₪ Welcome to Inviteshop.us trackers shop ₪

InviteShop - #To Buy , Trade , Sell Or Find Free Trackers Invites! Here you can buy private torrent tracker invites such as HDBits.org, Morethan.tv, PassThePopcorn, BroadcasTheNet , Art Of Misdirection ( AOM ) , BeyonHD , FSC , NZBs.in , Omgwtfnzbs , Karagarga , DB9 , GazelleGames , Thevault.click , Theoccult.click , Animebytes , MagicTorrents , SceneHD , TTG , Bibliotik , Redacted , Exigomusic , + more.

If you want to buy a tracker, you can see my contact information here:
Email: inviteshop52@gmail.com
My Discord: inviteshop. or inviteshop
Skype: https://join.skype.com/invite/BsB4uGwVTfPD
Skype Name: InviteShopStore
Telegram trackers shop: https://t.me/InviteShQp
Telegram Username: @InviteShQp

Check out my trackers store by clicking on the BIG SALE image.


The best payment mod we accept!

Or Register
https://join.skype.com/ExtraeOlbK0g Skype Name: InviteShopStore
Email: inviteshop52@gmail.com Telegram Username: @InviteShQp

Proton Pass Retains Passwords in Cleartext Form in Memory

Inviteshop

₪ Owner -> Big Seller ₪
Staff member
Admin / Sysop
Posts
10,811
Posts Power
10,811.0%
Liked
890
Joined
Jan 2, 1996
Website
inviteshop.us
The Proton Pass password manager follows the bad practice of keeping unencrypted usernames and passwords in the computer’s memory.

To make matters worse, this sensitive data is not wiped from the memory when the vault is locked post-login, making it susceptible to exfiltration by info-stealer malware or attackers with physical access to the target machine.

The security issue was first identified by German penetration tester Mike Kuketz. He highlighted the concern on Reddit, prompting a response from a Proton AG employee, the developers behind the software, who assured a fix in the upcoming update.

Despite multiple updates to Proton Pass since then, the security vulnerability persisted. Kuketz later received feedback from another company representative, explaining that this was standard behavior across many open-source password managers, including the competing product from Bitwarden.

The researcher gives the following steps to reproduce the issues on the latest version (1.6.1) of the Proton Pass add-on for Chrome and Firefox browsers:

  1. Install the add-on in the browser and log in.
  2. Open Windows Task Manager and expand browser processes.
  3. Right-click each process, creating an image file.
  4. Open the image with a hex editor.
  5. Use Ctrl + F to find usernames or passwords.

Caught, fixed, and crept back in

Kuketz notes that Cure53 caught that security problem in a recent audit on Proton Pass, marking it as “reported and fixed” by the time the audit report was published in July 2023.

This confused the analyst, who assumed that Cure53 was given a newer version to test that wasn’t made publicly available. However, this hypothesis made less sense after months had passed with no fix in sight.

The answer came from Proton AG themselves, who responded to Restore Privacy’s request for a comment on the situation, explaining that the issue was fixed in the summer and then reintroduced in a subsequent release. The spokesperson for the firm also told us that a fixed update should be on its way to reach users of Proton Pass before the end of the day.

“We’ve confirmed on our side that this bug (previously found in the Cure53 audit) has been reintroduced recently with some new Proton Pass features. This is an end-game scenario type of attack where the attacker would need access to browser or memory to have access to passwords.

This is a highly unlikely scenario, but as Proton is absolutely committed to the security and privacy of our users, we’ll be fixing this as soon as possible. We will be pushing an update to Proton Pass in the coming hours that corrects this bug and further obfuscates and hardens any data stored in memory.”

Proton AG

While the attack requires specific conditions and doesn’t pose an immediate threat to users following good security practices, the potential for malware to exploit this flaw and steal entire password vaults isn’t as improbable as the vendor suggests. Therefore, Proton Pass users should remain vigilant and regularly check for updates to the password manager.
 
Top Bottom