4 ms·
Someone debunk this so I can sleep at night.
by siedes 8y ago
Someone debunk this so I can sleep at night.
- Wowfunhappy 8y agoI think this is the same thing my javascript bookmarklet does automatically to reveal saved passwords (when I can’t remember them). The bookmarklet works everywhere I’ve ever tried it, and was super useful before I switched to a real password manager. So, consider this an anti-debunk.
- recursive 8y agoOh boy, get ready to be awake.
- int_19h 8y agoWhat is there to debunk? Someone who has access to your browser, has access to all your browsing data - of course! This includes saved passwords.
- jtms 8y agograb some ambien - you’re going to need it!
- tedmiston 8y agoAnother trick you can do is change the field type from password to text in the web inspector, which will also reveal the password in plaintext.
- efreak 8y agoEven simpler, a bookmarklet (untested) for those who can't (or shouldn't be allowed to) use devtools: ``` document.getElementsByTagName('input').forEach(function(e){if(e.type.toLowerCase()=='password'){e.type=text}}) ``` This should change all password fields on the page into plain text fields, with values intact. Prefix with `javascript:` and paste into a bookmark
- jjoonathan 8y agoI just stole all 4 of my banking passwords this way :/
- pjc50 8y agoAll extensions with access to the DOM can steal passwords. That's the argument used for restricting sideloading, etc. (Can they steal Basic-auth passwords, though?)