• Kaspersky easy-to-guess passwords

    Author
    Topic
    #2376507

    Hello,
    Recently, I read, that Kaspersky password manager generated passwords, that are easy to crack.
    The vulnerability was given name CVE-2020-27020.

    Safe version should be Kaspersky Password Manager 9.0.2 Patch F.

    Source: donjon.ledger.com

    Dell Latitude 3420, Intel Core i7 @ 2.8 GHz, 16GB RAM, W10 22H2 Enterprise

    HAL3000, AMD Athlon 200GE @ 3,4 GHz, 8GB RAM, Fedora 29

    PRUSA i3 MK3S+

    Viewing 2 reply threads
    Author
    Replies
    • #2376784

      They are only easy to crack if you know they were generated by Kaspersky.

      Any password that is long (> 16 characters) is going to take too long to guess in an attack against an online service. Using a long badly generated password is always better than using a short password.

      If you have an offline service (your password database) then you need a long and relatively complex password. Again, length is better than complexity.

      cheers, Paul

      • #2377013

        I wanted to warn users, that are using this application, that they should upgrade their app.

        Dell Latitude 3420, Intel Core i7 @ 2.8 GHz, 16GB RAM, W10 22H2 Enterprise

        HAL3000, AMD Athlon 200GE @ 3,4 GHz, 8GB RAM, Fedora 29

        PRUSA i3 MK3S+

    • #2377014

      The problem was fixed ages ago and disclosed recently (responsible notification). Users should already have updated, but the warning is appropriate.  🙂

      cheers, Paul

    • #2377825

      You don’t really need any of these “password generators” at all. Just think of a person, place or thing, translate it into some weird language that uses Latin script, then stick some squirrel noises in there with it.

      Easy-Peasy.

      Win7 Pro SP1 64-bit, Dell Latitude E6330 ("The Tank"), Intel CORE i5 "Ivy Bridge", 12GB RAM, Group "0Patch", Multiple Air-Gapped backup drives in different locations. Linux Mint Newbie
      --
      "The more kinks you put in the plumbing, the easier it is to stop up the pipes." -Scotty

      1 user thanked author for this post.
      • #2377828

        I personally dont use password generators. I usually use long sentence-like passwords. EasyPeasyToCrackPassword43 – thats how I like it.
        No #$&84gHXXg^ passwords for me, please. I do store my passwords to the browser, but only for sites like this – forum, eshop – and then for printers and other stuff on the network. I can live when attacker steals my password for the printer.

        No stored password for my banking and so, also I have set 2FA for banking. I like to keep my security simple.

        Dell Latitude 3420, Intel Core i7 @ 2.8 GHz, 16GB RAM, W10 22H2 Enterprise

        HAL3000, AMD Athlon 200GE @ 3,4 GHz, 8GB RAM, Fedora 29

        PRUSA i3 MK3S+

    Viewing 2 reply threads
    Reply To: Kaspersky easy-to-guess passwords

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: