Password managers are Small Tits | Adult Movies Onlinea vital line of defense in the battle for internet security — which makes it all the more painful when they shit the bed.
The Kaspersky Password Manager (KPM), a free tool used to generate and manage online passwords, has long been a popular alternative to the likes of LastPass or 1Password. Unfortunately, according to security researcher Jean-Baptiste Bédrune, a bad coding decision meant that the passwords it generated weren't truly random and as a result were relatively easy to brute force — a hacking technique using specialized tools to try hundreds of thousands (or millions) of password combinations in an attempt to guess the right one.
Bédrune, who is a security researcher for the cryptocurrency hard-wallet company Ledger, writes that when generating a supposedly random password, KPM used the current time as its "single source of entropy."
While that sounds super technical, it essentially boils down to KPM using the time as the basis for its pseudo random number generator. Knowing when the password was generated, even approximately, would therefore give a hacker vital information in an attempt to crack a victim's account.
"All the passwords it created could be bruteforced in seconds," writes Bédrune.
Bédrune's team submitted the vulnerability to Kaspersky through HackerOne's bug bounty program in June of 2019, and Ledger's blog post says Kaspersky notified potentially affected users in October of 2020.
When reached for comment, Kaspersky confirmed — but downplayed — the problem identified by Bédrune.
"This issue was only possible in the unlikely event that the attacker knew the user's account information and the exact time a password had been generated," wrote a company spokesperson. "It would also require the target to lower their password complexity settings."
Kaspersky also published a security advisory detailing the flaw in April of 2021.
"Password generator was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases," read the alert. "An attacker would need to know some additional information (for example, time of password generation)."
That alert also noted that, going forward, the password manager had fixed the issue — a claim echoed by the spokesperson.
"The company has issued a fix to the product and has incorporated a mechanism that notifies users if a specific password generated by the tool could be vulnerable and needs changing."
SEE ALSO: Why you need a secret phone number (and how to get one)
So what does this mean for the average KPM user? Well, if they've been using the same KPM-generated passwords for over two years (a habit that would typically be fine), they should create new ones.
Other than that? Keep using a password manager and enable two-factor authentication.
Topics Cybersecurity
Jeeves, Redux, and Other News by Sadie SteinHere Be Dragons by Sadie SteinPage Views by Sadie Stein'Quordle' today: See each 'Quordle' answer and hints for July 18Literary Vigilantes, and Other News by Sadie SteinBeached by Nathan DeuelIvor Gurney’s “To His Love” by Glyn MaxwellTesla starts production of long'Command Z' review: Steven Soderbergh's surprise sciShopping for Groceries with the Romantic Poets by Jason Novak'Command Z' review: Steven Soderbergh's surprise sciHappy Election Day by Sadie SteinRecapping Dante: Canto 6, or Crowdsourcing by Alexander AcimanWith the Rushes by Sadie SteinMole Catching: A Practical Guide by Sadie Stein'Quordle' today: See each 'Quordle' answer and hints for July 16Facebook wants to help you get vaxxedClaire Vaye Watkins Wins Dylan Thomas Prize by Sadie SteinFacebook wants to help you get vaxxedViral Fleetwood Mac skateboarding TikTok is for sale as a $500,000 NFT Tim Cook's new Twitter name calls out Trump's 'Tim Apple' flub 'The Simpsons' episode with Michael Jackson's voice pulled from circulation Joe Biden would like to take Trump 'behind the gym' 'Game of Thrones' is not a misogynistic show, female stars say ahead of final season It's appropriate that the internet actually broke on Kim Kardashian's birthday Welcome to New York, Taylor Swift exhibit. It's been waiting for you. Clinton and Trump were actually sort of nice to each other at the Al Smith dinner Donald Trump's 'nasty woman' comment is available in T Why hackers choose DDoS attacks 'Elder Scrolls: Blades' is a miraculously smartphone Revisiting superhero films of the '90s in honor of 'Captain Marvel' Congress saw some Nickelback hot takes on the House floor Trump didn't quite get the memo on charity dinner with Hillary Clinton Waymo starts selling its LiDAR sensors to power robots, security systems, and more Clinton drops another Trump burn after night of jokes Duterte hating on the U.S. has inspired a Spam meme in the Philippines Gayle King's interview with R. Kelly takes explosive turn: Watch Stop what you're doing and update Google Chrome Foursquare introduces experimental 'Hypertrending' feature for SXSW Researchers demonstrate new ways to hack your stupidly complex smart home
2.3884s , 10111.6875 kb
Copyright © 2025 Powered by 【Small Tits | Adult Movies Online】,Co-creation Information Network