Құпия сөздерді сақтау және басқару бағдарламасы туралы ақпарат. Онлайн қызметтер үшін күшті құпия сөздер жасау, сақтау және автоматты түрде енгізуге көмектеседі.
Ағылшыншамен салыстырыңыз: абзацты басыңыз — түпнұсқа терезеде ашылады. Абзац астындағы EN түймесі оны мәтін ішінде көрсетеді.
Мазмұны
Кіріспе
Құпия сөздерді сақтау және басқаруға арналған қосымша. Құпия сөздерді басқарушы – пайдаланушыларға жергілікті қосымшалар немесе веб-қосымшалар, онлайн-дүкендер немесе әлеуметтік желілер сияқты онлайн-қызметтер үшін құпия сөздерді сақтауға және басқаруға мүмкіндік беретін компьютерлік бағдарлама. Веб-браузерде әдетте құпия сөздерді басқарушының кіріктірілген нұсқасы болады. Көптеген жағдайларда олар құпия сөздерді қарапайым мәтін түрінде сақтағандықтан, хакерлік шабуылдарға ұшырау мүмкіндігін тудырады, сондықтан олар жиі сынап-тексеріледі. Құпия сөздерді басқарушылар құпия сөздерді жасауға және онлайн нысандарды автоматты түрде толтыруға көмектеседі. Құпия сөздерді басқарушы құпия сөздерді жасауға, оларды әдетте шифрланған деректер базасында сақтауға көмектеседі. Құпия сөздерден басқа, бұл қосымшалар кредиттік карта туралы ақпарат, мекенжайлар және жиі ұшатын жолаушылар туралы мәліметтер сияқты деректерді де сақтай алады. Құпия сөздерді басқарушылар көп факторлы аутентификацияны қосуға мүмкіндік береді, бірақ бұл қосымшаны/браузер кеңейтімді пайдалану үшін міндетті емес.
Application for storing and managing passwords
A password manager is a computer program that allows users to store and manage their passwords for local applications or online services such as web applications, online shops or social media. A web browser generally has a built in version of a password manager. These have been criticised frequently as many have stored the passwords in plaintext, allowing hacking attempts. Password managers can generate passwords and fill online forms. A password manager may assist in generating passwords, storing passwords, usually in an encrypted database. Aside from passwords, these applications may also store data such as credit card information, addresses, and frequent flyer information. Password managers may choose to integrate multi factor authentication Although, this is not required to use the application/browser extension.
Тарих
Парольдерді қауіпсіз сақтауға арналған алғашқы пароль менеджері – Брюс Шнайердің Password Safe бағдарламасы, ол 1997 жылдың 5 қыркүйегінде тегін пайдалануға арналған құрал ретінде жарық көрді. Microsoft Windows 95 үшін жасалған Password Safe, парольдер мен басқа да құпия деректерді шифрлау үшін Шнайердің Blowfish алгоритмін қолданды. Password Safe тегін бағдарлама ретінде шығарылғанмен, сол кездегі АҚШ криптографиялық экспорт шектеулеріне байланысты, бастапқыда оны жүктеуге тек АҚШ және Канада азаматтары мен тұрақты түрде тұратындарға ғана рұқсат етілді.
The first password manager software designed to securely store passwords was Password Safe created by Bruce Schneier, which was released as a free utility on September 5, 1997. Designed for Microsoft Windows 95, Password Safe used Schneier's Blowfish algorithm to encrypt passwords and other sensitive data. Although Password Safe was released as a free utility, due to U. S. cryptography export restrictions in place at the time, only U. S. and Canadian citizens and permanent residents were initially allowed to download it. Browser based password managers These are built directly into web browsers like Chrome, Safari, Firefox, and Edge. They offer convenient access for basic password management on the device where the browser is used. However, some may lack features like secure syncing across devices or strong encryption. Local password managers These are standalone applications installed on a user's device. They offer strong security as passwords are stored locally, but access may be limited to that specific device. Popular open source options include KeePass and Password Safe. Cloud based password managers These store passwords in encrypted form on remote servers, allowing access from supported internet connected devices. They typically offer features like automatic syncing, secure sharing, and strong encryption. Examples include 1Password, Bitwarden, and Dashlane. Enterprise password managers Designed for businesses, these cater to managing access credentials within an organization. They integrate with existing directory services and access control systems, often offering advanced features like role based permissions and privileged access management. Leading vendors include CyberArk and Delinea (formerly Thycotic). Hardware password managers These physical devices, often USB keys, provide an extra layer of security for password management. Some function as secure tokens for account/database access, such as Yubikey and OnlyKey, while others also offer offline storage for passwords, such as OnlyKey.
