12 ms·
Spook: Side channel attack which could read the memory from password managers
- deleted 5y ago[deleted]
- MrWiffles 5y agoAs if we needed yet another reason to avoid Chrome and friends…
- RcouF1uZ4gsC 5y agoI believe Chrome goes much further than Firefox in trying to isolate websites into separate processes. If anything, I would guess that Firefox would be much more vulnerable to these kinds of attacks.
- jack_pp 5y agoIt might be the case that Firefox is less vulnerable in general because it is not as targeted even though technically it might have more undiscovered exploits.
- bee_rider 5y agoThat's just security by obscurity.
- eropple 5y ago"Security by obscurity" is a phrase frequently repeated but generally misunderstood. There is value in not having the lock everybody's trying to pick with very advanced attacks so long as it is generally proof against being kicked down by simpler ones. So, sure, it may be security-by-obscurity--but it can also be significant and helpful depending on one's threat model. "Security by obscurity" is not a disqualifying objection under most models.
- unethical_ban 5y agoNot only is that not always a bad thing, but your statement implies that (a) it is the fault of FF that it is "obscure" for the purposes of security, and (b) that they aren't secure in the traditional sense, and only rely on the obscurity portion.
- bee_rider 5y agoI think the comment I responded implies that, more than mine. I'm writing this in Firefox, and I suspect that it is probably actually more secure in some nebulous sense just because they don't have any need to comply with shady characters like Google. But the particular advantage highlighted doesn't seem so great.
- dotancohen 5y agoSecurity by obscurity keeps my SSH logs clean. Not many bots come knocking on port 22122 (not the real port).
- latchkey 5y agoFrom the FAQ on the page: We have tested Spook.js on Chromium, which is the basis of the Chrome browser. Thus, in addition to Chrome itself, we expect most Chromium-based browsers to be vulnerable to some variant of Spook.js. This includes recent versions of Microsoft's Edge browser, as well as Brave which is a privacy-centered browser. Other browsers like Firefox and Safari use very different JavaScript execution engines, which currently stops Spook.js from working. We leave the task of investigating speculative exection attacks on these browsers to future work. Finally, Firefox has recently introduced Strict Site Isolation in its stable release. While Spook.js does not work on Firefox as is, we note that similarly to Chrome, Firefox also consolidates pages based on their eTLD+1 domain.
- Aachen 5y agoDamn, I thought this must be a Dutch find since Spook.js lends itself beautifully as a Dutch word, but alas.
- the-dude 5y agoThe English meaning is much more appropriate.
- sigg3 5y agoAnd other than Chrome? > we expect most Chromium-based browsers to be vulnerable [... including] recent versions of Microsoft's Edge browser, as well as Brave
- alanbernstein 5y agoSo does this justify my use of a password manager with no browser integration, and all the microseconds of lost productivity due to copying and pasting passwords all the time?
- neandrake 5y agoFor anyone looking for a personal password manager that is not a browser extension but also provides the functionality to auto-type passwords into the focused field I highly recommend codebook https://www.zetetic.net/codebook/ https://www.zetetic.net/codebook/ It's a one-time fee (per device~ish) and you can connect & sync it to Google Drive, Dropbox, Local folder, or to another device over WiFi. I've been using it for a few years and it has great iPhone and macOS integration. The Windows integration is also good but not quite as smooth as being integrated with FaceID or thumb print ID.
- jayknight 5y agoKeePass can emulate a keyboard and type your credentials for you. But it's initiated from the KeePass app instead of requesting it from the browser. It is slower than just having it autofilled but faster than copying it to your clipboard (where other programs might have access to it).
- loudtieblahblah 5y agoIMHO - keepass was way faster via keybinding than dragging your mouse to a browser plugin drop down.
- jackson1442 5y agoNot sure what other managers you’ve used but with 1Password I just press cmd+shift+x to show a popover, arrow keys to choose the account, then press enter. No mouse needed.
- dotancohen 5y agoMy muscle memory copies the URL from the browser into the Keepass search bar. Thus, I get more-or-less protection from rogue URLs as well - and I'm forced to look at the URL with my eyeballs.
- _wldu 5y agoWeb browsers today have “everything but the kitchen sink” capabilities built-in and are becoming more and more complex each year. They are turning into whole platforms that have browser plug-ins and extensions for every possible need known to humankind. While many of these add-ons are handy and useful, we should not trust them with password management. Browsers are just too complex and have far too much going on. Full article: https://www.go350.com/posts/the-design-flaws-of-password-managers/ https://www.go350.com/posts/the-design-flaws-of-password-man...
- i80and 5y ago> Web browsers today have “everything but the kitchen sink” capabilities built-in and are becoming more and more complex each year. Thinking back to the Netscape Suite and Mozilla, this is a fun cycle
- dotancohen 5y agoActually, Chrome today is a great Javascript IDE and application runtime. There's Chrome extensions for everything from calculators to full CRMs. I'm just waiting for it to get a decent web browser.
