An Analysis of Password Managers’ Password Checkup Tools
Adryana Hutchinson, Collins W. Munyendo, Adam J. Aviv, Peter B. Mayer · 2024
Password managers (PMs) have been widely recommended to users to generate and store random, secure, and unique passwords across websites. Using a PM is often not enough however, especially if users store passwords that are guessable, or have been breached. To assist users in updating insecure passwords, PMs come with “checkup" features that report the strength of users’ passwords. However, there has yet to be a systematic study of the features offered as part of these checkups, and the consistency of the checkup advice across different PMs. In this paper, we conduct a preliminary analysis of 14 PMs’ password checkup features, recording how many passwords are reported weak and compromised. We find that many PMs fail to report breached credentials. Weak passwords were also under-reported by PMs. This analysis forms the basis for a larger study on the consistencies of PM checkup tools and how users perceive and use them.