portbridal.blogg.se

Kaspersky password manager fixes that bruteforced
Kaspersky password manager fixes that bruteforced









“Kaspersky has fixed a security issue in Kaspersky Password Manager, which potentially allowed an attacker to find out passwords generated by the tool,” Kaspersky said in a statement. “All public versions of Kaspersky Password Manager liable to this issue now have a new logic of password generation and a passwords update alert for cases when a generated password is probably not strong enough.”Īlthough the issue has now been patched, several KPM versions before 9.0.2 Patch F on Windows, Android prior to 9.2.14.872, and iOS prior to 9.2.14.31 were affected. An attacker would need to know some additional information (for example, time of password generation),” the company said in its security advisory published on April 27, 2021.

#Kaspersky password manager fixes that bruteforced generator

“Password generator was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases.

kaspersky password manager fixes that bruteforced

In October 2020, users were notified that some passwords would need to be generated. Kaspersky was informed of the vulnerability in June 2019 for which the company released the fixed version in October 2019.

kaspersky password manager fixes that bruteforced

can be also easily retrieved if they had been generated using KPM. Moreover, passwords from leaked databases containing hashed passwords, passwords for encrypted archives, TrueCrypt/Veracrypt volumes, etc. Since the websites or forums display the creation time of accounts, an attacker can try to brute force the account password with a small range of passwords (~100) and gain access to it. Bruteforcing them takes a few minutes,” he added. For example, there are 315619200 seconds between 20, so KPM could generate at most 315619200 passwords for a given charset. “The consequences are obviously bad: every password could be bruteforced.









Kaspersky password manager fixes that bruteforced