A security analysis of two commercial Browser and Cloud based Password Managers

Rui Zhao, Chuan Yue, Kun Sun

Research output: Chapter in Book/Report/Conference proceedingConference contribution

5 Scopus citations

Abstract

In this paper, we analyze the security of two very popular commercial password managers: LastPass and RoboForm. Both of them are Browser and Cloud based Password Managers (BCPMs), and both of them have millions of active users worldwide. We investigate the security design and implementation of these two BCPMs with the focus on their underlying cryptographic mechanisms. We identify several vulnerabilities that could be exploited by outsider and insider attackers to break the security of these two BCPMs.

Original languageEnglish (US)
Title of host publicationProceedings - SocialCom/PASSAT/BigData/EconCom/BioMedCom 2013
Pages448-453
Number of pages6
DOIs
StatePublished - 2013
Externally publishedYes
Event2013 ASE/IEEE Int. Conf. on Social Computing, SocialCom 2013, the 2013 ASE/IEEE Int. Conf. on Big Data, BigData 2013, the 2013 Int. Conf. on Economic Computing, EconCom 2013, the 2013 PASSAT 2013, and the 2013 ASE/IEEE Int. Conf. on BioMedCom 2013 - Washington, DC, United States
Duration: Sep 8 2013Sep 14 2013

Publication series

NameProceedings - SocialCom/PASSAT/BigData/EconCom/BioMedCom 2013

Conference

Conference2013 ASE/IEEE Int. Conf. on Social Computing, SocialCom 2013, the 2013 ASE/IEEE Int. Conf. on Big Data, BigData 2013, the 2013 Int. Conf. on Economic Computing, EconCom 2013, the 2013 PASSAT 2013, and the 2013 ASE/IEEE Int. Conf. on BioMedCom 2013
Country/TerritoryUnited States
CityWashington, DC
Period9/8/139/14/13

Keywords

  • Browser
  • Cloud
  • Password manager
  • Security

ASJC Scopus subject areas

  • Software

Fingerprint

Dive into the research topics of 'A security analysis of two commercial Browser and Cloud based Password Managers'. Together they form a unique fingerprint.

Cite this