Software:Keeper (password manager)

From HandWiki
Short description: Password management software
Keeper Security, Inc.
Keeper-tag.png
Developer(s)Keeper Security Inc.
Initial releaseJanuary 2009
Operating systemWindows, Windows Phone, macOS, Linux, Android, iOS, Web, WatchOS, Wear OS[1]
TypePassword manager, secrets manager, agentless remote desktop gateway, privileged access manager
LicenseSoftware as a Service (SaaS)
Websitekeepersecurity.com

Keeper Security, Inc. (Keeper) is a provider of zero-knowledge security and encryption software covering password management, secrets management, connection management, privileged access management, dark web monitoring, digital file storage, and encrypted messaging, among other offerings.[2]

Keeper Password Manager

Keeper password manager uses a freemium pricing model for individual consumers[3] and a subscription-based model for households and businesses.[4] The free individual version of Keeper provides storage for passwords, identity data, and financial information, with included a password generator and two-factor authentication (2FA) on a single mobile device. The subscription-based model for individual consumers offers additional features such as unlimited password, identity data, and financial data storage on an unlimited number of devices, cross-device syncing, and record-sharing capabilities.[5]

Keeper is available as a mobile app for Android and iOS, as well as a desktop application for Windows, Linux, and MacOS.[6] It offers a desktop browser extension for Safari, Chrome, Firefox, Microsoft Edge, Opera, and Brave.[7]

Users secure their Keeper vaults with a “master password.” Users can further protect their vaults via a variety of multi-factor authentication methods, including Google Authenticator, Duo Security, FIDO U2F, and biometrics.[8]

Customer vaults are secured using an AES-256 key, which is derived from the user’s master password using PBKDF2 with 1,000,000 iterations by default. Only encrypted ciphertext is stored on Keeper’s servers, and the company has no way of decrypting the data its customers store in their digital vaults, nor can it retrieve their master passwords.[9]

Keeper users can directly share passwords, files, and other information “vault to vault” with other Keeper users and through One-Time Share for non-Keeper users; all shared content is secured with PKI encryption.[10][11]

Keeper Security Government Cloud

Keeper Security is listed as Authorized on the FedRAMP Marketplace at the Moderate Impact Level, with an authorization date of 8/23/2022[12] and Authorized on the StateRAMP Marketplace at the Moderate Impact Level, with an authorization date of 11/30/2022.[13] Keeper Security Government Cloud (KSGC) is for U.S. federal, state, and municipal government agencies. It supports compliance with the United States International Traffic in Arms Regulations (ITAR).

History

In 2009, Craig Lurey developed the original Keeper app with Darren Guccione.[14] In 2011, Lurey and Guccione officially co-founded Keeper Security, Inc. As of March 2022, Keeper had offices located in Chicago, IL (US Headquarters); El Dorado Hills, CA (Software Development); Cork, Ireland (EMEA Business Sales); and Cebu, Philippines (International Customer Support).[15]

In October 2019, Keeper launched KeeperMSP, a password management platform designed specifically for managed service providers (MSPs), managed security service providers (MSSPs), and their customers.[16] In August 2020, Keeper received a $60 million minority investment from venture capital firm Insight Partners.[17] In March 2021, Keeper launched Keeper SSO Connect.[18] In May 2021, Keeper was listed on the U.S. federal government’s FedRAMP Marketplace as a "CSP in Process."[19] In January 2022, Keeper announced the launch of Keeper Secrets Manager.[20]

In February 2022, Keeper acquired remote access gateway company Glyptodon Inc., creator of Glyptodon Enterprise and Apache Guacamole, and commenced integrating Glyptodon Enterprise into its product suite.[21] In May 2022, Keeper launched Keeper Connection Manager, a rebranding and revamping of Glyptodon Enterprise into a commercial-grade remote desktop gateway with expanded capabilities, advanced integrations, and ongoing feature development.[22]

