3 ms·
Thanks for this detailed description! Is there a way to close the entry point for evil JS? For example, can you tell the extension to stop touching the DOM and
by styfle 9y ago
Thanks for this detailed description!
Is there a way to close the entry point for evil JS? For example, can you tell the extension to stop touching the DOM and injecting any code. That way the username/password can be only interacted with via the browser's chrome button?
- UnoriginalGuy 9y agoNo practical one. The extension needs full access to the data in order to push it into a page's forms or to update them via the admin UI ("Lastpass Vault"). I believe the Chrome Web Store does check an extension's signing certificate before updates are published, so security wise that's a good thing, but realistically it remains the weakest part of Lastpass's overall design.