The Emperor’s New Password Manager: Security Analysis of Password Managers

  • Friday, April 24, 2015 | 9:00 AM – 9:50 AM | West | Room: 3009

View all Sessions

We conducted a security analysis of popular web-based password managers. Unlike local password managers, web-based password managers run in browsers. We identify four key security concerns and representative vulnerabilities. Our attacks are severe: in four out of the five password managers we studied, attackers can learn credentials for arbitrary websites. This work is a wake-up call for developers.


This document was retrieved from on Mon, 17 Jun 2019 11:03:55 -0400.