mSecure assessment by The Federal Office for Information Security (BSI)
H
Hans-Josef
ha iniziato un argomento
circa 3 ore fa
The Federal Office for Information Security (BSI) is the federal cybersecurity authority and designer of secure digitization in Germany and has assessed mSecure in 2025, amongst other password managers.
The findings make me wonder whether messures have been taken to improve the situation?
kind regards, HJ
Assessment and Recommendations for Consumers
Overall, the concept does not meet the usual expectations for password managers. Additional characteristics reinforce these security concerns. Users should carefully consider whether they can extend the necessary trust to the manufacturer without an objective basis before using the product.
Information about the employed concept, cryptographic mechanisms, conducted security audits, the software development process, and the third-party components (software libraries) used is not publicly and transparently available, which makes conducting security investigations more difficult.
Communication with the Manufacturer
mSeven Software did not respond to technical inquiries. In response to the audit report, the manufacturer stated that the secrets transmitted to them are not stored. Furthermore, the manufacturer confirmed the transmission of part of the key in the password-sharing feature.
Key Audit Findings
Significant deviations from common recommendations were identified.
Technical information is sent to the manufacturer, allowing them to access the contents of the password manager.
Furthermore, the biometric access control allows the setup of a new master password without knowing the old one, which poses a risk, especially for stolen devices. The recovery mechanism is based on this function.
The implementation of the password-sharing feature ignores common best practices and relies on a questionable concept that involves sending part of the key.
mSecure uses an RSA key length of 2048 bits, which does not meet current recommendations (see BSI TR-02102-1).
Hans-Josef
The Federal Office for Information Security (BSI) is the federal cybersecurity authority and designer of secure digitization in Germany and has assessed mSecure in 2025, amongst other password managers.
The findings make me wonder whether messures have been taken to improve the situation?
kind regards, HJ
Assessment and Recommendations for Consumers
Overall, the concept does not meet the usual expectations for password managers. Additional characteristics reinforce these security concerns. Users should carefully consider whether they can extend the necessary trust to the manufacturer without an objective basis before using the product.
Information about the employed concept, cryptographic mechanisms, conducted security audits, the software development process, and the third-party components (software libraries) used is not publicly and transparently available, which makes conducting security investigations more difficult.
Communication with the Manufacturer
mSeven Software did not respond to technical inquiries. In response to the audit report, the manufacturer stated that the secrets transmitted to them are not stored. Furthermore, the manufacturer confirmed the transmission of part of the key in the password-sharing feature.
Key Audit Findings
Significant deviations from common recommendations were identified.
Technical information is sent to the manufacturer, allowing them to access the contents of the password manager.
Furthermore, the biometric access control allows the setup of a new master password without knowing the old one, which poses a risk, especially for stolen devices. The recovery mechanism is based on this function.
The implementation of the password-sharing feature ignores common best practices and relies on a questionable concept that involves sending part of the key.
mSecure uses an RSA key length of 2048 bits, which does not meet current recommendations (see BSI TR-02102-1).