In August 2022, Keeper Security became Authorized on the FedRAMP Marketplace at the Moderate Impact Level.[12] In November 2022, Keeper Security became Authorized on the StateRAMP Marketplace at the Moderate Impact Level.[13]

Reception

PC World named Keeper an Editor's Choice in 2019[23] and Most Security-Minded Password Manager in 2022.[24] PCMag named Keeper “Best Password Manager for Businesses" (2022), as well as Best Password Manager and Editors' Choice for the previous three consecutive years.[25] Tom’s Guide named Keeper one of the best password managers of 2022.[26] U.S. News & World Report’s 360 Reviews team named Keeper Best Overall Password Manager of 2021.[3]

Incidents

In December 2017, Keeper was bundled with Windows 10 by Microsoft. Google security researcher Tavis Ormandy disclosed that the software recommended installing a browser addon which contained a vulnerability allowing any malicious website to steal any password.[27] A nearly identical vulnerability was already previously discovered and disclosed to Keeper in 2016.[28][29] Within 24 hours, the company issued a patch.[30][31] Days later, the company that makes Keeper sued Ars Technica, claiming their article was defamatory and misleading.[32] The lawsuit was dismissed on March 30, 2018, and Ars Technica added further clarifications to the article.[33]

Following the lawsuit, Keeper launched a public vulnerability disclosure program in partnership with Bugcrowd.[34]

