Менеджер паролей: безопасное хранение и управление паролями для сайтов и приложений. Генерация надежных паролей, защита от взлома, удобство использования.
Сравнивайте с английским: нажмите на абзац — оригинал откроется в окне. Кнопка EN под абзацем показывает его прямо в тексте.
Содержание
Введение
Приложение для хранения и управления паролями
Application for storing and managing passwords
Менеджер паролей – это компьютерная программа, позволяющая пользователям хранить и управлять своими паролями для локальных приложений или онлайн-сервисов, таких как веб-приложения, интернет-магазины или социальные сети. Обычно веб-браузер имеет встроенную версию менеджера паролей. Встроенные менеджеры часто подвергались критике, поскольку многие хранили пароли в незашифрованном виде, что делало возможными взломы. Менеджеры паролей могут генерировать пароли и автоматически заполнять онлайн-формы. Менеджер паролей может помогать в создании и хранении паролей, как правило, в зашифрованной базе данных. Помимо паролей, эти приложения могут также хранить данные, такие как информация о кредитных картах, адреса и данные программ лояльности авиакомпаний. Менеджеры паролей могут поддерживать многофакторную аутентификацию, хотя она и не является обязательной для использования приложения или расширения для браузера.
A password manager is a computer program that allows users to store and manage their passwords for local applications or online services such as web applications, online shops or social media. A web browser generally has a built in version of a password manager. These have been criticised frequently as many have stored the passwords in plaintext, allowing hacking attempts. Password managers can generate passwords and fill online forms. A password manager may assist in generating passwords, storing passwords, usually in an encrypted database. Aside from passwords, these applications may also store data such as credit card information, addresses, and frequent flyer information. Password managers may choose to integrate multi factor authentication Although, this is not required to use the application/browser extension.
История
Первым программным обеспечением для управления паролями, предназначенным для безопасного хранения паролей, был Password Safe, созданный Брюсом Шнайером и выпущенный 5 сентября 1997 года в качестве бесплатной утилиты. Разработанный для Microsoft Windows 95, Password Safe использовал алгоритм Blowfish, разработанный Шнайером, для шифрования паролей и других конфиденциальных данных. Несмотря на то, что Password Safe был выпущен как бесплатная утилита, из-за действовавших в то время ограничений на экспорт криптографии в США, первоначально загружать его разрешалось только гражданам и постоянным жителям США и Канады.
The first password manager software designed to securely store passwords was Password Safe created by Bruce Schneier, which was released as a free utility on September 5, 1997. Designed for Microsoft Windows 95, Password Safe used Schneier's Blowfish algorithm to encrypt passwords and other sensitive data. Although Password Safe was released as a free utility, due to U. S. cryptography export restrictions in place at the time, only U. S. and Canadian citizens and permanent residents were initially allowed to download it. Browser based password managers These are built directly into web browsers like Chrome, Safari, Firefox, and Edge. They offer convenient access for basic password management on the device where the browser is used. However, some may lack features like secure syncing across devices or strong encryption. Local password managers These are standalone applications installed on a user's device. They offer strong security as passwords are stored locally, but access may be limited to that specific device. Popular open source options include KeePass and Password Safe. Cloud based password managers These store passwords in encrypted form on remote servers, allowing access from supported internet connected devices. They typically offer features like automatic syncing, secure sharing, and strong encryption. Examples include 1Password, Bitwarden, and Dashlane. Enterprise password managers Designed for businesses, these cater to managing access credentials within an organization. They integrate with existing directory services and access control systems, often offering advanced features like role based permissions and privileged access management. Leading vendors include CyberArk and Delinea (formerly Thycotic). Hardware password managers These physical devices, often USB keys, provide an extra layer of security for password management. Some function as secure tokens for account/database access, such as Yubikey and OnlyKey, while others also offer offline storage for passwords, such as OnlyKey.
Менеджеры паролей на основе браузера: они встроены непосредственно в веб-браузеры, такие как Chrome, Safari, Firefox и Edge, и обеспечивают удобный доступ для базового управления паролями на устройстве, где используется браузер. Однако некоторые из них могут быть лишены таких функций, как безопасная синхронизация между устройствами или надежное шифрование.