**Шығанаққа негізделген пароль менеджерлері:** Бұл құралдар Chrome, Safari, Firefox және Edge сияқты веб-браузерлерге тікелей енгізілген. Олар браузер қолданылатын құрылғыда қарапайым парольдерді басқаруға ыңғайлы қол жеткізуді ұсынады. Дегенмен, кейбіреулері құрылғылар арасындағы қауіпсіз синхрондау немесе күшті шифрлау сияқты мүмкіндіктерден мүресіз болуы мүмкін.
The first password manager software designed to securely store passwords was Password Safe created by Bruce Schneier, which was released as a free utility on September 5, 1997. Designed for Microsoft Windows 95, Password Safe used Schneier's Blowfish algorithm to encrypt passwords and other sensitive data. Although Password Safe was released as a free utility, due to U. S. cryptography export restrictions in place at the time, only U. S. and Canadian citizens and permanent residents were initially allowed to download it. Browser based password managers These are built directly into web browsers like Chrome, Safari, Firefox, and Edge. They offer convenient access for basic password management on the device where the browser is used. However, some may lack features like secure syncing across devices or strong encryption. Local password managers These are standalone applications installed on a user's device. They offer strong security as passwords are stored locally, but access may be limited to that specific device. Popular open source options include KeePass and Password Safe. Cloud based password managers These store passwords in encrypted form on remote servers, allowing access from supported internet connected devices. They typically offer features like automatic syncing, secure sharing, and strong encryption. Examples include 1Password, Bitwarden, and Dashlane. Enterprise password managers Designed for businesses, these cater to managing access credentials within an organization. They integrate with existing directory services and access control systems, often offering advanced features like role based permissions and privileged access management. Leading vendors include CyberArk and Delinea (formerly Thycotic). Hardware password managers These physical devices, often USB keys, provide an extra layer of security for password management. Some function as secure tokens for account/database access, such as Yubikey and OnlyKey, while others also offer offline storage for passwords, such as OnlyKey.
**Жергілікті пароль менеджерлері:** Бұл пайдаланушының құрылғысына орнатылатын дербес бағдарламалар. Парольдер жергілікті түрде сақталығандықтан, олар жоғары деңгейдегі қауіпсіздікті қамтамасыз етеді, бірақ қол жеткізу тек сол құрылғымен шектелуі мүмкін. Танымал ашық кодты нұсқаларына KeePass және Password Safe жатады.
The first password manager software designed to securely store passwords was Password Safe created by Bruce Schneier, which was released as a free utility on September 5, 1997. Designed for Microsoft Windows 95, Password Safe used Schneier's Blowfish algorithm to encrypt passwords and other sensitive data. Although Password Safe was released as a free utility, due to U. S. cryptography export restrictions in place at the time, only U. S. and Canadian citizens and permanent residents were initially allowed to download it. Browser based password managers These are built directly into web browsers like Chrome, Safari, Firefox, and Edge. They offer convenient access for basic password management on the device where the browser is used. However, some may lack features like secure syncing across devices or strong encryption. Local password managers These are standalone applications installed on a user's device. They offer strong security as passwords are stored locally, but access may be limited to that specific device. Popular open source options include KeePass and Password Safe. Cloud based password managers These store passwords in encrypted form on remote servers, allowing access from supported internet connected devices. They typically offer features like automatic syncing, secure sharing, and strong encryption. Examples include 1Password, Bitwarden, and Dashlane. Enterprise password managers Designed for businesses, these cater to managing access credentials within an organization. They integrate with existing directory services and access control systems, often offering advanced features like role based permissions and privileged access management. Leading vendors include CyberArk and Delinea (formerly Thycotic). Hardware password managers These physical devices, often USB keys, provide an extra layer of security for password management. Some function as secure tokens for account/database access, such as Yubikey and OnlyKey, while others also offer offline storage for passwords, such as OnlyKey.
**Бұлтқа негізделген пароль менеджерлері:** Бұл құралдар парольдерді шифрланған түрде қашықтағы серверлерде сақтайды, осылайша интернетке қосылған құрылғылардан қол жеткізуге мүмкіндік береді. Олар әдетте автоматты синхрондау, қауіпсіз бөлісу және күшті шифрлау сияқты мүмкіндіктерді ұсынады. Мысалдарға 1Password, Bitwarden және Dashlane кіреді.
