Главная
Study mode:
on
1
Intro
2
Agenda
3
Background
4
Password Manager Research Timeline
5
Anatomy of a Password Manager
6
Workflow Overview
7
Password Manager Terminology
8
Password Manager States
9
"Not Running" State Security Guarantees
10
"Running:Unlocked" State Security Guarantees
11
Attacks on "Not Running" Password Managers
12
Attacks on "Running:Locked" Password Managers
13
Demo Attack - Running:Locked (1Password)
14
Windows Bug Discovery
15
LastPass (Windows bug mitigation)
16
Mitigation is helpful (for us)
17
Attacks on "Running:Unlocked" Password Managers
18
Attacks on "Running:Unlocked" Summary
19
Apply What You Have Learned Today/Going Forward
20
RSAConference 2020
Description:
Explore the security vulnerabilities of popular password managers in this 41-minute RSA Conference talk. Dive into the intricacies of how master passwords and stored secrets are handled during different states of password manager operation, including when logged out or locked. Examine the anatomy of password managers, their workflow, and terminology. Analyze security guarantees in various states such as "Not Running" and "Running:Unlocked." Witness demonstrations of attacks on password managers in different states, including a specific demo attack on 1Password in the "Running:Locked" state. Learn about a Windows bug discovery affecting LastPass and its mitigation. Gain insights into applying this knowledge for improved security practices and understand the implications for future password manager development.

Extracting Secrets from Locked Password Managers

RSA Conference
Add to list