The first password manager software designed to securely store passwords was Password Safe created by Bruce Schneier, which was released as a free utility on September 5, 1997. Designed for Microsoft Windows 95, Password Safe used Schneier's Blowfish algorithm to encrypt passwords and other sensitive data. Although Password Safe was released as a free utility, due to U. S. cryptography export restrictions in place at the time, only U. S. and Canadian citizens and permanent residents were initially allowed to download it. Browser based password managers These are built directly into web browsers like Chrome, Safari, Firefox, and Edge. They offer convenient access for basic password management on the device where the browser is used. However, some may lack features like secure syncing across devices or strong encryption. Local password managers These are standalone applications installed on a user's device. They offer strong security as passwords are stored locally, but access may be limited to that specific device. Popular open source options include KeePass and Password Safe. Cloud based password managers These store passwords in encrypted form on remote servers, allowing access from supported internet connected devices. They typically offer features like automatic syncing, secure sharing, and strong encryption. Examples include 1Password, Bitwarden, and Dashlane. Enterprise password managers Designed for businesses, these cater to managing access credentials within an organization. They integrate with existing directory services and access control systems, often offering advanced features like role based permissions and privileged access management. Leading vendors include CyberArk and Delinea (formerly Thycotic). Hardware password managers These physical devices, often USB keys, provide an extra layer of security for password management. Some function as secure tokens for account/database access, such as Yubikey and OnlyKey, while others also offer offline storage for passwords, such as OnlyKey.
Локальные менеджеры паролей: это автономные приложения, установленные на устройстве пользователя. Они обеспечивают высокий уровень безопасности, поскольку пароли хранятся локально, но доступ к ним может быть ограничен этим конкретным устройством. Популярные варианты с открытым исходным кодом включают KeePass и Password Safe.
The first password manager software designed to securely store passwords was Password Safe created by Bruce Schneier, which was released as a free utility on September 5, 1997. Designed for Microsoft Windows 95, Password Safe used Schneier's Blowfish algorithm to encrypt passwords and other sensitive data. Although Password Safe was released as a free utility, due to U. S. cryptography export restrictions in place at the time, only U. S. and Canadian citizens and permanent residents were initially allowed to download it. Browser based password managers These are built directly into web browsers like Chrome, Safari, Firefox, and Edge. They offer convenient access for basic password management on the device where the browser is used. However, some may lack features like secure syncing across devices or strong encryption. Local password managers These are standalone applications installed on a user's device. They offer strong security as passwords are stored locally, but access may be limited to that specific device. Popular open source options include KeePass and Password Safe. Cloud based password managers These store passwords in encrypted form on remote servers, allowing access from supported internet connected devices. They typically offer features like automatic syncing, secure sharing, and strong encryption. Examples include 1Password, Bitwarden, and Dashlane. Enterprise password managers Designed for businesses, these cater to managing access credentials within an organization. They integrate with existing directory services and access control systems, often offering advanced features like role based permissions and privileged access management. Leading vendors include CyberArk and Delinea (formerly Thycotic). Hardware password managers These physical devices, often USB keys, provide an extra layer of security for password management. Some function as secure tokens for account/database access, such as Yubikey and OnlyKey, while others also offer offline storage for passwords, such as OnlyKey.
Облачные менеджеры паролей: они хранят пароли в зашифрованном виде на удаленных серверах, обеспечивая доступ с поддерживаемых устройств, подключенных к Интернету. Обычно они предлагают такие функции, как автоматическая синхронизация, безопасный обмен и надежное шифрование. Примеры включают 1Password, Bitwarden и Dashlane.
The first password manager software designed to securely store passwords was Password Safe created by Bruce Schneier, which was released as a free utility on September 5, 1997. Designed for Microsoft Windows 95, Password Safe used Schneier's Blowfish algorithm to encrypt passwords and other sensitive data. Although Password Safe was released as a free utility, due to U. S. cryptography export restrictions in place at the time, only U. S. and Canadian citizens and permanent residents were initially allowed to download it. Browser based password managers These are built directly into web browsers like Chrome, Safari, Firefox, and Edge. They offer convenient access for basic password management on the device where the browser is used. However, some may lack features like secure syncing across devices or strong encryption. Local password managers These are standalone applications installed on a user's device. They offer strong security as passwords are stored locally, but access may be limited to that specific device. Popular open source options include KeePass and Password Safe. Cloud based password managers These store passwords in encrypted form on remote servers, allowing access from supported internet connected devices. They typically offer features like automatic syncing, secure sharing, and strong encryption. Examples include 1Password, Bitwarden, and Dashlane. Enterprise password managers Designed for businesses, these cater to managing access credentials within an organization. They integrate with existing directory services and access control systems, often offering advanced features like role based permissions and privileged access management. Leading vendors include CyberArk and Delinea (formerly Thycotic). Hardware password managers These physical devices, often USB keys, provide an extra layer of security for password management. Some function as secure tokens for account/database access, such as Yubikey and OnlyKey, while others also offer offline storage for passwords, such as OnlyKey.
Корпоративные менеджеры паролей: разработанные для бизнеса, они предназначены для управления учетными данными доступа в организации. Они интегрируются с существующими службами каталогов и системами контроля доступа, часто предлагая расширенные функции, такие как разрешения на основе ролей и управление привилегированным доступом. Ведущие поставщики включают CyberArk и Delinea (ранее Thycotic).
