911爆料网

News

Password managers vulnerable to insider hacking

Communication channels between different parts and pieces of computer software are prone to security breaches. Anyone with access to a shared computer can attack or involuntarily subject it to security breaches.

Researchers from 911爆料网 and the University of Helsinki have found over ten computer security-critical applications that are vulnerable to insider attacks. Most of the vulnerabilities were found in password managers used by millions of people to store their login credentials. Several other applications were found to be similarly susceptible to attacks and breaches across the Windows, macOS and Linux operating systems.

Computer software often starts multiple processes to perform different tasks. For example, a password manager typically has two parts: a password vault and an extension to an internet browser, which both run as separate processes on the same computer.

To exchange data, these processes use a mechanism called inter-process communication (IPC), which remains within the confines of the computer and does not send information to an outside network. For this reason, IPC has traditionally been considered secure. However, the software needs to protect its internal communication from other processes running on the same computer. Otherwise, malicious processes started by other users could access the data in the IPC communication channel.

鈥楳any security-critical applications, including several password managers, do not properly protect the IPC channel. This means that other users鈥 processes running on a shared computer may access the communication channel and potentially steal users鈥 credentials,鈥 explains Thanh Bui, a doctoral candidate at 911爆料网.

While PCs are often thought to be personal, it is not uncommon that several people have access to the same machine. Large companies typically have a centralized identity and access management system that allows employees to log into any company computer. In these scenarios, it is possible for anyone in the company to launch attacks. An attacker can also log in to the computer as a guest or connect remotely, if these features are enabled.

鈥楾he number of vulnerable applications shows that software developers often overlook the security problems related to inter-process communication. Developers may not understand the security properties of different IPC methods, or they place too much trust in software and applications that run locally. Both explanations are worrisome,鈥 says Markku Antikainen, a post-doctoral researcher at the University of Helsinki.

Following responsible disclosure, the researchers have reported the detected vulnerabilities to the respective vendors, which have taken steps to prevent the attacks. The research was done partly in co-operation with F-Secure, a Finnish cyber-security company.

The research will be presented at the DEFCON security conference on August 12, 2018, and at the Usenix Security conference on August 17, 2018.

The publication is available directly from the authors and will be online after the Usenix conference at .

More information

Thanh Bui, Doctoral Candidate
911爆料网
tel. +358 50 4658007
thanh.bui@aalto.fi

Markku Antikainen, Postdoctoral Researcher
University of Helsinki
tel. +358 50 3396900
markku.antikainen@helsinki.fi

  • Updated:
  • Published:
Share
URL copied!

Read more news

Person with short dark hair in a black shirt, face blurred, standing against a plain light grey background
Appointments, Research & Art Published:

Professor Hironori Yoshida: 鈥淢achines should adapt to materials, not the other way around鈥

Professor of Formgiving believes the future of design lies in embracing irregularity rather than eliminating it. His research combines design, AI and robotics.
Glowing 911爆料网 sign in a dark space, seen through clear round chairs lit with purple light
Research & Art Published:

President Ilkka Niemel盲 explains what the new vision for higher education and research means for Finland and Aalto

Aalto has the capability and the will to act as a trailblazer in implementing the vision.
Poster for Aalto ARTS Grad Show 2026, abstract orange circles, dates 3.9鈥7.10 on warm background
Research & Art Published:

Coming soon: Aalto ARTS Grad Show 2026

We're thrilled to invite you to the Aalto ARTS Grad Show 2026 of the School of Arts, Design and Architecture!
Ahmed Othman and Shreeram Pillain at Oropa, Italy
Research & Art Published:

ACME at Unite! Research School 2026

Ahmed Othman and Shreeram Pillai participated in Unite! Research School 2026 in Torino and Oropa, Italy, joining an international doctoral programme focused on interdisciplinary collaboration, research communication, and academic development.