Password managers are Korean College Girl Room Salon (2025)a vital line of defense in the battle for internet security — which makes it all the more painful when they shit the bed.
The Kaspersky Password Manager (KPM), a free tool used to generate and manage online passwords, has long been a popular alternative to the likes of LastPass or 1Password. Unfortunately, according to security researcher Jean-Baptiste Bédrune, a bad coding decision meant that the passwords it generated weren't truly random and as a result were relatively easy to brute force — a hacking technique using specialized tools to try hundreds of thousands (or millions) of password combinations in an attempt to guess the right one.
Bédrune, who is a security researcher for the cryptocurrency hard-wallet company Ledger, writes that when generating a supposedly random password, KPM used the current time as its "single source of entropy."
While that sounds super technical, it essentially boils down to KPM using the time as the basis for its pseudo random number generator. Knowing when the password was generated, even approximately, would therefore give a hacker vital information in an attempt to crack a victim's account.
"All the passwords it created could be bruteforced in seconds," writes Bédrune.
Bédrune's team submitted the vulnerability to Kaspersky through HackerOne's bug bounty program in June of 2019, and Ledger's blog post says Kaspersky notified potentially affected users in October of 2020.
When reached for comment, Kaspersky confirmed — but downplayed — the problem identified by Bédrune.
"This issue was only possible in the unlikely event that the attacker knew the user's account information and the exact time a password had been generated," wrote a company spokesperson. "It would also require the target to lower their password complexity settings."
Kaspersky also published a security advisory detailing the flaw in April of 2021.
"Password generator was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases," read the alert. "An attacker would need to know some additional information (for example, time of password generation)."
That alert also noted that, going forward, the password manager had fixed the issue — a claim echoed by the spokesperson.
"The company has issued a fix to the product and has incorporated a mechanism that notifies users if a specific password generated by the tool could be vulnerable and needs changing."
SEE ALSO: Why you need a secret phone number (and how to get one)
So what does this mean for the average KPM user? Well, if they've been using the same KPM-generated passwords for over two years (a habit that would typically be fine), they should create new ones.
Other than that? Keep using a password manager and enable two-factor authentication.
Topics Cybersecurity
Hurricane Florence replaced its eyewall. What does that mean?All the best dance moves from the Republican National ConventionTaylor Swift responds to Kanye and Kim Kardashian's 'character assassination'Donald Trump entered the Republican National Convention like a extraterrestrial wrestling superstarMelania Trump accused of plagiarizing Michelle Obama speech, Rickrolling AmericaA man on a leash, a polar bear and other bizarre things at the Republican National ConventionApple announces release date for iOS 12Facebook's Rosetta AI can read all the memesBob Woodward's Trump book is bad, boring, and bogusHere's how to choose between the iPhone XR, XS, and XS Max10 video games we can't wait to escape with this fallA Harry Potter star is joining 'Dancing With the Stars'Here's how much the Apple Watch Series 4 will cost youMark Zuckerberg subtly made a case for not breaking up FacebookThis probably fake app gets other people to pick up your dog's poopApple didn't mention anything about AirPower, AirPods, or iPadsMelania Trump is mercilessly mocked by Twitter after accusations of plagiarismThe top 10 video game boyfriends, rankedAlleged burglar uses 'Pokémon Go' as excuse, police are not impressedHere's how to choose between the iPhone XR, XS, and XS Max TV characters from 2019 that would make really great Halloween costumes Pornhub reveals that Super Bowl halftime porn is a thing UPS drones get FAA approval, but don't expect them at your house After 11 years, the feud between Chili's and 'The Office's Pam Beesly is now over Microsoft teases dual Just a bunch of amazing cosplay from New York Comic Con Mum slams Trump on Facebook for calling daughter's murder 'terrorism' The truth behind Airbnb's Super Bowl ad TikTok will be mercifully free of political ads Mash up all your favourite 2000s tunes with this very addictive website Floating LED sculpture educates public about water quality J.K. Rowling's response to this meme about her death is absolutely classic Glenlivet's Tide Pod Céline Dion photobombed a couple's proposal and her reaction was priceless Wikipedia has only granted one takedown request. Here it is. Restaurant bill reminds customers that 'immigrants make America great' Simone Biles nails signature dismount, now known as 'The Biles' Just when you thought there was nothing else to leak, the Google Pixel 4 spec sheet shows up Dad receives unintentionally hilarious letter from son's school This 'Handmaid's Tale' wedding photo seems like it was not a good idea
2.2083s , 8203.3828125 kb
Copyright © 2025 Powered by 【Korean College Girl Room Salon (2025)】,Miracle Information Network