Why password managers are not as secure as you think
University researchers have raised concerns about the security of web-based password managers that free people from the burden of having to remember website credentials.
Scientists at the University of California, Berkeley, studied five password managers and found vulnerabilities in diverse features like one-time passwords, shared passwords and "bookmarklets," which are used to sign into websites on mobile browsers.
"The root causes of the vulnerabilities are also diverse: ranging from logic and authorization mistakes to misunderstandings about the web security model," the researchers said in a paper scheduled to be presented in August at the Usenix Security Symposium in San Diego.