Jump to content

Malware’s new target: your password manager’s password


securitybreach

Recommended Posts

securitybreach

Big surprise...... B)

 

 

Screen-Shot-2014-11-19-at-12.29.08-PM.png

Aurich Lawson / Thinkstock

 

Cyber criminals have started targeting the password managers that protect an individual's most sensitive credentials by using a keylogger to steal the master password in certain cases, according to research from data-protection company IBM Trusteer.

 

The research found that a configuration file, which attackers use to tailor the Citadel trojan for specific campaigns, had been modified to start up a keylogger when the user opened either Password Safe or KeePass, two open-source password managers. While malware has previously targeted the credentials stored in the password managers included in popular Web browsers, third-party password managers have typically not been targeted.

 

While the current impact of the attack is low, the implications of the attacker’s focus is that password managers will soon come under more widespread assault, Dana Tamir, director of enterprise security for IBM Trusteer, told Ars Technica.

 

“Once the malware captures this master key, then they can use that master key to exercise complete control over the machine and any of the user’s online accounts,” she said......

 

 

http://arstechnica.c...ster-passwords/

Link to comment
Share on other sites

V.T. Eric Layton

My MASTER Password Manager is dead tree/ink format. So, even if they do manage to trash my LastPass account, I won't lose anything. Besides, I only use LastPass for non-critical passwords like logins to forums and silly Internet carp like that; no banking, credit card, passwords stored with LastPass. I don't even keep passwords on my computers.... anywhere. You want my passwords, you have to break into my house, face my fearsome kitties, and find the password hardcopy (it's hiding). Good luck with that, especially since I don't leave my house much these days and I have one of these near-to-hand always...

 

NN32zK1.jpg?1

  • Like 3
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...