A Security Analysis of Password Managers on Android

被引:1
|
作者
Sharma, Abhyudaya [1 ]
Mishra, Sweta [1 ]
机构
[1] Shiv Nadar Univ, Greater Noida, India
来源
INFORMATION SYSTEMS SECURITY, ICISS 2023 | 2023年 / 14424卷
关键词
password manager; android; security; reverse engineering;
D O I
10.1007/978-3-031-49099-6_1
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Password Managers are software tools designed to help users easily store and access credentials across devices while also reducing, if not eliminating, reuse of passwords across different service providers. Previous research has identified several security vulnerabilities with desktop and browser-based password managers; however, aside from research on possibilities of phishing, the security of password manager applications on mobile devices had never been investigated comprehensively prior to this paper. We present a study of three of the most popular password managers on the Google Play Store including but not limited to their password generators, vault and metadata storage, and autofill capabilities. By building upon past findings, we identify several weaknesses in password managers including generation of weak and statistically non-random passwords, unencrypted storage of metadata and application settings, and possibilities for credential phishing. In addition, we suggest several improvements to mobile password managers, other Android applications, and the Android operating system that can improve the user experience and security of password managers on Android devices. From our observations, we also determine areas for future research that can help improve the security of password managers.
引用
收藏
页码:3 / 22
页数:20
相关论文
共 50 条
  • [31] Security Analysis Method of Recognition-based Graphical Password
    Khodadadi, Touraj
    Alizadeh, Mojtaba
    Gholizadeh, Somayyeh
    Zamani, Mazdak
    Darvishi, Mahdi
    JURNAL TEKNOLOGI, 2015, 72 (05):
  • [32] Towards Formal Analysis of the Permission-based Security Model for Android
    Shin, Wook
    Kiyomoto, Shinsaku
    Fukushima, Kazuhide
    Tanaka, Toshiaki
    ICWMC: 2009 FIFTH INTERNATIONAL CONFERENCE ON WIRELESS AND MOBILE COMMUNICATIONS, 2009, : 87 - 92
  • [33] Breaking into the vault: Privacy, security and forensic analysis of Android vault applications
    Zhang, Xiaolu
    Baggili, Ibrahim
    Breitinger, Frank
    COMPUTERS & SECURITY, 2017, 70 : 516 - 531
  • [34] A Comparative Usability Evaluation of Traditional Password Managers
    Karole, Ambarish
    Saxena, Nitesh
    Christin, Nicolas
    INFORMATION SECURITY AND CRYPTOLOGY - ICISC 2010, 2011, 6829 : 233 - +
  • [35] Security Analysis of Mobile Money Applications on Android
    Darvish, Hesham
    Husain, Mohammad
    2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, : 3072 - 3078
  • [36] A Survey Paper on Vulnerabilities in Android OS and Security of Android Devices
    Meshram, P. D.
    Thool, R. C.
    2014 IEEE GLOBAL CONFERENCE ON WIRELESS COMPUTING AND NETWORKING (GCWCN), 2014, : 174 - 178
  • [37] Password Security as a Game of Entropies
    Rass, Stefan
    Koenig, Sandra
    ENTROPY, 2018, 20 (05)
  • [38] Security Evaluation for Graphical Password
    Lashkari, Arash Habibi
    Manaf, Azizah Abdul
    Masrom, Maslin
    Daud, Salwani Mohd
    DIGITAL INFORMATION AND COMMUNICATION TECHNOLOGY AND ITS APPLICATIONS, PT I, 2011, 166 : 431 - +
  • [39] METHOD OF PASSWORD SECURITY EVALUATION
    Hub, Miloslav
    Capek, Jan
    DCABES 2009: THE 8TH INTERNATIONAL SYMPOSIUM ON DISTRIBUTED COMPUTING AND APPLICATIONS TO BUSINESS, ENGINEERING AND SCIENCE, PROCEEDINGS, 2009, : 401 - 405
  • [40] Studying Security Weaknesses of Android System
    Park, Jae-Kyung
    Choi, Sang-Yong
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2015, 9 (03): : 7 - 12