3 ms·
Password should be saved per-site. Like, I think they actually are.
by abugheratwork 8y ago
Password should be saved per-site. Like, I think they actually are.
- btrettel 8y agoYou're right, that mitigates most of the risk. Firefox seems to save passwords per domain name. This may not be specific enough in certain cases. E.g., if I have a password on domain.com, but domain.com offers web hosting at domain.com/username, then my understanding is it would be relatively easy to obtain my credentials for domain.com with the right phishing site at domain.com/username. Correct me if I'm wrong.
- robjan 8y agoIn that case, cookies would be completely insecure as well
- baroffoos 8y agoThe entire web security model breaks down in this case. No web hosting except the most hacked together system does this. They all provide sub domains or sanitize the content so it can't run any code. Like the sibling comment pointed out, you could just use JS to grab your login cookie from the other site.
- btrettel 8y agoGood points. Unfortunately there are a lot of "hacked together" services out there. I can think of one site I had to use recently for event registration which suffered from the flaw I mentioned. (Note that I have no choice over which service to use here, as I don't run the event.) The site puts each event under different directories, not subdomains as it should. Firefox saved my login details for one past event and wanted to use them for another event. I don't know the extent by which the event pages can be customized, but if you could put the right JS on one event page then it seems there are multiple approaches to getting credentials and potentially obtaining sensitive information. Fortunately in this case an attacker wouldn't obtain much of value best I can tell.