENGINEERING (CSCE 2015), 2015, : 1013 - 1018
  • [24] Security and Efficiency Analysis of One Time Password Techniques
    Tzemos, Ioannis
    Fournaris, Apostolos P.
    Sklavos, Nicolas
    20TH PAN-HELLENIC CONFERENCE ON INFORMATICS (PCI 2016), 2016,
  • [25] Password Managers-It's All about Trust and Transparency
    Alodhyani, Fahad
    Theodorakopoulos, George
    Reinecke, Philipp
    FUTURE INTERNET, 2020, 12 (11): : 1 - 50
  • [26] Analysis of Security Permissions on Android and iOS from a Privacy Perspective
    Luna, Carlos
    Galuppo, Raul Ignacio
    2024 L LATIN AMERICAN COMPUTER CONFERENCE, CLEI 2024, 2024,
  • [27] Android Security Issues and Solutions
    Karthick, S.
    Binu, Sumitra
    2017 INTERNATIONAL CONFERENCE ON INNOVATIVE MECHANISMS FOR INDUSTRY APPLICATIONS (ICIMIA), 2017, : 686 - 689
  • [28] The Perils of Android Security Configuration
    Vecchiato, Daniel
    Vieira, Marco
    Martins, Eliane
    COMPUTER, 2016, 49 (06) : 15 - 21
  • [29] The Android Platform Security Model
    Mayrhofer, Rene
    Vander Stoep, Jeffrey
    Brubaker, Chad
    Kralevich, Nick
    ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2021, 24 (03)
  • [30] Survey of Android OS security
    National Computer Network Intrusion Protection Center, University of Chinese Academy of Sciences, Beijing
    101408, China
    Jisuanji Yanjiu yu Fazhan, 7 (1385-1396): : 1385 - 1396