The first password manager software designed to securely store passwords was Password Safe created by Bruce Schneier, which was released as a free utility on September 5, 1997. Designed for Microsoft Windows 95, Password Safe used Schneier's Blowfish algorithm to encrypt passwords and other sensitive data. Although Password Safe was released as a free utility, due to U. S. cryptography export restrictions in place at the time, only U. S. and Canadian citizens and permanent residents were initially allowed to download it. Browser based password managers These are built directly into web browsers like Chrome, Safari, Firefox, and Edge. They offer convenient access for basic password management on the device where the browser is used. However, some may lack features like secure syncing across devices or strong encryption. Local password managers These are standalone applications installed on a user's device. They offer strong security as passwords are stored locally, but access may be limited to that specific device. Popular open source options include KeePass and Password Safe. Cloud based password managers These store passwords in encrypted form on remote servers, allowing access from supported internet connected devices. They typically offer features like automatic syncing, secure sharing, and strong encryption. Examples include 1Password, Bitwarden, and Dashlane. Enterprise password managers Designed for businesses, these cater to managing access credentials within an organization. They integrate with existing directory services and access control systems, often offering advanced features like role based permissions and privileged access management. Leading vendors include CyberArk and Delinea (formerly Thycotic). Hardware password managers These physical devices, often USB keys, provide an extra layer of security for password management. Some function as secure tokens for account/database access, such as Yubikey and OnlyKey, while others also offer offline storage for passwords, such as OnlyKey.
**Кәсіпорындық пароль менеджерлері:** Бизнес үшін жасалған бұл құралдар ұйым ішіндегі кіру деректерін басқаруға арналған. Олар қолданыстағы каталогтық қызметтермен және кіруді бақылау жүйелерімен интеграцияланып, рөлге негізделген рұқсаттар мен артықшылықты кіруді басқару сияқты кеңейтілген мүмкіндіктерді ұсынады. Жетекші жеткізушілер CyberArk және Delinea (бұрынғы Thycotic) болып табылады.
The first password manager software designed to securely store passwords was Password Safe created by Bruce Schneier, which was released as a free utility on September 5, 1997. Designed for Microsoft Windows 95, Password Safe used Schneier's Blowfish algorithm to encrypt passwords and other sensitive data. Although Password Safe was released as a free utility, due to U. S. cryptography export restrictions in place at the time, only U. S. and Canadian citizens and permanent residents were initially allowed to download it. Browser based password managers These are built directly into web browsers like Chrome, Safari, Firefox, and Edge. They offer convenient access for basic password management on the device where the browser is used. However, some may lack features like secure syncing across devices or strong encryption. Local password managers These are standalone applications installed on a user's device. They offer strong security as passwords are stored locally, but access may be limited to that specific device. Popular open source options include KeePass and Password Safe. Cloud based password managers These store passwords in encrypted form on remote servers, allowing access from supported internet connected devices. They typically offer features like automatic syncing, secure sharing, and strong encryption. Examples include 1Password, Bitwarden, and Dashlane. Enterprise password managers Designed for businesses, these cater to managing access credentials within an organization. They integrate with existing directory services and access control systems, often offering advanced features like role based permissions and privileged access management. Leading vendors include CyberArk and Delinea (formerly Thycotic). Hardware password managers These physical devices, often USB keys, provide an extra layer of security for password management. Some function as secure tokens for account/database access, such as Yubikey and OnlyKey, while others also offer offline storage for passwords, such as OnlyKey.
**Жабдықтық пароль менеджерлері:** Көбінесе USB кілттері болып табылатын бұл физикалық құрылғылар парольдерді басқару үшін қосымша қауіпсіздік деңгейін қамтамасыз етеді. Кейбіреулері, мысалы Yubikey және OnlyKey, есептік жазбаларға/деректер қорына кіру үшін қауіпсіз токендер ретінде жұмыс істейді, ал басқалары, мысалы OnlyKey, парольдерді оффлайн сақтау мүмкіндігін ұсынады.
