Special offer

Are Password Managers as Safe as You Think They Are?

By
Services for Real Estate Pros with IDTheftSecurity.com Inc

You have probably heard of password managers, and you probably think they are pretty safe, right? Well, there is new research out there that may might make you think twice, especially if you use password managers like KeePass, 1Password, Lastpass, or Dashlane. Frankly, I’m not worried about it, but read on.

Specifically, this study looked at the instances of passwords leaking from a host compute or focused on if these password managers were accidently leaving passwords in the computer’s memory.

What was found was that all of the password managers that were looked at did a good job at keeping these passwords secure when in a state where it was “not running.” This means that a hacker would not be able to force the program into giving away the user’s passwords. However, it was also noted that though each password manager that was tested attempted to scrub these passwords from the memory of the computer, it wasn’t always successful…meaning, your passwords could still be in the memory.

Some of these programs, like 1Password, seemed to have left the master password, but also the secret key for the program. This could possibly allow a hacker to access the info in this program. But, it’s important to note that these programs are trying to remove this information, but due to various situational issues, it’s not always possible.

Another program, LastPass, was also examined, and it, too, caused some concern amongst researchers. Basically, the program scrambles the passwords when the user is typing them in, but they are decrypted into the computer’s memory. Additionally, even when the software is locked, the passwords are still sitting in the memory just waiting for someone to extract it.

KeePass, which is yet another password manager, was also looked at here. In this case, it removes the master password from the computer’s memory, and it is not able to be recovered. However, other credentials that were stored in KeePass were able to be accessed, which is also problematic.

Should you be worried about this? Well, it depends on your personal thought process. Some people probably won’t care too much, and others won’t be affected because they don’t use password managers that have these issues. Since the researchers pointed out these issues each password manager has done their own updates and corrected any issues. The real vulnerability isn’t the security of the password managers but the security of the devices, their users and if the users are deploying the same password across multiple accounts.  Using the same password over and over is the risk here. So get a password manager so you can have a different password everywhere.

Robert Siciliano personal security and identity theft expert and speaker is the author of Identity Theft Privacy: Security Protection and Fraud Prevention: Your Guide to Protecting Yourself from Identity Theft and Computer Fraud. See him knock’em dead in this Security Awareness Training video.

Carol Williams
Although I'm retired, I love sharing my knowledge and learning from other real estate industry professionals. - Wenatchee, WA
Retired Agent / Broker / Prop. Mgr, Wenatchee, WA

Hi Robert,
I've always wondered about the security of Password Managers.  I figure anything online is vulnerable and have doubted password managers are any different.

Jun 13, 2019 10:24 AM
Grant Schneider
Performance Development Strategies - Armonk, NY
Your Coach Helping You Create Successful Outcomes

Hi Robert - I have been wary of the ease of a password manager.  I don't want to forget the passward manager and lose all my individual passwords.

Jun 13, 2019 10:48 AM
Sandy Padula & Norm Padula, JD, GRI
HomeSmart Realty West & Florida Realty Investments - , CA
Presence, Persistence & Perseverance

As always, Robert Siciliano your content is appreciated and confirms my security protocol of only using a USB drive and not leaving it plugged into my computer unless absolutely necessary

Jun 13, 2019 11:55 AM
Nina Hollander, Broker
Coldwell Banker Realty - Charlotte, NC
Your Greater Charlotte Realtor

Hi Robert... well, this was certainly an eye-opener. It seems it gets more difficult by the day to stay ahead by even one step.

Jun 13, 2019 12:13 PM
Sheri Sperry - MCNE®
Coldwell Banker Realty - Sedona, AZ
(928) 274-7355 ~ YOUR Solutions REALTOR®

Hi Robert Siciliano - Thanks for the info. I think it is important to remain vigilante in this area. 

Jun 13, 2019 01:20 PM
Debe Maxwell, CRS
Savvy + Company (704) 491-3310 - Charlotte, NC
The RIGHT CHARLOTTE REALTOR!

I use LastPass and did not know about this vulnerability. I'll be more vigilant in the future to ensure I don't fall victim to a hack. Thanks Robert!

Jun 13, 2019 01:40 PM
Kathy Streib
Cypress, TX
Home Stager/Redesign

Hi Robert- I hesitated using a Password Manager for years but finally after reading your blog, I decided to jump in. And I am very careful about my devices. 

Jun 13, 2019 07:32 PM
Sally K. & David L. Hanson
EXP Realty 414-525-0563 - Brookfield, WI
WI Real Estate Agents - Luxury - Divorce

We are not trusting of most "security" claimed software.

Jun 14, 2019 05:58 AM
Jeff Dowler, CRS
eXp Realty of California, Inc. - Carlsbad, CA
The Southern California Relocation Dude

Robert:

Thanks for the 411 on password managers. I don't use them but was aware of some of this. I also heard they have all been hacked.

Jeff

Jun 15, 2019 02:20 PM
Kat Palmiotti
eXp Commercial, Referral Divison - Kalispell, MT
Helping your Montana dreams take root

I'm suspect of anything keeping passwords safe. Interesting information about these products.

Jun 16, 2019 03:04 AM
Jerry Lucas
ABC Legal Docs LLC - Colorado Springs, CO
Notary Training, Consulting. Colorado Springs, CO

Everyone should be using two-factor authentication (2FA) which requires a second factor to log in, such as a USB Yubi key or authenticator software, sending a one-time passcode (OTP) to your cell phone or email address to be entered quickly.

With 2FA, even if a hacker discovers your password, that is not sufficient to log in without also using the OTP.

Jun 17, 2019 06:51 PM
Mary Hutchison, SRES, ABR
Better Homes and Gardens Real Estate-Kansas City Homes - Kansas City, MO
Experienced Agent in Kansas City Metro area

I don't use a password manager. It does sound tempting but ....don't want to risk it.

Jun 19, 2019 12:45 PM