{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T23:00:41Z","timestamp":1777676441836,"version":"3.51.4"},"publisher-location":"Cham","reference-count":32,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031651748","type":"print"},{"value":"9783031651755","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2024,7,26]],"date-time":"2024-07-26T00:00:00Z","timestamp":1721952000000},"content-version":"vor","delay-in-days":207,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Password management has long been a persistently challenging task. This led to the introduction of password management software, which has been around for at least 25 years in various forms, including desktop and browser-based applications. This work assesses the ability of two dozen password managers, 12 desktop applications, and 12 browser plugins, to effectively protect the confidentiality of secret credentials in six representative scenarios. Our analysis focuses on the period during which a Password Manager (PM) resides in the RAM. Despite the sensitive nature of these applications, our results show that across all scenarios, only three desktop PM applications and two browser plugins do not store plaintext passwords in the system memory. Oddly enough, at the time of writing, only two vendors recognized the exploit as a vulnerability, reserving CVE-2023-23349, while the rest chose to disregard or underrate the issue.<\/jats:p>","DOI":"10.1007\/978-3-031-65175-5_5","type":"book-chapter","created":{"date-parts":[[2024,7,25]],"date-time":"2024-07-25T14:43:01Z","timestamp":1721918581000},"page":"61-75","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Keep Your Memory Dump Shut: Unveiling Data Leaks in\u00a0Password Managers"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6507-5052","authenticated-orcid":false,"given":"Efstratios","family":"Chatzoglou","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4492-5104","authenticated-orcid":false,"given":"Vyron","family":"Kampourakis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9481-0906","authenticated-orcid":false,"given":"Zisis","family":"Tsiatsikas","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0142-7503","authenticated-orcid":false,"given":"Georgios","family":"Karopoulos","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6348-5031","authenticated-orcid":false,"given":"Georgios","family":"Kambourakis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,7,26]]},"reference":[{"key":"5_CR1","unstructured":"AlessandroZ: LaZagne. https:\/\/github.com\/AlessandroZ\/LaZagne. Accessed 14 Jan 2024"},{"key":"5_CR2","doi-asserted-by":"crossref","unstructured":"Apostolopoulos, D., Marinakis, G., Ntantogian, C., Xenakis, C.: Discovering authentication credentials in volatile memory of android mobile devices. In: Conference on e-Business, e-Services and e-Society, pp. 178\u2013185 (2013)","DOI":"10.1007\/978-3-642-37437-1_15"},{"key":"5_CR3","unstructured":"Barten, D.: Client-side attacks on the lastpass browser extension (2019). https:\/\/api.semanticscholar.org\/CorpusID:153315475"},{"key":"5_CR4","unstructured":"C.E.: Pandora. https:\/\/github.com\/efchatz\/pandora. Accessed 14 Jan 2024"},{"key":"5_CR5","doi-asserted-by":"crossref","unstructured":"Carr, M., Shahandashti, S.F.: Revisiting security vulnerabilities in commercial password managers. In: ICT Systems Security and Privacy Protection, pp. 265\u2013279 (2020)","DOI":"10.1007\/978-3-030-58201-2_18"},{"key":"5_CR6","doi-asserted-by":"crossref","unstructured":"Chapman, R.: Sanitizing sensitive data: how to get it right (or at least less wrong...). In: Reliable Software Technologies \u2013 Ada-Europe 2017, pp. 37\u201352 (2017)","DOI":"10.1007\/978-3-319-60588-3_3"},{"key":"5_CR7","doi-asserted-by":"publisher","first-page":"69","DOI":"10.1016\/j.cosrev.2019.03.002","volume":"33","author":"S Chaudhary","year":"2019","unstructured":"Chaudhary, S., Schafeitel-T\u00e4htinen, T., Helenius, M., Berki, E.: Usability, security and trust in password managers: a quest for user-centric properties and features. Comput. Sci. Rev. 33, 69\u201390 (2019)","journal-title":"Comput. Sci. Rev."},{"key":"5_CR8","unstructured":"Cybernews: Chrome password managers: Best extensions in 2023. https:\/\/cybernews.com\/best-password-managers\/password-managers-for-chrome. Accessed 14 Jan 2024"},{"issue":"1","key":"5_CR9","first-page":"12","volume":"7","author":"M Fagan","year":"2017","unstructured":"Fagan, M., Albayram, Y., Khan, M.M.H., Buck, R.: An investigation into users\u2019 considerations towards using password managers. HCIS 7(1), 12 (2017)","journal-title":"HCIS"},{"key":"5_CR10","unstructured":"Fung, B., Sands, G.: Former SolarWinds CEO blames intern for \u2018solarwinds123\u2019 password leak. https:\/\/edition.cnn.com\/2021\/02\/26\/politics\/solarwinds123-password-intern\/index.html. Accessed 14 Jan 2024"},{"key":"5_CR11","doi-asserted-by":"crossref","unstructured":"Gangwal, A., Singh, S., Srivastava, A.: Autospill: credential leakage from mobile password managers. In: Proceedings of the Thirteenth ACM Conference on Data and Application Security and Privacy, pp. 39\u201347 (2023)","DOI":"10.1145\/3577923.3583658"},{"key":"5_CR12","doi-asserted-by":"crossref","unstructured":"Gray, J., Franqueira, V.N.L., Yu, Y.: Forensically-sound analysis of security risks of using local password managers. In: 2016 IEEE 24th (REW), pp. 114\u2013121 (2016)","DOI":"10.1109\/REW.2016.034"},{"key":"5_CR13","unstructured":"hfiref0x: Defeating windows user account control. https:\/\/github.com\/hfiref0x\/UACME#readme. Accessed 14 Jan 2024"},{"key":"5_CR14","unstructured":"Kotadia, M.: Gates predicts death