The problem with KPM, Ledger’s researcher explains, is also what differentiated it from other password managers out there: in an attempt to create passwords that are as far away as possible from those generated by humans, the application became predictable.

The passwords appeared to have been created so as to prevent cracking from commonly used password crackers. The employed algorithm, however, allowed an attacker who knew that the passwords were generated using KPM to create the most probable passwords generated by the utility, Bédrune says.

  • @joojmachineOP
    link
    13 years ago

    Oh it wasn’t mentioned in the article, all it had was “Kaspersky started releasing patches in 2019, but it only published an advisory in April 2021.”

    • @ajz
      link
      2
      edit-2
      2 years ago

      deleted by creator