
Security Alert: Kaspersky Password Manager Revealed by ZDNet for Creating Weak, Brute-Force Susceptible Passwords

Security Alert: Kaspersky Password Manager Revealed by ZDNet for Creating Weak, Brute-Force Susceptible Passwords
Logo: Kaspersky Lab/Composition: ZDNet
Suppose you are in the business of generating passwords, it would probably be a good idea to use an additional source of entropy other than the current time, but for a long time, that’s all Kaspersky Password Manager (KPM) used.
In a blog post to cap off an almost two year saga, Ledger Donjon head of security research Jean-Baptiste Bédrune showed KPM was doing just that.
ZDNET Recommends
“Kaspersky Password Manager used a complex method to generate its passwords. This method aimed to create passwords hard to break for standard password crackers. However, such method lowers the strength of the generated passwords against dedicated tools,” Bédrune wrote.
One of the techniques used by KPM was to make letters that are not often used appear more frequently, which Bédrune said was probably an attempt to trick password cracking tools.
“Their password cracking method relies on the fact that there are probably ‘e’ and ‘a’ in a password created by a human than ‘x’ or ‘j’, or that the bigrams ‘th’ and ‘he’ will appear much more often than ‘qx’ or ‘zr’,” he said.
“Passwords generated by KPM will be, on average, far in the list of candidate passwords tested by these tools. If an attacker tries to crack a list of passwords generated by KPM, he will probably wait quite a long time until the first one is found. This is quite clever.”
The flip side was that if an attacker could deduce that KPM was used, then the bias in the password generator started to work against it.
“If an attacker knows a person uses KPM, he will be able to break his password much more easily than a fully random password. Our recommendation is, however, to generate random passwords long enough to be too strong to be broken by a tool.”
The big mistake made by KPM though was using the current system time in seconds as the seed into a Mersenne Twister pseudorandom number generator.
“It means every instance of Kaspersky Password Manager in the world will generate the exact same password at a given second,” Bédrune said.
Because the program has an animation that takes longer than a second when a password is created, Bédrune said it could be why this issue was not discovered.
“The consequences are obviously bad: every password could be bruteforced,” he said.
“For example, there are 315619200 seconds between 2010 and 2021, so KPM could generate at most 315619200 passwords for a given charset. Bruteforcing them takes a few minutes.”
Bédrune added due to sites often showing account creation time, that would leave KPM users vulnerable to a bruteforce attack of around 100 possible passwords.
However, due to some bad coding leading to an out-of-bounds read on an array, Ledger Donjon found an additional smidgen of entropy.
“Although the algorithm is wrong, it actually makes the passwords more difficult to bruteforce in some cases,” the post said.
KPM versions prior to 9.0.2 Patch F on Windows, 9.2.14.872 on Android, or 9.2.14.31 on iOS were affected, with Kaspersky replacing the Mersenne Twister with BCryptGenRandom function on its Windows version, the research team said.
Kaspersky was informed of the vulnerability in June 2019, and released the fix version in October that same year. In October 2020, users were notified that some passwords would need to be generated, with Kaspersky publishing its security advisory on 27 April 2021.
“All public versions of Kaspersky Password Manager liable to this issue now have a new logic of password generation and a passwords update alert for cases when a generated password is probably not strong enough,” the security company said.
In late 2015, Kaspersky said one in seven people were using just one password .
“A strong password that differs for each account is an important basic element of protecting your digital identity,” David Emm, principal security researcher at Kaspersky Lab, said at the time in a delicious piece of irony.
More Security News
- China reportedly warns local tech companies of increased cybersecurity oversight
- Kaseya ransomware attack: 1,500 companies affected, company confirms
- Japan to bolster national cybersecurity defence with 800 new hires: Report
- Didi barred from China appstores amidst government cybersecurity review
- Ransomware attacks driving cyber reinsurance rates up 40%
Also read:
- [New] Beyond Advertisements A Direct Look at RecordCast
- [Updated] 2024 Approved Navigating VLC's Features for MP4 & Diverse Format Changes
- [Updated] In 2024, Enhancing Engagement The Ultimate Guide for TikTok Unboxings
- [Updated] In 2024, Maximizing Learning Through Efficient Audio Capture Techniques (Mac)
- Complete Guide on Managing Your iPhone's iCloud Storage: Backup, Restoration & Deletion Tips
- Comprehensive Guide: Syncing Your Chats with iCloud via WhatsApp
- Detailed Steps to Correctly Resolve 'Chrome Could Not Load Plugin' On Windows 10 Machines
- Diamond in the Sky | Free Book
- Efficiently Clear Out iCloud Book Collections: The Ultimate Guide to Saving Cloud Storage
- Effortless Steps to Save WhatsApp Chat Videos Across iPhone, Android Devices, and Laptops
- Fixing Your Missing WhatsApp Backups: Unveiling Reasons Behind and Effective Solutions to Try
- Guide: Accessing Your iCloud Keychain Passwords Across iPhone, iPad & Mac
- How to Transfer Data From HDD to Samsung SSD on Windows 11/10/7
- How to Use Phone Clone to Migrate Your Xiaomi Redmi Note 12T Pro Data? | Dr.fone
- Restore Missing App Icon on Oppo K11x Step-by-Step Solutions | Dr.fone
- Seamlessly Reduce Your WhatsApp Audio Files with These Proven Strategies
- Step-by-Step Guide: Completely Removing Your WhatsApp Profile From iOS Devices
- Troubleshoot Your iCloud Picture Sharing Problems for iOS Devices and MacBook Computers - Essential Steps!
- Understanding & Addressing the Resolved Windows 11 Update Data Base Problem
- Title: Security Alert: Kaspersky Password Manager Revealed by ZDNet for Creating Weak, Brute-Force Susceptible Passwords
- Author: Matthew
- Created at : 2025-02-13 00:51:51
- Updated at : 2025-02-19 16:39:53
- Link: https://app-tips.techidaily.com/security-alert-kaspersky-password-manager-revealed-by-zdnet-for-creating-weak-brute-force-susceptible-passwords/
- License: This work is licensed under CC BY-NC-SA 4.0.