Repository logo
Log In(current)
  1. Home
  2. Colleges & Schools
  3. Graduate School
  4. Doctoral Dissertations
  5. An Analysis of Modern Password Manager Security and Usage on Desktop and Mobile Devices
Details

An Analysis of Modern Password Manager Security and Usage on Desktop and Mobile Devices

Date Issued
May 1, 2021
Author(s)
Oesch, Timothy
Advisor(s)
Scott I. Ruoti
Additional Advisor(s)
Kent Seamons
Jinyuan Sun
Doowon Kim
Scott I. Ruoti
Permanent URI
https://trace.tennessee.edu/handle/20.500.14382/27935
Abstract

Security experts recommend password managers to help users generate, store, and enter strong, unique passwords. Prior research confirms that managers do help users move towards these objectives, but it also identified usability and security issues that had the potential to leak user data or prevent users from making full use of their manager. In this dissertation, I set out to measure to what extent modern managers have addressed these security issues on both desktop and mobile environments. Additionally, I have interviewed individuals to understand their password management behavior.


I begin my analysis by conducting the first security evaluation of the full password manager lifecycle (generation, storage, and autofill) on desktop devices, including the creation and analysis of a corpus of 147 million generated passwords. My results show that a small percentage of generated passwords are weak against both online and offline attacks, and that attacks against autofill mechanisms are still possible in modern managers. Next, I present a comparative analysis of autofill frameworks on iOS and Android. I find that these frameworks fail to properly verify webpage security and identify a new class of phishing attacks enabled by incorrect handling of autofill within WebView controls hosted in apps. Finally, I interview users of third-party password managers to understand both how and why they use their managers as they do. I find evidence that many users leverage multiple password managers to address issues with existing managers, as well as provide explanations for why password reuse continues even in the presence of a password manager. Based on these results, I conclude with recommendations addressing the attacks and usability issues identified in this work.

Subjects

password managers

security

usability

Disciplines
Information Security
Other Computer Engineering
Other Computer Sciences
Degree
Doctor of Philosophy
Major
Computer Engineering
Comments

Final version after defense with corrections

File(s)
Thumbnail Image
Name

oesch_dissertation.pdf

Size

4.07 MB

Format

Adobe PDF

Checksum (MD5)

25a80ec06bc8228574103a7ca933a717


University Libraries

1015 Volunteer Boulevard
Knoxville, TN 37996
865-974-4351

Map & Directions
Donate to the Libraries
  • About
  • John C. Hodges Society
  • Speaking Volumes magazine
  • Outreach
  • Directory
  • Employment
  • Policies
  • Library Intranet
University of Tennessee power T logo

The University of Tennessee, Knoxville
Knoxville, Tennessee 37996
865-974-1000

Events
A-Z
Apply
Privacy
Map
Directory
Give to UT
Accessibility

Built with DSpace-CRIS software - Extension maintained and optimized by 4Science