Password managers are Taste of Younger Sister in law (2025)a vital line of defense in the battle for internet security — which makes it all the more painful when they shit the bed.
The Kaspersky Password Manager (KPM), a free tool used to generate and manage online passwords, has long been a popular alternative to the likes of LastPass or 1Password. Unfortunately, according to security researcher Jean-Baptiste Bédrune, a bad coding decision meant that the passwords it generated weren't truly random and as a result were relatively easy to brute force — a hacking technique using specialized tools to try hundreds of thousands (or millions) of password combinations in an attempt to guess the right one.
Bédrune, who is a security researcher for the cryptocurrency hard-wallet company Ledger, writes that when generating a supposedly random password, KPM used the current time as its "single source of entropy."
While that sounds super technical, it essentially boils down to KPM using the time as the basis for its pseudo random number generator. Knowing when the password was generated, even approximately, would therefore give a hacker vital information in an attempt to crack a victim's account.
"All the passwords it created could be bruteforced in seconds," writes Bédrune.
Bédrune's team submitted the vulnerability to Kaspersky through HackerOne's bug bounty program in June of 2019, and Ledger's blog post says Kaspersky notified potentially affected users in October of 2020.
When reached for comment, Kaspersky confirmed — but downplayed — the problem identified by Bédrune.
"This issue was only possible in the unlikely event that the attacker knew the user's account information and the exact time a password had been generated," wrote a company spokesperson. "It would also require the target to lower their password complexity settings."
Kaspersky also published a security advisory detailing the flaw in April of 2021.
"Password generator was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases," read the alert. "An attacker would need to know some additional information (for example, time of password generation)."
That alert also noted that, going forward, the password manager had fixed the issue — a claim echoed by the spokesperson.
"The company has issued a fix to the product and has incorporated a mechanism that notifies users if a specific password generated by the tool could be vulnerable and needs changing."
SEE ALSO: Why you need a secret phone number (and how to get one)
So what does this mean for the average KPM user? Well, if they've been using the same KPM-generated passwords for over two years (a habit that would typically be fine), they should create new ones.
Other than that? Keep using a password manager and enable two-factor authentication.
Topics Cybersecurity
‘Empire of AI’ author on OpenAI’s cult of AGI and why Sam Altman tried to discredit her bookSpaceX announces allBest Kindle deal: Save 20% on the Kindle ColorsoftCan ChatGPT pass the Turing Test? What the research says.What motherhood can teach us about the workplaceDid Siri snoop on you? Apply to get up to $100 from Apple.NASA astronauts show new way to take out space trashSpaceX announces allWhat motherhood can teach us about the workplacePopular YouTuber declares: Do not buy the Pixel 9a smartphoneBest TV deal: Get the LG UR9000 4K TV for 21% off at AmazonNumber Representations in Computer HardwareJBL Quantum 200 Gaming Headset deal: Get $29.95 offBlack Friday GPU Buying Guide: November GPU Pricing UpdateHow to watch Axiom space mission depart from ISSFacebook to add labels to climate change postsMrBeast is teaming with 'Maximum Ride' author James Patterson to write a novelArtificialThe vital telescopes discovering EarthWhy manatees are suddenly dying in Florida Xbox Series X All Best Sony WH1000XM4 headphones deal: Save $150 at Best Buy Shop the Indie Author Winter Wonderland event [2024] Clemson vs. SMU football livestreams: kickoff time, streaming deals, and more Best Apple Watch Series 10 deal: Save over $60 at Amazon Best earbuds deal: Save $50 on the JBL Tune 230NC TWS Best TV deal: Save $500 on the Sony 85 Google Search AI Overviews at 6 months: Is the feature getting better? Add holiday cheer to your Mac's desktop with Festivitas JBL Vibe Beam deal: $24.95 at Amazon Best Dyson deal: Save $110 on the Dyson Airwrap (Special Edition) Packers vs. Lions 2024 livestream: How to watch NFL for free Wordle today: The answer and hints for December 5 Best monitor deal: Save $120 on LG 34 NYT Connections hints and answers for December 6: Tips to solve 'Connections' #544. Bitcoin finally hits $100k Save hundreds during Best Buy's 3 Evidence of a black hole visiting Earth may be hiding in your house Browns vs. Steelers 2024 livestream: How to watch NFL online NYT Strands hints, answers for December 7
2.632s , 10111.8125 kb
Copyright © 2025 Powered by 【Taste of Younger Sister in law (2025)】,Prosperous Times Information Network