Hey, you, get off of my clipboard: On how usability trumps security in android password managers

28Citations
Citations of this article
36Readers
Mendeley users who have this article in their library.
Get full text

Abstract

Password managers aim to help users manage their ever increasing number of passwords for online authentication. Since users only have to memorise one master secret to unlock an encrypted password database or key chain storing all their (hopefully) different and strong passwords, password managers are intended to increase username/password security. With mobile Internet usage on the rise, password managers have found their way onto smartphones and tablets. In this paper, we analyse the security of password managers on Android devices. While encryption mechanisms are used to protect credentials, we will show that a usability feature of the investigated mobile password managers puts the users' usernames and passwords at risk. We demonstrate the consequences of our findings by analysing 21 popular free and paid password managers for Android. We then make recommendations how to overcome the current problems and provide an implementation of a secure and usable mobile password manager. © 2013 Springer-Verlag.

Cite

CITATION STYLE

APA

Fahl, S., Harbach, M., Oltrogge, M., Muders, T., & Smith, M. (2013). Hey, you, get off of my clipboard: On how usability trumps security in android password managers. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 7859 LNCS, pp. 144–161). https://doi.org/10.1007/978-3-642-39884-1_12

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free