Password managers are a vital line of defense in the battle for internet security — which makes it all the more painful when they shit the bed.
The Kaspersky Password Manager (KPM), a free tool used to generate and manage online passwords, has long been a popular alternative to the likes of LastPass or 1Password. Unfortunately, according to security researcher Jean-Baptiste Bédrune, a bad coding decision meant that the passwords it generated weren't truly random and as a result were relatively easy to brute force — a hacking technique using specialized tools to try hundreds of thousands (or millions) of password combinations in an attempt to guess the right one.
Bédrune, who is a security researcher for the cryptocurrency hard-wallet company Ledger, writes that when generating a supposedly random password, KPM used the current time as its "single source of entropy."
While that sounds super technical, it essentially boils down to KPM using the time as the basis for its pseudo random number generator. Knowing when the password was generated, even approximately, would therefore give a hacker vital information in an attempt to crack a victim's account.
"All the passwords it created could be bruteforced in seconds," writes Bédrune.
Bédrune's team submitted the vulnerability to Kaspersky through HackerOne's bug bounty program in June of 2019, and Ledger's blog post says Kaspersky notified potentially affected users in October of 2020.
When reached for comment, Kaspersky confirmed — but downplayed — the problem identified by Bédrune.
"This issue was only possible in the unlikely event that the attacker knew the user's account information and the exact time a password had been generated," wrote a company spokesperson. "It would also require the target to lower their password complexity settings."
Kaspersky also published a security advisory detailing the flaw in April of 2021.
"Password generator was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases," read the alert. "An attacker would need to know some additional information (for example, time of password generation)."
That alert also noted that, going forward, the password manager had fixed the issue — a claim echoed by the spokesperson.
"The company has issued a fix to the product and has incorporated a mechanism that notifies users if a specific password generated by the tool could be vulnerable and needs changing."
SEE ALSO: Why you need a secret phone number (and how to get one)
So what does this mean for the average KPM user? Well, if they've been using the same KPM-generated passwords for over two years (a habit that would typically be fine), they should create new ones.
Other than that? Keep using a password manager and enable two-factor authentication.
Copyright © 2023 Powered by
A popular password manager screwed up, but there's an easy fix-雷电交加网
sitemap
文章
588
浏览
4
获赞
9
Instagram's 'Pinned Comments' feature is now available to everyone
If you're trying to inject some positivity into your Instagram posts, the new Pinned Comments featurAll hail the 2 best Halloween tweets of all time
Unfortunately, there are a lot of good tweets. And candy corn debates, scary movies, and the constanPornhub says searches for aliens and Area 51 are out of this world
There's a whole lot of talk about aliens on the internet right now, and it's even driving people toRobocalls, WeChat messages, and more spread misinformation on Election Day
It's Nov. 3, Election Day, and you know what that means: Misinformation will be flooding the interneTiger Woods won the Masters, and everybody loves a comeback
Dramatic comebacks are usually the stuff of sports movies, complete with sweeping music and tearfulApple released three iPads in 2020. Which is right for you?
It's safe to say that Apple has released a ton of products in 2020, including threenew iPads: iPad PWhat happens to Trump's Twitter account after the transfer of power?
It's been almost four years since since our first "digital" president handed over the presidential THow to clear your cache on Mac
Many of your daily computer activities — like opening programs, logging onto email, and navigaHarry and Meghan share a new pic of baby Archie for Mother's Day
Baby feet: a great way to celebrate Mother's Day.The Duke and Duchess of Sussex posted a new photo oBilly Eichner tells woman 'f*** you,' 9 years later she sends him the sweetest message
For most people, receiving a message from someone you once told "fuck you" is basically your worst nThis guy trolls his girlfriend by giving her a new forehead
Sometimes revenge is just a forehead away.Twitter user Teddy (@Tgflx) has come up with a new way toBilly Eichner tells woman 'f*** you,' 9 years later she sends him the sweetest message
For most people, receiving a message from someone you once told "fuck you" is basically your worst nMarvel Studios president has an extremely hilarious reaction to reporter's question
We're down to the wire, counting the final hours until everyone collectively lose their minds over ASee the number of U.S. COVID
Getting a window into the United States' fight against the pandemic has often felt like trying to prTwitter, Facebook, Instagram, Twitch ban Donald Trump
UPDATE: Jan. 6, 2021, 5:43 p.m. PST This post was updated to include Facebook blocking Trump for 24