Password Managers vulnerable

Password managers are vulnerable to insider hacking attacks

Published: 19:06, August 15, 2018

Password managers are vulnerable to insider hacking attacks, a team of researchers has discovered. They say they found more than ten computer security-critical applications that were vulnerable to insider hacking. The majority of the vulnerabilities were found in password managers that millions of people use. People use them, for example, to store their login details.

The researchers also found that many other applications were similarly susceptible to attacks and breaches across macOS, Linux, and Windows operating systems.

The researchers, from the University of Helsinki and Aalto University, presented their findings at the DEFCON Security Conference on August 12th, 2018. They also presented their research at the Usenix Security Conference on August 17th, 2018 (Abstract citation below).

People we call ‘hackers‘ carry out hacking attacksA hacker is somebody who gains access to a computer system by breaking password codes. They are not supposed to or allowed to do this, i.e., they do it without authorization.

Password Managers vulnerable
In an Abstract regarding the vulnerabilities of password managers, the researchers wrote: “The vulnerabilities can be exploited in enterprise environments with centralized access control that gives multiple users remote or local login access to the same host. Computers with guest accounts and shared computers at home are similarly vulnerable.”

Password managers typically have two parts

Computer software typically starts multiple processes to carry out different tasks. Password managers, for example, usually have two parts: an extension to an internet browser and a password vault. Both of them run on the same computer as separate processes.

These processes use a system we call IPC to exchange data. IPC stands for inter-process communication. The process does not send data to an outside network; it remains within the confines of the computer. Hence, most people consider IPC as secure.

However, the software has to protect its internal communication from other processes. Specifically, other processes running within that same computer.

Otherwise, malicious processes that other users initiated could access the data through the IPC communication channel.

Password managers might not protect IPC channels

Thanh Bui, a doctoral candidate at Aalto University, explained:

“Many security-critical applications, including several password managers, do not properly protect the IPC channel. This means that other users’ processes running on a shared computer may access the communication channel and potentially steal users’ credentials.”

Some PCs have multiple users

We generally see PCs as personal devices. However, many of them have more than one user.

Large companies, for example, may have a centralized identity and access management system. The system allows workers to log into any company computer.

In such companies, anybody in the company can launch an attack. If certain features are enabled, the attacker can also log into the computer remotely or as a guest.

Markku Antikainen, a post-doctoral researcher at the University of Helsinki, said:

“The number of vulnerable applications shows that software developers often overlook the security problems related to inter-process communication.”

“Developers may not understand the security properties of different IPC methods, or they place too much trust in software and applications that run locally. Both explanations are worrisome.”

Following responsible disclosure, the research team has reported the vulnerabilities they detected to the respective vendors. The vendors have subsequently taken measures to prevent the attacks.

The researchers carried out this study partly in cooperation with Finnish cyber-security company F-Secure.

Citation:

Man-in-the-Machine: Exploiting Ill-Secured Communication Inside the Computer,” Thanh Bui and Siddharth Prakash Rao, Aalto University; Markku Antikainen, University of Helsinki; Viswanathan Manihatty Bojan and Tuomas Aura, Aalto University. 27th Usenix Security Symposium, Baltimore, MD, USA, August 17, 2018.

Christian Nordqvist Avatar

Other News

IQE revenue rises 43% as AI demand boosts semiconductor materials

Sep 7, 2026

German industrial production falls as car output drops sharply

Sep 7, 2026

Eurozone growth picks up, but employment barely rises

Sep 7, 2026

Why businesses replace equipment that still works

Sep 7, 2026

What happens to a product after a customer returns it?

Sep 7, 2026

Factories weigh the cost of recycled water against supply risks

Sep 7, 2026

Why invoice fraud remains a business risk as payments go digital

Sep 7, 2026

EV battery recyclers face a long wait for used packs

Sep 6, 2026

France moves business invoicing beyond the emailed PDF

Sep 6, 2026

The financing gap that can stop an export order before it ships

Sep 6, 2026

Singapore sets a benchmark for liquid-cooled AI data centers

Sep 6, 2026

Non-food sales lead a 0.6% decline in eurozone retail trade

Sep 6, 2026

Texas repair law expands access to electronics parts and tools

Sep 6, 2026

Thailand’s high-income push puts smaller firms and regional cities in focus

Sep 6, 2026

Canada’s trade surplus shrinks as exports to the US fall

Sep 5, 2026

El Niño strengthens into 2027, raising risks for food prices, power and trade

Sep 5, 2026

Nvidia agrees to buy Hugging Face for $12.93 billion, pledges to keep platform open

Sep 5, 2026

Global food prices rise as sugar leads August increases

Sep 5, 2026

A weaker currency can lift overseas profits without reviving factories at home

Sep 5, 2026

AI shortcuts may weaken managers’ judgment, researchers warn

Sep 4, 2026