REVIEWS / PASSWORD MANAGERS / OWNER INSIGHTS

🦉 WE READ 53 OWNER COMMENTS

Kaspersky Password Manager: what owners actually say

Technical community raises serious concerns about Kaspersky Password Manager's flawed password generation algorithm and company's intelligence ties

HACKERNEWS · 30 REDDIT · 14 STACKEXCHANGE · 5 YOUTUBE · 4

What owners complain about

  • Predictable password generation COMMON

    Multiple highly-upvoted comments explain that Kaspersky Password Manager used a time-based seed for its PRNG instead of a cryptographically secure random generator, making generated passwords predictable. Attackers could use 'member since' dates to dramatically narrow brute-force attempts against leaked hashed passwords.

  • Low entropy despite appearance of randomness COMMON

    Commenters note that while passwords looked random, the mathematical entropy was far lower than expected because the generation was not properly unpredictable. One commenter states the passwords were 'very easy to predict using computers' based on entropy analysis.

  • Founder and company ties to Russian intelligence SOME

    Multiple commenters discuss Eugene Kaspersky's education at the KGB Higher School's Technical Faculty (now the Institute of Cryptography run by FSB), describing him as still a 'state security reserve officer.' This raises trust concerns specifically relevant to a password management product.

  • General distrust of AV-bundled software SOME

    Commenters describe AV software as 'virtually impossible to vet' and 'the literal stone to keep tigers away,' stating that bugs found in AV products are 'so obviously stupid.' This extends to distrust of Kaspersky's password management offering.

  • Users actively recommend competitors instead SOME

    Multiple commenters recommend Bitwarden and 1Password as alternatives, with several explicitly saying they switched away from competitors to these products. No commenter in the sample recommends Kaspersky Password Manager.

What owners love

  • Affection for founder's expertise

    One YouTube commenter expresses love for founder Eugene Kaspersky, though notably adds uncertainty about the password management product specifically.

  • Acknowledgment of strong antivirus detection historically

    While not directly praising the password manager, one commenter asks whether Kaspersky can detect Pegasus spyware, implying a reputation for strong malware detection capabilities that could extend to the broader security suite.

Surprising patterns

  • The technical discussion reveals that even a weak PRNG would have been acceptable if properly seeded — the specific failure was using the current time as a seed, which is a surprisingly elementary cryptographic mistake for a security company.
  • Several commenters note that the attack only becomes practical when combined with a database leak, meaning the vulnerability's real-world impact depends on a secondary breach — but commenters stress that such leaks are 'rampant' and inevitable.
  • Even commenters who defend aspects of Kaspersky's approach concede the core criticism, with one stating that while the PRNG discussion is 'relatively irrelevant' compared to proper seeding, the time-based seed was undeniably a serious flaw.

WHO SHOULD SKIP IT

Anyone who needs cryptographically defensible password generation or who is uncomfortable with the company's documented ties to Russian intelligence services, as both concerns are raised repeatedly and never refuted in the sampled comments.

2.1/10 GYIBB verdict
Full review →

Synthesised from 53 real owner comments across 4 platforms. Every point is grounded in the comments — no marketing, no AI guessing. How we do it →