See also

References

  1. Keeper. "Download Password Manager for Mac, PC, Linux & More - Keeper". https://keepersecurity.com/en_US/download.html. Retrieved 8 February 2018. 
  2. "Exclusive: Keeper Security launches industry-first solution" (in en). https://itbrief.com.au/story/exclusive-keeper-security-launches-industry-first-solution. 
  3. 3.0 3.1 Pegoraro, Rob; Forster, Timothy J. (August 12, 2021). "Keeper Password Manager Review and Prices". U.S. News & World Report. https://www.usnews.com/360-reviews/privacy/password-managers/keeper. 
  4. "Keeper Password Manager Pricing". https://www.g2.com/products/keeper-password-manager/pricing. 
  5. Long, Emily (January 27, 2022). "Keeper password manager review". Tom's Guide. https://www.tomsguide.com/reviews/keeper. 
  6. "Keeper Web Vault & Desktop App User Guide". https://docs.keeper.io/user-guides/web-vault. 
  7. "KeeperFill Browser Extensions - User Guides". https://docs.keeper.io/user-guides/browser-extensions. 
  8. Nieves, Edgar J. (March 4, 2022). "5 Best Password Managers of 2022". Money Magazine. https://money.com/best-password-managers/#keeper. 
  9. Mazūra, Justinas (March 16, 2022). "Keeper password manager app review 2022". Cybernews. https://cybernews.com/best-password-managers/keeper-password-manager-review/. 
  10. "Keeper Security: Comprehensive, Zero-Trust, Enterprise-Grade Password Security & Management". https://security.cioreview.com/vendor/2021/keeper_security. 
  11. "One of the best password managers around just picked up an excellent new feature" (in en). 2022-06-23. https://www.techradar.com/news/one-of-the-best-password-managers-around-just-picked-up-an-excellent-new-feature. 
  12. 12.0 12.1 "The Federal Risk And Management Program Dashboard". https://marketplace.fedramp.gov/#!/product/keeper-security-government-cloud-ksgc. 
  13. 13.0 13.1 "Authorized Product List" (in en-US). https://stateramp.org/product-list/. 
  14. "No matter how much we innovate, passwords are here to stay". April 16, 2021. https://www.siliconrepublic.com/enterprise/passwords-cto-keeper-security. 
  15. "Company Overview & Solutions Guide". https://www.keeper.io/hubfs/PDF/Keeper_FactSheet_2021.pdf. 
  16. "Keeper Security Unveils Exclusive Solution for Managed Service Providers". PR Newswire. October 30, 2019. https://www.prnewswire.com/news-releases/keeper-security-unveils-exclusive-solution-for-managed-service-providers-300947930.html. 
  17. Earley, Kelly (August 18, 2020). "Keeper Security's password protection tech raises $60m". Silicon Republic. https://www.siliconrepublic.com/start-ups/keeper-password-protection-manager-funding. 
  18. "Keeper Security Reimagines and Secures the Passwordless Future with Keeper SSO Connect™ Cloud". PR Newswire. March 9, 2021. https://www.prnewswire.com/news-releases/keeper-security-reimagines-and-secures-the-passwordless-future-with-keeper-sso-connect-cloud-301243257.html. 
  19. "Keeper Password Manager on Twitter". May 24, 2021. https://twitter.com/keepersecurity/status/1396879208643764227. 
  20. Spadafora, Anthony (January 12, 2022). "Keeper Security wants to help keep all your online secrets". TechRadar Pro. https://www.techradar.com/news/keeper-security-wants-to-help-keep-all-your-online-secrets. 
  21. Riley, Duncan (February 3, 2022). "Keeper Security acquires Apache Guacamole inventor Glyptodon". Silicon Angle. https://siliconangle.com/2022/02/03/keeper-security-acquires-apache-guacamole-inventor-glyptodon/. 
  22. Murphy, Ian (2022-05-05). "Keeper Security launches Keeper Connection Manager" (in en-GB). https://www.enterprisetimes.co.uk/2022/05/05/keeper-security-launches-keeper-connection-manager/. 
  23. Ansaldo, Michael (October 30, 2019). "Keeper review: Security is the greatest strength of this password manager". https://www.pcworld.com/article/398233/keeper-password-manager-review.html. 
  24. Ansaldo, Michael (July 13, 2022). "Best password managers: Reviews of the top products". https://www.pcworld.com/article/407092/best-password-managers-reviews-and-buying-advice.html. 
  25. Key, Kim (February 1, 2022). "The Best Password Managers for Businesses in 2022". PCMag. https://www.pcmag.com/picks/the-best-password-managers-for-businesses. 
  26. Wagenseil, Paul (March 1, 2022). "The best password managers in 2022". Tom's Guide. https://www.tomsguide.com/us/best-password-managers,review-3785.html. 
  27. "Windows 10 included password manager with huge security hole" (in en-US). Engadget. https://www.engadget.com/2017/12/16/windows-10-bundled-password-manager-had-security-flaw/. 
  28. "For 8 days Windows bundled a password manager with a critical plugin flaw" (in en-us). Ars Technica. https://arstechnica.com/information-technology/2017/12/microsoft-is-forcing-users-to-install-a-critically-flawed-password-manager/. 
  29. Chirgwin, Richard (18 December 2017). "Windows 10 bundles a briefly vulnerable password manager" (in en). The Register. https://www.theregister.co.uk/2017/12/18/windows_10_bundles_vuln/. 
  30. Kovacs, Eduard (18 December 2017). "Google Researcher Finds Critical Flaw in Keeper Password Manager". Security Week. http://www.securityweek.com/google-researcher-finds-critical-flaw-keeper-password-manager. 
  31. Security, Keeper (2017-12-15). "Update for Keeper Browser Extension 11.4.4 - Keeper Blog" (in en-US). Keeper Blog. https://blog.keepersecurity.com/2017/12/15/update-for-keeper-browser-extension-v11-4/. 
  32. Whittaker, Zack. "Security firm Keeper sues news reporter over vulnerability story" (in en). ZDNet. http://www.zdnet.com/article/security-firm-keeper-sues-news-reporter-over-vulnerability-story/. 
  33. "Press releases | Ars Technica". https://arstechnica.com/press-releases/. 
  34. "Keeper Security Public Bounty Program". https://bugcrowd.com/keepersecurity. 

External links