- DaiPlusPlus 5y agoYes, but that was application capabilities, not platform capabilities: back with Netscape Communicator there was no insanely-capable JavaScript features like WebUSB, WebRTC, TypedArray buffers, and so on. This is what we're referring to when we say web-browsers are like operating-systems: because of the capabilities afforded to JavaScript programs, not because the browser is bundled with a built-in mail client (like Emacs...) or because of non-web-platform feature bloat like Seamonkey. --------- I imagine eventually Thunderbird will come back as a 100% JS application (no more XUL?) in a normal Firefox (or Chrome, or Edge, or Safari, but not iOS Safari, because reasons) window - making use of a hypothetical-but-easily-imaginable WebIMAP, WebPOP, or just after raw TCP sockets become a thing in JS: https://wicg.github.io/raw-sockets/docs/explainer.html https://wicg.github.io/raw-sockets/docs/explainer.html
- theogravity 5y agoThis is around the third time that I've read about a vulnerability with LastPass. Is 1Password susceptible to the same attack?
- joshAg 5y agoit's not anything specific to lastpass, because it's an issue with how chrome was(n't) isolating extensions. That's just the pw manager extension they picked for proof of exploitability. Any password manager that has a chrome extension that prefills passwords has the same issue.
- bee_rider 5y agoThis title seems a bit over-broad. The attack is based on using the built-in chrome credential manager. Further, it seems to depend either on the user installing an evil chrome plugin (in which case, you are already doomed, right?), or confusing a website like Tumblr into mixing up the user content and the login page, and getting the autofill info there. The second attack seems limited to just the site that is being messed with. The fact that sites like Tumblr which apparently (?) host random unvetted javascript for bloggers aren't protected by site isolation is not that surprising, right? Anyway, autofill and built-in password managers have always seemed suspicious to me. People should stick to stuff like keepass I guess.
- sroussey 5y agoOlder UGC site makers have this issue when posting such sites as subdomains. Newer ones put user stuff on subdomains of another top level domain. Mitigations include having login on a separate domain and use oauth to yourself. :) There is actually a list of such sites that Firefox has (had? haven’t been in the space in a while) that they could use for various reasons. Like treating the tumblr.com domain as an international domain (co.uk) which Google search would do as well.
- deleted 5y ago[deleted]
- Groxx 5y agoPage as a whole seems over-broad. E.g. the first FAQ entry: > Have I been affected by this attack? > If you have an Intel processor or an Apple device with the M1 chip, then yes with very high probability. We also expect our attack to be effective for AMD machines, however this has been only partially demonstrated. while also further down > Has Spook.js been abused in the wild? > We do not have any evidence so far that Spook.js has been or not been abused in the wild. and I haven't been able to find any references whatsoever to evidence that this technique has been actively used.
- bananaportfolio 5y agoIt looks like they were able to exploit the Last Level Cache of Intel and Apple processors, but failed to do so against an AMD processor using the Zen architecture. Instead of plainly saying as much, the authors simulate a theoretical leakage rate for AMD processors by way of making V8 expose clflush in absence of a practical LLC eviction mechanism.
- gzer0 5y agoTangentially related, but is my understanding of the V8 expose clflush instruction correct? AMD introduced the Clflush instruction which was supposed to decrease the number of TLB misses and improve performance. This instruction was ultimately responsible for making V8’s behavior erratic and unpredictable with regards to memory operations. Modern processors with x86-64 architecture support 2-way page tables and most modern operating systems support several layers of virtual memory. However, many of these techniques made the V8's behavior unreliable and unpredictable which led to a performance hit for AMD processors with AMD chips especially those who implemented TLB remapping instructions.
- manbart 5y agoNo sr g. It on we fbeg feed th C hey Vic
- c7DJTLrn 5y agoAlright, it has a site and a logo, it checks out.
- bjt 5y agoI guess security researchers feel compelled to do this career-wise. It's not enough to just report a CVE. You need a marketing site for your exploit to get it picked up in the tech press and establish your reputation. Starting to feel like academics chasing citations.
- mhh__ 5y agoGiven my struggles explaining Spectre to some professional developers having a logo and a name seems like a smart idea if you want to convince someone who doesn't program at all to listen to you at all.
- pseudosavant 5y agoSome of these claims... "can retrieve data from Chrome extensions (such as credential managers) if a user installs a malicous extension." News flash, you can do pretty much anything you want if you can get the user to install a malicious extension. That is social engineering, not a side-channel attack.
- floober 5y agoI think the severity of this would very much depend on the permissions that would have to be granted to the extension in order for it to happen.
- noway421 5y agoWill putting `rel=noreferrer` on your links help you protect from this?
- Nextgrid 5y agoThis is why I use the 1Password Classic extension (which they try to deprecate in favour of 1Password X). If I understand correctly, this extension can only ever ask the main 1Password UI (running in its own system process) to appear (providing site metadata such as the URL so it can suggest relevant accounts), in which I can then select the password I want. This means the browser extension itself has no access to the master password nor the entire password database. In contrast, 1Password X and LastPass seem to let the browser extension access all passwords including the master password.