
Ledger Donjon experts found that the passwords generated by Kaspersky Password Manager only looked random. In fact, they were created by a generator of pseudo -random numbers and strictly depended on the moment when the user pressed the new password button. This moment, or rather, the system time of the device in seconds - became the number of SEED, on the basis of which the Kaspersky Password Manager generator worked.
As a result, if two Kaspersky Password Manager clients in different parts of the light at the same time - literally at the same second - clicked on the button and at the same time left other default settings, the generator gave the same result and both received an identical password.
Only if during the generation the user changed the length of the password and a set of characters used (such an option is in the manager), the password turned out to be different.
Not only - and not so much in this. The worse is that over the past decade (2011-2020), only 315 million 619 thousand 200 seconds have passed. Exactly so many passwords with default settings could generate Kaspersky Password Manager. The attacker could very quickly (with the help of special recruiting programs) to recreate this whole list and then use it to hack the overcoming of encrypted archives, documents, flash drives and hard drives.
And if he could at least approximately find out when the victim got a password in Kaspersky Password Manager, then hacking would become radically easier: one could even try to sort out passwords of another length and with a different set of characters (in this case, the options for the number of SEED, thanks to which they are restored, are much less).
According to the researchers, perhaps vulnerability remains unnoticed by the animation that imitated symbols when creating a password. Between the click, as a result of which the generator stopped the work, and the appearance of a password on the screen passed more than one second. And even if the user would immediately click the next time after that, the password would have been different. The user simply did not have the opportunity to find out that the same passwords are generated within one second.
The generation of identical passwords was the main, but not the only problem with the Kaspersky Password Manager, discovered by the Ledger Donjon researchers. So, for example, the pseudo -random number, chosen by the Kaspersky Laboratory, did not have all the properties that allow it to be used in cryptography. And the characters in the generated password fell out and were not located with the same probability, that is, not quite randomly. Experts suggested that so the developers of the password manager wanted to make the attack on the dictionaries to be made. In this case, the attackers sort through passwords using dictionaries (sometimes slightly modified, for example, the letter “o” changes to the number “0”). In this manager it was done like this: more often such sequences of letters fall out that are not found in ordinary words. But if the attacker knew for sure that the victim created a password using Kaspersky Password Manager, then he could modify his attack and in theory to choose a password faster than it would be with an absolutely random sequence of numbers, letters and characters.
If you use the password manager from the Kaspersky Lab, check that you do not have programs with versions before these:
If necessary, upgrade and be sure to change all your old passwords.
The Kaspersky Laboratory in the Medusa comment also said that she introduced the mechanism, thanks to which users receive special notifications, if the generated password is not reliable enough and should be changed.
Denis Dmitriev