Password Managers vulnerable

Password managers are vulnerable to insider hacking attacks

Published: 19:06, August 15, 2018

Password managers are vulnerable to insider hacking attacks, a team of researchers has discovered. They say they found more than ten computer security-critical applications that were vulnerable to insider hacking. The majority of the vulnerabilities were found in password managers that millions of people use. People use them, for example, to store their login details.

The researchers also found that many other applications were similarly susceptible to attacks and breaches across macOS, Linux, and Windows operating systems.

The researchers, from the University of Helsinki and Aalto University, presented their findings at the DEFCON Security Conference on August 12th, 2018. They also presented their research at the Usenix Security Conference on August 17th, 2018 (Abstract citation below).

People we call ‘hackers‘ carry out hacking attacksA hacker is somebody who gains access to a computer system by breaking password codes. They are not supposed to or allowed to do this, i.e., they do it without authorization.

Password Managers vulnerable
In an Abstract regarding the vulnerabilities of password managers, the researchers wrote: “The vulnerabilities can be exploited in enterprise environments with centralized access control that gives multiple users remote or local login access to the same host. Computers with guest accounts and shared computers at home are similarly vulnerable.”

Password managers typically have two parts

Computer software typically starts multiple processes to carry out different tasks. Password managers, for example, usually have two parts: an extension to an internet browser and a password vault. Both of them run on the same computer as separate processes.

These processes use a system we call IPC to exchange data. IPC stands for inter-process communication. The process does not send data to an outside network; it remains within the confines of the computer. Hence, most people consider IPC as secure.

However, the software has to protect its internal communication from other processes. Specifically, other processes running within that same computer.

Otherwise, malicious processes that other users initiated could access the data through the IPC communication channel.

Password managers might not protect IPC channels

Thanh Bui, a doctoral candidate at Aalto University, explained:

“Many security-critical applications, including several password managers, do not properly protect the IPC channel. This means that other users’ processes running on a shared computer may access the communication channel and potentially steal users’ credentials.”

Some PCs have multiple users

We generally see PCs as personal devices. However, many of them have more than one user.

Large companies, for example, may have a centralized identity and access management system. The system allows workers to log into any company computer.

In such companies, anybody in the company can launch an attack. If certain features are enabled, the attacker can also log into the computer remotely or as a guest.

Markku Antikainen, a post-doctoral researcher at the University of Helsinki, said:

“The number of vulnerable applications shows that software developers often overlook the security problems related to inter-process communication.”

“Developers may not understand the security properties of different IPC methods, or they place too much trust in software and applications that run locally. Both explanations are worrisome.”

Following responsible disclosure, the research team has reported the vulnerabilities they detected to the respective vendors. The vendors have subsequently taken measures to prevent the attacks.

The researchers carried out this study partly in cooperation with Finnish cyber-security company F-Secure.

Citation:

Man-in-the-Machine: Exploiting Ill-Secured Communication Inside the Computer,” Thanh Bui and Siddharth Prakash Rao, Aalto University; Markku Antikainen, University of Helsinki; Viswanathan Manihatty Bojan and Tuomas Aura, Aalto University. 27th Usenix Security Symposium, Baltimore, MD, USA, August 17, 2018.

Christian Nordqvist Avatar

Other News

Paramount secures final required clearance, but $110 billion Warner Bros. deal remains on hold

Aug 17, 2026

Drax receives carbon-capture permit as funding question remains

Aug 16, 2026

Apple and Google challenge UK app-payment plan as fee dispute deepens

Aug 16, 2026

Can going green improve a company’s financial performance? Sales may be the missing link

Aug 16, 2026

Core Scientific pays $444 million for 440MW Oklahoma power position

Aug 16, 2026

UK goods exports fall 6.3% in June as goods deficit widens

Aug 15, 2026

Study links biased evidence ratings to rising confidence in a simulated business decision

Aug 15, 2026

Shrinkflation study finds higher dollar sales despite lower product volume

Aug 15, 2026

Cocoa study finds monitoring change cut estimated false reporting from 25% to 11%

Aug 14, 2026

Moody’s methodology change led affected companies to borrow more, study finds

Aug 14, 2026

Pony.ai and Uber plan more than 2,000 robotaxis across five European cities

Aug 14, 2026

Great Britain temporarily halts disposable barbecue sales over wildfire risk

Aug 14, 2026

SpaceX completes all-stock Cursor acquisition at $60 billion implied value

Aug 14, 2026

Good company news does not necessarily mean higher returns, study finds

Aug 14, 2026

Maersk raises 2026 forecast as freight rates and volumes lift Q2 earnings

Aug 14, 2026

Shoppers who used smart trolley screens spent 32% more, study finds

Aug 13, 2026

Stressful drives to work linked to negative behavior towards colleagues

Aug 13, 2026

Extra payments on oldest loan may cost borrowers more, study finds

Aug 13, 2026

Cisco revenue rises 18% as hyperscaler AI orders reach $9.3 billion

Aug 12, 2026

Bank of America agrees to invest up to $1.9 billion in Jio Credit

Aug 12, 2026