The first password manager software designed to securely store passwords was Password Safe created by Bruce Schneier, which was released as a free utility on September 5, 1997. Designed for Microsoft Windows 95, Password Safe used Schneier's Blowfish algorithm to encrypt passwords and other sensitive data. Although Password Safe was released as a free utility, due to U. S. cryptography export restrictions in place at the time, only U. S. and Canadian citizens and permanent residents were initially allowed to download it. Browser based password managers These are built directly into web browsers like Chrome, Safari, Firefox, and Edge. They offer convenient access for basic password management on the device where the browser is used. However, some may lack features like secure syncing across devices or strong encryption. Local password managers These are standalone applications installed on a user's device. They offer strong security as passwords are stored locally, but access may be limited to that specific device. Popular open source options include KeePass and Password Safe. Cloud based password managers These store passwords in encrypted form on remote servers, allowing access from supported internet connected devices. They typically offer features like automatic syncing, secure sharing, and strong encryption. Examples include 1Password, Bitwarden, and Dashlane. Enterprise password managers Designed for businesses, these cater to managing access credentials within an organization. They integrate with existing directory services and access control systems, often offering advanced features like role based permissions and privileged access management. Leading vendors include CyberArk and Delinea (formerly Thycotic). Hardware password managers These physical devices, often USB keys, provide an extra layer of security for password management. Some function as secure tokens for account/database access, such as Yubikey and OnlyKey, while others also offer offline storage for passwords, such as OnlyKey.
Аппаратные менеджеры паролей: эти физические устройства, часто USB-ключи, обеспечивают дополнительный уровень безопасности для управления паролями. Некоторые из них функционируют как безопасные токены для доступа к учетным записям/базам данных, такие как Yubikey и OnlyKey, а другие также предлагают автономное хранение паролей, например, OnlyKey.
The first password manager software designed to securely store passwords was Password Safe created by Bruce Schneier, which was released as a free utility on September 5, 1997. Designed for Microsoft Windows 95, Password Safe used Schneier's Blowfish algorithm to encrypt passwords and other sensitive data. Although Password Safe was released as a free utility, due to U. S. cryptography export restrictions in place at the time, only U. S. and Canadian citizens and permanent residents were initially allowed to download it. Browser based password managers These are built directly into web browsers like Chrome, Safari, Firefox, and Edge. They offer convenient access for basic password management on the device where the browser is used. However, some may lack features like secure syncing across devices or strong encryption. Local password managers These are standalone applications installed on a user's device. They offer strong security as passwords are stored locally, but access may be limited to that specific device. Popular open source options include KeePass and Password Safe. Cloud based password managers These store passwords in encrypted form on remote servers, allowing access from supported internet connected devices. They typically offer features like automatic syncing, secure sharing, and strong encryption. Examples include 1Password, Bitwarden, and Dashlane. Enterprise password managers Designed for businesses, these cater to managing access credentials within an organization. They integrate with existing directory services and access control systems, often offering advanced features like role based permissions and privileged access management. Leading vendors include CyberArk and Delinea (formerly Thycotic). Hardware password managers These physical devices, often USB keys, provide an extra layer of security for password management. Some function as secure tokens for account/database access, such as Yubikey and OnlyKey, while others also offer offline storage for passwords, such as OnlyKey.
Слабое хранилище в хранилище
Некоторые приложения хранят пароли в незашифрованном файле, что делает их легкодоступными для вредоносного ПО или злоумышленников, пытающихся похитить личную информацию.
Some applications store passwords as an unencrypted file, leaving the passwords easily accessible to malware or people attempted to steal personal information.
Мастер-пароль как однократная ошибка
Некоторые менеджеры паролей требуют от пользователя выбора главного пароля или парольной фразы для формирования ключа, используемого для шифрования хранимых паролей, доступных приложению для чтения. Безопасность этого подхода зависит от надёжности выбранного пароля (который может быть угадан с помощью вредоносного ПО), а также от того, что сама парольная фраза никогда не сохраняется локально, где её может прочитать вредоносная программа или злоумышленник. Компрометация главного пароля может сделать уязвимыми все защищённые пароли, что означает, что одна точка входа может привести к раскрытию конфиденциальной информации. Это известно как единственная точка отказа.
Some password managers require a user selected master password or passphrase to form the key used to encrypt passwords stored for the application to read. The security of this approach depends on the strength of the chosen password (which may be guessed through malware), and also that the passphrase itself is never stored locally where a malicious program or individual could read it. A compromised master password may render all of the protected passwords vulnerable, meaning that a single point of entry can compromise the confidentiality of sensitive information. This is known as a single point of failure.