The first password manager software designed to securely store passwords was Password Safe created by Bruce Schneier, which was released as a free utility on September 5, 1997. Designed for Microsoft Windows 95, Password Safe used Schneier's Blowfish algorithm to encrypt passwords and other sensitive data. Although Password Safe was released as a free utility, due to U. S. cryptography export restrictions in place at the time, only U. S. and Canadian citizens and permanent residents were initially allowed to download it. Browser based password managers These are built directly into web browsers like Chrome, Safari, Firefox, and Edge. They offer convenient access for basic password management on the device where the browser is used. However, some may lack features like secure syncing across devices or strong encryption. Local password managers These are standalone applications installed on a user's device. They offer strong security as passwords are stored locally, but access may be limited to that specific device. Popular open source options include KeePass and Password Safe. Cloud based password managers These store passwords in encrypted form on remote servers, allowing access from supported internet connected devices. They typically offer features like automatic syncing, secure sharing, and strong encryption. Examples include 1Password, Bitwarden, and Dashlane. Enterprise password managers Designed for businesses, these cater to managing access credentials within an organization. They integrate with existing directory services and access control systems, often offering advanced features like role based permissions and privileged access management. Leading vendors include CyberArk and Delinea (formerly Thycotic). Hardware password managers These physical devices, often USB keys, provide an extra layer of security for password management. Some function as secure tokens for account/database access, such as Yubikey and OnlyKey, while others also offer offline storage for passwords, such as OnlyKey.
Қамқордағы қоршаудың әлсіздігі
Кейбір қолданбалар парольдерді шифрланбаған файл түрінде сақтайды, бұл парольдерді зиянды бағдарламаларға немесе жеке ақпаратты ұрлауға талпынған адамдарға оңай жете алуға мүмкіндік береді.
Some applications store passwords as an unencrypted file, leaving the passwords easily accessible to malware or people attempted to steal personal information.
Бір сәтсіздік нүктесі ретінде негізгі пароль
Кейбір парольдерді басқарушы бағдарламалар қолданушы таңдаған негізгі пароль немесе құпия сөз тіркесін қажет етеді, ол қолданбаға оқу үшін сақталған парольдерді шифрлеуге пайдаланылады. Бұл тәсілдің қауіпсіздігі таңдалған парольдің күштілігіне (оны зиянды бағдарлама арқылы болжауға болады) және құпия сөз тіркесінің өзі зиянды бағдарлама немесе жеке тұлға оқи алатын жерде сақталмауына байланысты. Компромиссияланған негізгі пароль барлық қорғалған парольдерді осал қылуы мүмкін, яғни бір кіру нүктесі құпия ақпараттың құпиялылығын бұзуы мүмкін. Бұл бір ғана сәтсіздік нүктесі деп аталады.
Some password managers require a user selected master password or passphrase to form the key used to encrypt passwords stored for the application to read. The security of this approach depends on the strength of the chosen password (which may be guessed through malware), and also that the passphrase itself is never stored locally where a malicious program or individual could read it. A compromised master password may render all of the protected passwords vulnerable, meaning that a single point of entry can compromise the confidentiality of sensitive information. This is known as a single point of failure.
Құрылғының қауіпсіздігіне тәуелділік
Парольдерді басқарушы жүйелер сенімхаттарды күшті қорғауға мүмкіндік берсе де, олардың тиімділігі пайдаланушы құрылғысының қауіпсіздігіне байланысты. Егер құрылғы Raccoon сияқты, деректерді ұрлауда шеберлік танытатын зиянды бағдарламамен бұзылса, пароль менеджерінің қорғауы күшін жояды. Кіллоггерлер сияқты зиянды бағдарламалар пароль менеджеріне кіруге қолданылатын бас парольді ұрлап, сақталған барлық деректерге толық қол жеткізуге мүмкіндік береді. Клипбордты бақылаушылар менеджерден көшірілген құпия ақпаратты ұстап алады, ал кейбір зиянды бағдарламалар тіпті шифрланған парольдік сақтау файлын ұрлай алады. Қорыта айтқанда, парольді ұрлайтын зиянды бағдарламалық жасақтама орнатылған құрылғы пароль менеджерінің қауіпсіздік шараларын айналып өтіп, сақталған деректерді әлсіз қалдырады. Парольді растау әдістері сияқты, кілтті тіркеу немесе акустикалық криптоанализ "бас парольді" болжау немесе көшіру үшін қолданылуы мүмкін, ол басылған кілттерді тіркеп, құпия ақпаратқа қол жеткізуге тырысатын адамдарға қандай кілт басылғанын жібереді.
