Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Major Security Vulnerability Found in Top Password Managers for Windows 10
#1
Quote:The Independent Security Evaluators (ISE) conducted a security audit of 1Password, Dashlane, KeePass, and LastPass on Windows 10, and the results are worrying, to say the least.

All of them keep the master password in plaintext in the PC memory, which means a hacker with access to the computer could easily read it and then get access to all the data stored in the password manager.

The master password is the key that is being used by password managers to guard the application, and users are required to provide it whenever they want to unlock it.

Security researchers discovered that this master password remains in the memory of the device in plaintext as long as the password manager itself is in a locked state. This means the password manager has already been launched, unlocked, and then locked automatically for security reasons.

“Using a proprietary, reverse engineering, tool, ISE analysts were able to quickly evaluate the password managers’ handling of secrets in its locked state. ISE found that standard memory forensics can be used to extract the master password and the secrets it’s supposed to guard,” researchers explain.

SOURCE: https://news.softpedia.com/news/major-se...5028.shtml
[-] The following 4 users say Thank You to silversurfer for this post:
  • darktwilight, Der.Reisende, dinosaur07, harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
F-Secure 19.4
What's new in the ...harlan4096 — 09:44
Thunderbird Supernova 115.10.1
Thunderbird Supern...harlan4096 — 09:41
Microsoft Edge 124.0.2478.51
Version 124.0.2478...harlan4096 — 09:40
Rogue Anti-Malware 15.16.1
V15.16.1 04/12/202...harlan4096 — 09:39
Intel Xeon 6 6980P “Granite Rapids-AP” C...
Intel Xeon 6 specs...harlan4096 — 09:37

[-]
Birthdays
Today's Birthdays
avatar (36)RobertUtelt
Upcoming Birthdays
avatar (43)wapedDow
avatar (42)techlignub
avatar (41)Stevenmam
avatar (48)onlinbah
avatar (49)steakelask
avatar (43)Termoplenka
avatar (41)bycoPaist
avatar (47)pieloKat
avatar (41)ilyagNeexy
avatar (49)donitascene
avatar (49)Toligo

[-]
Online Staff
There are no staff members currently online.

>