Зависимость от безопасности устройства
Хотя менеджеры паролей обеспечивают надежную защиту учетных данных, их эффективность зависит от безопасности устройства пользователя. Если устройство скомпрометировано вредоносным ПО, таким как Raccoon, которое специализируется на краже данных, защита менеджера паролей может быть сведена на нет. Вредоносные программы, такие как кейлоггеры, могут украсть главный пароль, используемый для доступа к менеджеру паролей, предоставив полный доступ ко всем сохраненным учетным данным. Программы-снифферы могут перехватывать конфиденциальную информацию, скопированную из менеджера, а некоторые вредоносные программы могут даже украсть сам зашифрованный файл хранилища паролей. По сути, скомпрометированное устройство с вредоносным ПО, предназначенным для кражи паролей, может обойти меры безопасности менеджера паролей, делая сохраненные учетные данные уязвимыми. Как и в случае методов аутентификации по паролю, для угадывания или копирования "мастер-пароля" могут использоваться кейлоггинг или акустический криптоанализ – методы, фиксирующие нажатия клавиш и передающие информацию о них злоумышленникам, пытающимся получить доступ к конфиденциальным данным.
While password managers offer robust security for credentials, their effectiveness hinges on the user's device security. If a device is compromised by malware like Raccoon, which excels at stealing data, the password manager's protections can be nullified. Malware like keyloggers can steal the master password used to access the password manager, granting full access to all stored credentials. Clipboard sniffers can capture sensitive information copied from the manager, and some malware might even steal the encrypted password vault file itself. In essence, a compromised device with password stealing malware can bypass the security measures of the password manager, leaving the stored credentials vulnerable. As with password authentication techniques, key logging or acoustic cryptanalysis may be used to guess or copy the "master password". that take the keystrokes and send what key was pressed to the person/people trying to access confidential information.
Облачное хранилище
Облачные менеджеры паролей предлагают централизованное хранилище для учетных данных для входа. Однако этот подход вызывает вопросы безопасности. Одной из потенциальных уязвимостей является утечка данных непосредственно в менеджере паролей. В случае такого инцидента злоумышленники могут получить доступ к большому количеству пользовательских учётных записей. Инцидент с LastPass в 2022 году служит примером этой угрозы.
Cloud based password managers offer a centralized location for storing login credentials. However, this approach raises security concerns. One potential vulnerability is a data breach at the password manager itself. If such an event were to occur, attackers could potentially gain access to a large number of user credentials. A 2022 security incident involving LastPass exemplifies this risk.
Безопасность генератора паролей
Некоторые менеджеры паролей могут включать в себя генератор паролей. Сгенерированные пароли могут оказаться уязвимыми для подбора, если менеджер паролей использует слабый метод случайной генерации "затравки", от которой зависят все пароли, созданные этой программой. Известны случаи, например, с Kaspersky Password Manager в 2021 году, когда недостаток в методе генерации паролей привел к созданию предсказуемых паролей.
Some password managers may include a password generator. Generated passwords may be guessable if the password manager uses a weak method of randomly generating a "seed" that all passwords generated by this program. There are documented cases, like the one with Kaspersky Password Manager in 2021, where a flaw in the password generation method resulted in predictable passwords.
Другие
В 2014 году исследователи из Университета Карнеги-Меллона обнаружили, что хотя браузеры отказываются автоматически заполнять пароли, если протокол страницы входа отличается от протокола, при котором пароль был сохранен (HTTP против HTTPS), некоторые менеджеры паролей небезопасно заполняли пароли для незашифрованной (HTTP) версии сохраненных паролей на зашифрованных (HTTPS) сайтах. Кроме того, большинство менеджеров паролей не имели защиты от атак, основанных на использовании iframe и перенаправлений, что потенциально могло привести к раскрытию дополнительных паролей при использовании синхронизации паролей на нескольких устройствах. Среди причин, которые приводились, – защита от автоматизированных атак, защита от фишинга, блокировка вредоносного ПО или просто обеспечение несовместимости. Клиентское программное обеспечение безопасности Trusteer от IBM предоставляет явные опции для блокировки менеджеров паролей. Такая блокировка подвергается критике со стороны специалистов по информационной безопасности, поскольку снижает уровень безопасности пользователей. Например, Firefox 38, Chrome 34 и Safari, начиная с версии 7.0.2.
A 2014 paper by researchers at Carnegie Mellon University found that while browsers refuse to autofill passwords if the login page protocol differs from when the password was saved (HTTP vs. HTTPS), some password managers insecurely filled passwords for the unencrypted (HTTP) version of saved passwords for encrypted (HTTPS) sites. Additionally, most managers lacked protection against iframe and redirection based attacks, potentially exposing additional passwords when password synchronization was used across multiple devices. Reasons cited have included protecting against automated attacks, protecting against phishing, blocking malware, or simply denying compatibility. The Trusteer client security software from IBM features explicit options to block password managers. Such blocking has been criticized by information security professionals as making users less secure. such as Firefox 38, Chrome 34, and Safari from about 7.0.2.