While password managers offer robust security for credentials, their effectiveness hinges on the user's device security. If a device is compromised by malware like Raccoon, which excels at stealing data, the password manager's protections can be nullified. Malware like keyloggers can steal the master password used to access the password manager, granting full access to all stored credentials. Clipboard sniffers can capture sensitive information copied from the manager, and some malware might even steal the encrypted password vault file itself. In essence, a compromised device with password stealing malware can bypass the security measures of the password manager, leaving the stored credentials vulnerable. As with password authentication techniques, key logging or acoustic cryptanalysis may be used to guess or copy the "master password". that take the keystrokes and send what key was pressed to the person/people trying to access confidential information.
Бұлт-негізделген сақтау
Бұлтты негіздегі парольдерді басқару жүйелері кіру деректерін сақтау үшін орталықтандырылған орын ұсынады. Дегенмен, мұндай тәсіл қауіпсіздік туралы алаңдаушылықтар тудырады. Бір мүмкін осал тұс – парольдерді басқару жүйесінің өзінде деректердің бұзылуы. Егер мұндай жағдай болса, шабуылшылар көптеген пайдаланушылардың кіру деректеріне қол жеткізе алады. 2022 жылы LastPass компаниясында болған қауіпсіздік оқиғасы осы тәуекелді көрсетеді.
Cloud based password managers offer a centralized location for storing login credentials. However, this approach raises security concerns. One potential vulnerability is a data breach at the password manager itself. If such an event were to occur, attackers could potentially gain access to a large number of user credentials. A 2022 security incident involving LastPass exemplifies this risk.
Пароль генераторының қауіпсіздігі
Кейбір парольдерді басқару құралдары пароль генераторын қамтиды. Егер пароль менеджері барлық осы бағдарлама арқылы жасалған парольдер үшін кездейсоқ "тұқымды" өте әлсіз әдіспен құратын болса, жасалған парольдерді болжау мүмкін. Мысалы, 2021 жылы Kaspersky Password Manager-де болған жайтта, пароль жасау әдісіндегі қателік болжамды парольдерге алып келді.
Some password managers may include a password generator. Generated passwords may be guessable if the password manager uses a weak method of randomly generating a "seed" that all passwords generated by this program. There are documented cases, like the one with Kaspersky Password Manager in 2021, where a flaw in the password generation method resulted in predictable passwords.
Басқалар
Карнеги Меллон университетінің зерттеушілері 2014 жылы жариялаған мақаласында, егер кіру бетінің протоколы (HTTP және HTTPS) пароль сақталған кездегіден өзгеше болса, браузерлер парольдерді автоматты түрде толтырудан бас тартады. Алайда, кейбір пароль менеджерлері шифрланған (HTTPS) сайттар үшін сақталған парольдерді шифрланбаған (HTTP) нұсқасы арқылы қауіпсіз емес түрде толтырған. Сонымен қатар, көптеген менеджерлер iframe және қайта бағыттау шабуылдарына қарсы қорғанысқа ие болмаған, бұл бірнеше құрылғыда парольді синхрондау қолданылғанда қосымша парольдердің ашылуына әкелуі мүмкін. Бұл шаралар автоматтандырылған шабуылдардан қорғау, фишингтен сақтау, зиянды бағдарламаларды тоқтату немесе үйлесімділікті қамтамасыз ету мақсатында жасалған. IBM-нің Trusteer клиенттік қауіпсіздік бағдарламалық құралы пароль менеджерлерін тоқтатуға арналған нақты опцияларды ұсынады. Ақпараттық қауіпсіздік мамандары мұндай тоқтатуды пайдаланушылардың қауіпсіздігін азайтады деп сынаған. Мысалы, Firefox 38, Chrome 34 және Safari 7.0.2 нұсқаларында.
A 2014 paper by researchers at Carnegie Mellon University found that while browsers refuse to autofill passwords if the login page protocol differs from when the password was saved (HTTP vs. HTTPS), some password managers insecurely filled passwords for the unencrypted (HTTP) version of saved passwords for encrypted (HTTPS) sites. Additionally, most managers lacked protection against iframe and redirection based attacks, potentially exposing additional passwords when password synchronization was used across multiple devices. Reasons cited have included protecting against automated attacks, protecting against phishing, blocking malware, or simply denying compatibility. The Trusteer client security software from IBM features explicit options to block password managers. Such blocking has been criticized by information security professionals as making users less secure. such as Firefox 38, Chrome 34, and Safari from about 7.0.2.