A Security Analysis of Password Managers on Android

被引:1
|
作者
Sharma, Abhyudaya [1 ]
Mishra, Sweta [1 ]
机构
[1] Shiv Nadar Univ, Greater Noida, India
来源
关键词
password manager; android; security; reverse engineering;
D O I
10.1007/978-3-031-49099-6_1
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Password Managers are software tools designed to help users easily store and access credentials across devices while also reducing, if not eliminating, reuse of passwords across different service providers. Previous research has identified several security vulnerabilities with desktop and browser-based password managers; however, aside from research on possibilities of phishing, the security of password manager applications on mobile devices had never been investigated comprehensively prior to this paper. We present a study of three of the most popular password managers on the Google Play Store including but not limited to their password generators, vault and metadata storage, and autofill capabilities. By building upon past findings, we identify several weaknesses in password managers including generation of weak and statistically non-random passwords, unencrypted storage of metadata and application settings, and possibilities for credential phishing. In addition, we suggest several improvements to mobile password managers, other Android applications, and the Android operating system that can improve the user experience and security of password managers on Android devices. From our observations, we also determine areas for future research that can help improve the security of password managers.
引用
收藏
页码:3 / 22
页数:20
相关论文
共 50 条
  • [21] Fine with "1234"? An Analysis of SMS On Time Password Randomness in Android Apps
    Ma, Siqi
    Li, Juanru
    Kim, Hyoungshick
    Bertino, Elisa
    Nepal, Surya
    Ostry, Diethelm
    Sun, Cong
    2021 IEEE/ACM 43RD INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE 2021), 2021, : 1671 - 1682
  • [22] SpanDex: Secure Password Tracking for Android
    Cox, Landon P.
    Gilbert, Peter
    Lawler, Geoffrey
    Pistol, Valentin
    Razeen, Ali
    Wu, Bi
    Cheemalapati, Sai
    PROCEEDINGS OF THE 23RD USENIX SECURITY SYMPOSIUM, 2014, : 481 - 494
  • [23] Security Analysis of Password-Authenticated Key Retrieval
    Shin, SeongHan
    Kobara, Kazukuni
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2017, 14 (05) : 573 - 576
  • [24] Security in iOS and Android: A Comparative Analysis
    Ignacio Galuppo, Raul
    Luna, Carlos
    Betarte, Gustavo
    2018 37TH INTERNATIONAL CONFERENCE OF THE CHILEAN COMPUTER SCIENCE SOCIETY (SCCC), 2018,
  • [25] The Analysis of the Security of Android Application Components
    Li, Xiu
    Li, Dai-Ping
    INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND COMMUNICATION ENGINEERING (CSCE 2015), 2015, : 1013 - 1018
  • [26] ByPass: Reconsidering the Usability of Password Managers
    Stobert, Elizabeth
    Safaie, Tina
    Molyneaux, Heather
    Mannan, Mohammad
    Youssef, Amr
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS (SECURECOMM 2020), PT I, 2020, 335 : 446 - 466
  • [27] Security Analysis of OnlineCabBooking Android Application
    Grover, Nishant
    Saxena, Jyotsna
    Sihag, Vikas
    PROCEEDINGS OF THE INTERNATIONAL CONFERENCE ON DATA ENGINEERING AND COMMUNICATION TECHNOLOGY, ICDECT 2016, VOL 1, 2017, 468 : 603 - 611
  • [28] Analysis and research of android security system
    Zheng, Ling
    Liu, Yanjiao
    ADVANCES IN ENERGY, ENVIRONMENT AND MATERIALS SCIENCE, 2016, : 735 - 739
  • [29] Security analysis of secure password authentication for keystroke dynamics
    Song, Hyunsoo
    Kwon, Taekyoung
    KNOWLEDGE-BASED INTELLIGENT INFORMATION AND ENGINEERING SYSTEMS, PT 1, PROCEEDINGS, 2006, 4251 : 916 - 923
  • [30] A STUDY OF PASSWORD SECURITY
    LUBY, M
    RACKOFF, C
    LECTURE NOTES IN COMPUTER SCIENCE, 1988, 293 : 392 - 397