Language Selection

English French German Italian Portuguese Spanish

Password Management Concerns with IE and Firefox

Filed under
Security

This two-part paper presents an analysis of the security mechanisms, risks, attacks, and defenses of the two most commonly used password management systems for web browsers, found in Internet Explorer and Firefox. The article specifically addresses IE 6 and 7 and Firefox 1.5 and 2.0. Attention is devoted to the following areas:

  • Password storage mechanisms: The means of safeguarding usernames and passwords on the local file system through encryption (addressed in part 1).

  • Attacks on Password Managers: The methods of subverting or bypassing safeguards (partially addressed in part 1; continued in part 2).
  • False sense of security: Users employing password managers without any awareness of the risk factors (discussed in part 2).
  • Usability: Features that enhance or deter the usability of security features (discussed in part 2).
  • Mitigation and Countermeasures: Actions that can be taken by users and corporations to reduce the risk (part 2).

Internet Explorer and Firefox together amass roughly ninety-five percent of all browser market share. [ref 1] AutoComplete [ref 2] and Password Manager [ref 3] are the features that store web form usernames, passwords, and URLs for Internet Explorer (since version 4), and Firefox (since version 0.7), respectively.

Each browser has helpful features to aid the user from being tasked with remembering different usernames and passwords as a means of authentication for web sites. Thus when navigating to a URL such as http://www.gmail.com where form input fields are present, both IE and Firefox will prompt the user if he or she wants to save their username and password. When the user re-visits the same web site the browser will automatically fill the fields.

Although these features greatly simplify the responsibility of the user, they also introduce security considerations that are addressed in the next few sections.

Part One
Part Two

More in Tux Machines

[GNU IceCat] browser is (finally) on Fedora

GNU Icecat will be available on Fedora updates-testing repositories for some days. That’s right time to test harshly this new web browser (really it’s not so new considering it’s a fork of Firefox) and leave a positive/negative karma or open a bug. Read more

today's howtos

today's howtos

Leftovers: Gaming

  • Ryan Icculus Gordon On The Linux Action Show
    Ryan Icculus Gordon has just recently been on a guest on the excellent Linux Action Show to talk about Linux gaming. Ryan Icculus Gordon is the name behind a number of big ports, and you can see here just what he has done. Hint: It's a lot.
  • Empire: Total War Looks Close To A Linux Version, Pokes Fun At Linux Gamers
    We already knew that Total War: Rome II would come to Linux which sadly didn't come out when expected early this year, but now it looks like the original Empire: Total War will come to Linux too.
  • Another (Linux) game added to the Humble Jumbo Bundle 2
    - Legend of Grimrock: Old school and modern gaming combines in this thrilling dungeon crawler RPG from Almost Human Games. A group of prisoners are sentenced to certain death by exile to the secluded Mount Grimrock for vile crimes they may or may not have committed. Unbeknownst to their captors, the mountain is riddled with ancient tunnels, dungeons, and tombs built by crumbled civilizations long perished now. If they ever wish to see daylight again and reclaim their freedom, the ragtag group of prisoners must form a team and descend through the mountain, level by level.