A Security Analysis of Password Managers on Android

被引:1
|
作者
Sharma, Abhyudaya [1 ]
Mishra, Sweta [1 ]
机构
[1] Shiv Nadar Univ, Greater Noida, India
来源
INFORMATION SYSTEMS SECURITY, ICISS 2023 | 2023年 / 14424卷
关键词
password manager; android; security; reverse engineering;
D O I
10.1007/978-3-031-49099-6_1
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Password Managers are software tools designed to help users easily store and access credentials across devices while also reducing, if not eliminating, reuse of passwords across different service providers. Previous research has identified several security vulnerabilities with desktop and browser-based password managers; however, aside from research on possibilities of phishing, the security of password manager applications on mobile devices had never been investigated comprehensively prior to this paper. We present a study of three of the most popular password managers on the Google Play Store including but not limited to their password generators, vault and metadata storage, and autofill capabilities. By building upon past findings, we identify several weaknesses in password managers including generation of weak and statistically non-random passwords, unencrypted storage of metadata and application settings, and possibilities for credential phishing. In addition, we suggest several improvements to mobile password managers, other Android applications, and the Android operating system that can improve the user experience and security of password managers on Android devices. From our observations, we also determine areas for future research that can help improve the security of password managers.
引用
收藏
页码:3 / 22
页数:20
相关论文
共 50 条
  • [41] An Android Security Policy Enforcement Tool
    Cotterell, Kathryn
    Welch, Ian
    Chen, Aaron
    INTERNATIONAL JOURNAL OF ELECTRONICS AND TELECOMMUNICATIONS, 2015, 61 (04) : 311 - 320
  • [42] Lightweight Security Enforcement on Android Platform
    Park, Jiyeon
    Kim, Bongjae
    Min, Hong
    Cho, Yookun
    Jang, Minwoo
    Chung, Yoojin
    INFORMATION-AN INTERNATIONAL INTERDISCIPLINARY JOURNAL, 2012, 15 (07): : 2823 - 2832
  • [43] Google Android: A Comprehensive Security Assessment
    Shabtai, Asaf
    Fledel, Yuval
    Kanonov, Uri
    Elovici, Yuval
    Dolev, Shlomi
    Glezer, Chanan
    IEEE SECURITY & PRIVACY, 2010, 8 (02) : 35 - 44
  • [44] Android (Nougats) Security Issues and Solutions
    Iqbal, Shahid
    Yasin, Amber
    Naqash, Talha
    PROCEEDINGS OF 4TH IEEE INTERNATIONAL CONFERENCE ON APPLIED SYSTEM INNOVATION 2018 ( IEEE ICASI 2018 ), 2018, : 1152 - 1155
  • [45] Android Security Overview: A Systematic Survey
    Xia, Xuwei
    Qian, Chen
    Liu, Bo
    2016 2ND IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND COMMUNICATIONS (ICCC), 2016, : 2805 - 2809
  • [46] A SmartWatch-based Password Input Extension for Android
    Gao, Bohao
    Mu, Qing
    Zhang, Quanxin
    Li, Yuanzhang
    Tan, Yuan
    PROCEEDINGS OF THE 2014 INTERNATIONAL CONFERENCE ON MECHATRONICS, ELECTRONIC, INDUSTRIAL AND CONTROL ENGINEERING, 2014, 5 : 255 - 259
  • [47] Security Mechanism for Android Cloud Computing
    Archana, R.
    Mythili, C.
    Kalyani, S. Nithya
    2015 GLOBAL CONFERENCE ON COMMUNICATION TECHNOLOGIES (GCCT), 2015, : 133 - 138
  • [48] A Multi-Tier Security Analysis of Official Car Management Apps for Android
    Chatzoglou, Efstratios
    Kambourakis, Georgios
    Kouliaridis, Vasileios
    FUTURE INTERNET, 2021, 13 (03): : 1 - 35
  • [49] Android Apps Security Assessment using Sentiment Analysis Techniques: Comparative Study
    Aljumah A.
    Altuwijri A.
    Alsuhaibani T.
    Selmi A.
    Alruhaily N.
    International Journal of Interactive Mobile Technologies, 2021, 15 (24) : 123 - 133
  • [50] Security Analysis Testing for Secure Instant Messaging in Android with Study Case: Telegram
    Candra, Aditya
    Kurniawan, Yusuf
    Rhee, Kyung-Hyune
    PROCEEDINGS OF THE 2016 6TH INTERNATIONAL CONFERENCE ON SYSTEM ENGINEERING AND TECHNOLOGY (ICSET), 2016, : 93 - 97