• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / Keeper password manager: once again no security

Keeper password manager: once again no security

10/03/2018 09:24 by giorgos

Keeper password manager development company was found once more not to be so interested in safety. This time, he was using a server that allowed anyone to access and replace files with malicious content, according to a security researcher.keeper 1 - Keeper password manager: once again no security

Chris Vickery, who discovered the exposed server, immediately alerted ZDNet, who attempted to contact Keeper via phone and email on Friday. An hour after disclosure, the server was secured.

However, the director of Aaron Gessner refused any allegations.

The Chicago-based company has a storage server on Amazon S3 to host installers for its various supported platforms.

However, the server was not password protected and gave access to anyone and "full control" of its contents (reading, replacing and deleting files).
keeper jpg - Keeper password manager: once again no security

Many of the files included installation files for Windows, Mac, Android and iPhone. A file on the server had a private signature certificate issued by Apple. The certificate can be used to sign the company's iPhone applications, and was issued to Callpod Inc., a company founded by Keeper CEO Darren Guccione.

Naturally, a specialized attacker could replace a legitimate iPhone or iPad install program with a malicious file.

Let's say the Keeper application developer recently sued the Ars Technica security researcher, And Goodin, because he posted a vulnerability that he discovered in Keeper's password manager browser extension.

Although the company confirmed the vulnerability, it filed a lawsuit against Goodin for allegedly making "false and misleading statements about the Keeper application."

The news provoked many reactions in the security community, which criticized the company's response. Many high-level researchers and known community figures argued that such an action would likely have bad results in future security investigations and vulnerabilities.

  • Secure your Wi-Fi: Measures and countermeasures for everyone
Keeper password manager: once again no security was last modified: 10 March, 2018, 9: 25 am by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: Newstag: aaron, amazon, android, apple, I'm sure

You May Also Like

Adware: How can it steal your personal data?
7 Android applications that act as a remote control for your computer
Google: how do we improve Android security?

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « Ubuntu 18.04 LTS Bionic Beaver Beta 1 has just been released
Next Post: Samsung Galaxy S9 Microsoft Edition in Microsoft Store »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.