8 ms·
Define "one go". Keepassxc auto-type allows you to add a delay between writing the username and writing the password. Works just fine for me in these "two ste
by AsusFan 7y ago
Define "one go".
Keepassxc auto-type allows you to add a delay between writing the username and writing the password.
Works just fine for me in these "two step" login scenarios.
Edit to clarify:
This is what I am talking about:
https://github.com/keepassxreboot/keepassxc/wiki/Autotype-Custom-Sequence#delay-n https://github.com/keepassxreboot/keepassxc/wiki/Autotype-Cu...
- goshx 7y agoIt sounds like a hack that most regular users would never know about or do.
- jimmaswell 7y agoI do this stuff manually in autohotkey for flows like tabbing to the MFA app window, clicking the right place to copy the code, tabbing back into the app I'm trying to log into, clicking the right space to get to the input fields, and entering the username/password/mfa. As well as for logging onto a website where I need to enter the username, hit tab, hit enter to select "log in with password", then enter the password and hit enter again. Saves a lot of time/dealing with typos in the unnecessarily complex passwords these systems require and it's cool to watch it do it.
- fwip 7y agoYou store all your passwords in plain text on your machine?
- jimmaswell 7y agoJust some, which is no worse than saving them in a browser.
- ahje 7y agoChrome and Edge uses the OS' own storage mechanisms for passwords (Safari too?), and that's considerably more safe than a plain text file. Firefox uses a weaker scheme, but the passwords are still encrypted and it's definitely less accessible for an intruder compared to a plain text file.
- jimmaswell 7y agoYou can just open the browser and look at the saved passwords in the settings. A little bit harder I guess.
- ahje 7y agoIf you set a master password for saved logins in Firefox then passwords won't be available with a simple click, and they will be encrypted on disk. In browsers that use the OS' password storage then they will normally be stored in encrypted form, although the browser integration is seamless so you won't notice the difference. In both cases, there is a significant security advantage in cases where the data on disk is leaked (say, if someone steals your computer and you don't have full-disk encryption.
- crummy 7y agoChrome now requires your machine login to do this (on Windows at least where I tested it.)
- davchana 7y agoAt least in Chrome if you want to view the passwords; it asks you for Windows account password.
- jsf01 7y agoThat’s added friction. Every standard username/password form takes me only one click to enter into my password manager. Your timing based approach also adds uncertainty. What if the second form is different now? What if the first request doesn’t finish in the specified delay time? When dealing with credentials, I don’t want to think about any of those things.
- greggyb 7y agoWhat if the one-page login has a change that requires two tabs to get to the password field, instead of one? This has happened to me on multiple sites. What if the one-page login is changed to require additional information? At least one airline loyalty program I belong to now requires User Id, Last Name, and Password to be filled in. Credential-collecting workflows have myriad ways to break the "standard" of USERNAME<tab>PASSWORD<return> that are present regardless of how many pages the workflow spans.
- Mirioron 7y agoThen I complain to them that their site is garbage.
- greggyb 7y agoI just spend <1 minute to update the login procedure for that site in my password manager and don't think about it again, continuing to log into all sites the same way, with a hotkey to perform auto-type for that site. Which of us is happier?
- stcredzero 7y agoHigh-pedantry groups like programmers are odd, in that they display this emotional state where they have nothing but complaints about how crappy the world is, yet they seem inwardly smug and happy about how they're clever enough to know better. Is that misery? Is that happiness? I'm in one of those groups, and still, I don't really know for sure.
- basq 7y agoWas an avid user of kpxc for a year. The auto type feature did not feel secure compared to other pwm's. It requires the username input field to be focused, and if the wrong field is focused (click didn't take?) or otherwise changes mid-type it spills your credentials into the input and sends them. Other managers seem to at least try to validate the entry types.
- CaptainMarvel 7y agoUse the browser plugin?