欢迎访问行业研究报告数据库

行业分类

当前位置:首页 > 报告详细信息

找到报告 1 篇 当前为第 1 页 共 1

用户的新密码经理:基于网络的密码管理器安全性分析

The Emperor’s New Password Manager: Security Analysis of Web-based Password Managers

作者:Zhiwei Li;Warren He;Devdatta Akhawe;Dawn Song 作者单位:EECS Department, University of California, Berkeley 加工时间:2015-04-08 信息来源:EECS 索取原文[18 页]
关键词:密码;密码保护;密码管理;安全性分析;网络
摘 要:We conduct a security analysis of five popular web-based password managers. Unlike “local” password managers, web-based password managers run in the browser. We identify four key security concerns for web-based password managers and, for each, identify representative vulnerabilities through our case studies. Our attacks are severe: in four out of the five password managers we studied, an attacker can learn a user’s credentials for arbitrary websites. We find vulnerabilities in diverse features like one-time passwords, bookmarklets, and shared passwords. The root-causes of the vulnerabilities are also diverse: ranging from logic and authorization mistakes to misunderstandings about the web security model, in addition to the typical vulnerabilities like CSRF and XSS.
内 容:
© 2016 武汉世讯达文化传播有限责任公司 版权所有 技术支持:武汉中网维优
客服中心

QQ咨询


点击这里给我发消息 客服员


电话咨询


027-87841330


微信公众号




展开客服