A Security Analysis of Password Managers on Android

被引:1
|
作者
Sharma, Abhyudaya [1 ]
Mishra, Sweta [1 ]
机构
[1] Shiv Nadar Univ, Greater Noida, India
来源
关键词
password manager; android; security; reverse engineering;
D O I
10.1007/978-3-031-49099-6_1
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Password Managers are software tools designed to help users easily store and access credentials across devices while also reducing, if not eliminating, reuse of passwords across different service providers. Previous research has identified several security vulnerabilities with desktop and browser-based password managers; however, aside from research on possibilities of phishing, the security of password manager applications on mobile devices had never been investigated comprehensively prior to this paper. We present a study of three of the most popular password managers on the Google Play Store including but not limited to their password generators, vault and metadata storage, and autofill capabilities. By building upon past findings, we identify several weaknesses in password managers including generation of weak and statistically non-random passwords, unencrypted storage of metadata and application settings, and possibilities for credential phishing. In addition, we suggest several improvements to mobile password managers, other Android applications, and the Android operating system that can improve the user experience and security of password managers on Android devices. From our observations, we also determine areas for future research that can help improve the security of password managers.
引用
收藏
页码:3 / 22
页数:20
相关论文
共 50 条
  • [1] Android Password Managers and Vault Applications: Data Storage Security Issues Identification
    Sabev, P.
    Petrov, M.
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2022, 67
  • [2] The Emperor's New Password Manager: Security Analysis of Web-based Password Managers
    Li, Zhiwei
    He, Warren
    Akhawe, Devdatta
    Song, Dawn
    PROCEEDINGS OF THE 23RD USENIX SECURITY SYMPOSIUM, 2014, : 465 - 479
  • [3] A Security Analysis of Two Commercial Browser and Cloud Based Password Managers
    Zhao, Rui
    Yue, Chuan
    Sun, Kun
    2013 ASE/IEEE INTERNATIONAL CONFERENCE ON SOCIAL COMPUTING (SOCIALCOM), 2013, : 448 - 453
  • [4] An Analysis of Password Managers' Password Checkup Tools
    Hutchinson, Adryana
    Munyendo, Collins W.
    Aviv, Adam J.
    Mayer, Peter
    EXTENDED ABSTRACTS OF THE 2024 CHI CONFERENCE ON HUMAN FACTORS IN COMPUTING SYSTEMS, CHI 2024, 2024,
  • [5] Forensically-Sound Analysis of Security Risks of using Local Password Managers
    Gray, Joshua
    Franqueira, Virginia N. L.
    Yu, Yijun
    2016 IEEE 24TH INTERNATIONAL REQUIREMENTS ENGINEERING CONFERENCE WORKSHOPS (REW), 2016, : 114 - 121
  • [6] Analysis on password protection in Android applications
    Shao Shuai
    Dong Guowei
    Guo Tao
    Yang Tianchang
    Shi Chenjie
    2014 NINTH INTERNATIONAL CONFERENCE ON P2P, PARALLEL, GRID, CLOUD AND INTERNET COMPUTING (3PGCIC), 2014, : 504 - 507
  • [7] Exploiting a Bad User Practice to Retrieve Data Leakage on Android Password Managers
    Casati, Luca
    Visconti, Andrea
    INNOVATIVE MOBILE AND INTERNET SERVICES IN UBIQUITOUS COMPUTING, IMIS-2017, 2018, 612 : 952 - 958
  • [8] That Was Then, This Is Now: A Security Evaluation of Password Generation, Storage, and Autofill in Browser-Based Password Managers
    Oesch, Sean
    Ruoti, Scott
    PROCEEDINGS OF THE 29TH USENIX SECURITY SYMPOSIUM, 2020, : 2165 - 2182
  • [9] Password Security: Password Behavior Analysis at a Small University
    Awad, Mohammed
    Al-Qudah, Zakaria
    Idwan, Sahar
    Jallad, Abdul Halim
    2016 5TH INTERNATIONAL CONFERENCE ON ELECTRONIC DEVICES, SYSTEMS AND APPLICATIONS (ICEDSA), 2016,
  • [10] Does the layout of the Android unlock pattern affect the security and usability of the password?
    Zhang, Lei
    Guo, Yajun
    Guo, Xiaowei
    Shao, Xiaowei
    JOURNAL OF INFORMATION SECURITY AND APPLICATIONS, 2021, 62