of the password. https:\/\/www.cnet.com\/news\/privacy\/gates-predicts-death-of-the-password. Accessed 14 Jan 2024"},{"key":"5_CR15","doi-asserted-by":"crossref","unstructured":"Lee, J., Chen, A., Wallach, D.S.: Total recall: persistence of passwords in android. In: Proceedings 2019 Network and Distributed System Security Symposium (2019). https:\/\/api.semanticscholar.org\/CorpusID:142503488","DOI":"10.14722\/ndss.2019.23180"},{"key":"5_CR16","doi-asserted-by":"crossref","unstructured":"Li, Z., He, W., Akhawe, D., Song, D.: The $$\\{$$Emperor\u2019s$$\\}$$ new password manager: security analysis of web-based password managers. In: 23rd USENIX, pp. 465\u2013479 (2014)","DOI":"10.21236\/ADA614474"},{"key":"5_CR17","doi-asserted-by":"crossref","unstructured":"Luevanos, C., Elizarraras, J., Hirschi, K., Yeh, J.H.: Analysis on the security and use of password managers. In: 2017 18th (PDCAT), pp. 17\u201324 (2017)","DOI":"10.1109\/PDCAT.2017.00013"},{"key":"5_CR18","unstructured":"Machine, W.: Counterpane systems brings the security of blowfish to a password database. https:\/\/web.archive.org\/web\/19980119124510. http:\/\/www.counterpane.com\/passsafe.html. Accessed 14 Jan 2024"},{"key":"5_CR19","doi-asserted-by":"crossref","unstructured":"Malliaros, S., Ntantogian, C., Xenakis, C.: Protecting sensitive information in the volatile memory from disclosure attacks. In: 2016 11th International Conference on Availability, Reliability and Security (ARES), pp. 687\u2013693 (2016)","DOI":"10.1109\/ARES.2016.75"},{"key":"5_CR20","unstructured":"Microsoft: Protecting anti-malware services. https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/services\/protecting-anti-malware-services-. Accessed 14 Jan 2024"},{"key":"5_CR21","unstructured":"Oesch, S., Ruoti, S.: That was then, this is now: a security evaluation of password generation, storage, and autofill in browser-based password managers. In: Proceedings of the 29th USENIX, pp. 2165\u20132182 (2020)"},{"key":"5_CR22","unstructured":"OWASP: Cryptographic storage. https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/Cryptographic_Storage_Cheat_Sheet.html#minimise-the-storage-of-sensitive-information. Accessed 14 Jan 2024"},{"key":"5_CR23","unstructured":"OWASP: Secure product design. https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/Secure_Product_Design_Cheat_Sheet.html. Accessed 14 Jan 2024"},{"key":"5_CR24","unstructured":"OWASP: Testing memory for sensitive data. https:\/\/mas.owasp.org\/MASTG\/tests\/android\/MASVS-STORAGE\/MASTG-TEST-0011\/. Accessed 14 Jan 2024"},{"key":"5_CR25","unstructured":"PASCU, L.: 29 vulnerabilities found in android password managers. https:\/\/www.bitdefender.com\/blog\/hotforsecurity\/29-vulnerabilities-found-in-top-rated-password-managers-for-android\/. Accessed 14 Jan 2024"},{"key":"5_CR26","unstructured":"Pearman, S., Zhang, S.A., Bauer, L., Christin, N., Cranor, L.F.: Why people (don\u2019t) use password managers effectively. In: SOUPS 2019, pp. 319\u2013338 (2019)"},{"key":"5_CR27","doi-asserted-by":"crossref","unstructured":"Sabev, P., Petrov, M.: Android password managers and vault applications: data storage security issues identification. J. Inf. Secur. Appl. 67(C) (2022)","DOI":"10.1016\/j.jisa.2022.103152"},{"key":"5_CR28","unstructured":"Silver, D., Jana, S., Boneh, D., Chen, E., Jackson, C.: Password managers: attacks and defenses. In: 23rd USENIX, pp. 449\u2013464 (2014)"},{"key":"5_CR29","unstructured":"sysdig: Keepass cve-2023-32784: Detection of processes memory dump. https:\/\/sysdig.com\/blog\/keepass-cve-2023-32784-detection\/. Accessed 14 Jan 2024"},{"key":"5_CR30","unstructured":"Turton, W., Mehrotra, K.: Colonial Pipeline. https:\/\/www.governing.com\/security\/bad-password-gave-colonial-pipeline-hackers-access. Accessed 14 Jan 2024"},{"key":"5_CR31","unstructured":"Wired: The best password managers to secure your digital life. https:\/\/www.wired.com\/story\/best-password-managers\/. Accessed 14 Jan 2024"},{"key":"5_CR32","first-page":"183","volume":"1","author":"R Zhao","year":"2013","unstructured":"Zhao, R., Yue, C., Sun, K.: Vulnerability and risk analysis of two commercial browser and cloud based password managers. Acad. Sci. Eng. Sci. J. 1, 183\u2013197 (2013)","journal-title":"Acad. Sci. Eng. Sci. J."}],"container-title":["IFIP Advances in Information and Communication Technology","ICT Systems Security and Privacy Protection"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-65175-5_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,25]],"date-time":"2024-07-25T14:48:41Z","timestamp":1721918921000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-65175-5_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031651748","9783031651755"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-65175-5_5","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"value":"1868-4238","type":"print"},{"value":"1868-422X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"26 July 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SEC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"IFIP International Conference on ICT Systems Security and Privacy Protection","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Edinburgh","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"United Kingdom","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"12 June 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"14 June 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"39","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"sec2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/ifipsec2024.co.uk\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}