4 ms·
I don't think that's naive. A browser plugin is another component that you have to trust. But maybe you haven't considered all threats. I use the Chrome passwo
by dancek 8y ago
I don't think that's naive. A browser plugin is another component that you have to trust. But maybe you haven't considered all threats.
I use the Chrome password store. Copying passwords over clipboard seems quite unsafe to me. And I have to trust my browser with my passwords anyway, even if I use no password manager at all.
Of course, if you (really) control all software running on your machine, the clipboard is no issue. But I'm lazy and don't have the time to read all source code and compile everything myself.
The downside is that I've considered changing to Firefox as my primary browser a couple of times, but the passwords make switching harder.
- paulryanrogers 8y agoSome password managers like Keepass put the password into the clipboard only temporarily. And their Auto-type actually splits input among simulated key presses and clipboard data.
- dancek 8y agoGood to know! I'll have to consider switching to Keepass, then.
- sgc 8y agoThis is what I use. Although it is not perfect, it does require an exploit targeting it specifically. Until it becomes a de facto standard, I would expect this type of exploit to be found largely in targeted attack on an individual or specific organization rather than in a broadly sweeping virus.