Password Manager Proves Security Risk
Google has uncovered a major bug in a security software tool that could expose user passwords to hackers. Its the second time in a matter of weeks that Google's found problems with security software.
On this occasion the problem is with the antivirus package from Trend Micro, specifically a Password Manager feature. This allows users to store passwords securely with a master security code; at the touch of a button, users can then have them the program automatically fill in passwords and logins on websites.
According to Google's Tavis Ormandy, the feature is installed by default with Trend Micro's antivirus software and starts automatically when Windows starts. (Source: google.com)
Tool Used Outdated Connection
Ormandy says the problem lies with the way the Password Manager interacts with the Chrome browser and its underlying system Chromium - specifically, the way that the sandbox feature works. The tool was was originally set up to work with version 41 of Chromium when that version was available last year.
The latest edition of Chromium is version 49, which now utilizes Chrome's sandbox features much differently than in the past. In short, the old version of Trend Micro's Password Manager does not comply with security features of the new sandbox, which means that certain programming code of the Password Manager is able to overstep parts of the system memory and is thus susceptible to exploit. (Source: engadget.com)
As a simple analogy, the vulnerability acted like a hole in a wall, which then allows hackers to remotely access the computer. Ormandy demonstrated the flaw by remotely forcing a computer to open the Windows calculator, but said it would have been just as simple to access the list of stored usernames passwords in the Password Manager itself.
Trend Micro Patch a Must Install
Trend Micro quickly acknowledged the bug and thanked Google for its vigilance. It has now issued a patch for the vulnerability, which users should install immediately. Of course, keeping security software updated is good practice and helps to ensure that the system has the latest signature database of known threats.
Two weeks ago, Ormandy uncovered a serious problem with a Chrome browser extension created by another security firm, AVG. In that case, AVG had deliberately crafted the extension to bypass Google's own security measures. The matter is so severe that Google may blacklist AVG entirely from Chrome.
What's Your Opinion?
Do you use Trend Micro's password manager software? Do you worry about security on such tools? Do you think its safer to use a password manager that's a standalone product from a dedicated company rather than an add-on tool in an antivirus package?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.
Comments
I would guess it's safer to use a standalone product...
... since a standalone product is designed and built expressly for that purpose.
But it's still a crapshoot, IMO.
I'm using KeePass 2. It's open source, so that's good, but I don't have Windows programming skills. Has any independent party reviewed the source code line by line? If yes, *who* is the "independent party"? And how independent, honest, and capable are they?
In all honesty, I have to go on the fact that KeePass 2 is a very mature product and has good reviews / recommendations from seemingly knowledgeable and trustworthy sources.