5 ms·
Pasting a password into a phishing site because you don't have the browser checking the domain for you seems like a bigger risk than being exploited by somethin
by kam 5y ago
Pasting a password into a phishing site because you don't have the browser checking the domain for you seems like a bigger risk than being exploited by something like this.
- ziml77 5y agoAgreed. The only time I nearly lost an account to phishing it was because I manually copy-pasted my credentials. It's an easy mistake to make, especially if you happen to be tired or distracted.
- marbu 5y agoGood mitigation of that would be for a password manager to store an url along with password.
- K5EiS 5y agoThat is usually what password managers do.
- Biganon 5y agoParent comment was precisely using this as a pro for in-browser password managers (or extensions). They can check the current domain. A standalone desktop app can't do that (well it can, but it's a bit more complicated to truly understand what tab you're currently looking at, and intend to use a password with)
- marbu 5y agoTo clarify: I suggested to store url in the password manager so that when I want to login somewhere, I go the the manager, locate the account, copy paste url stored there into url bar of the browser in a new tab, and then do the same with actual credentials. There is no room for any phishing in such case. That said I understand that when a password manager is closely integrated with (or even within) a browser, it can do more checking for me, and make the whole experience nicer. But such integration is imho not a silver bullet, and there are downsides which comes with this approach as well.
- the8472 5y agoIf you're not using SSO/central identity providers and use each site's own login form instead you're much less likely to encounter an unexpected login form which makes any such form suspicious.
- Thorrez 5y agoThe classic phishing is an email from e.g. Facebook saying your account is at risk of something. So you click the Facebook link and sign in to Facebook (uh oh that was actually a phishing site pretending to be Facebook). I don't see how avoiding SSO helps with this.
- the8472 5y agoEmail is a separate topic. I have a domain and use a separate address for each service. So phishing tends to go to the wrong address and thus the wrong folder, which makes things pretty obvious.
- Thorrez 5y agoMy point is I don't see how whether you use SSO or not is relevant. If you use SSO, you could fall for an SSO phishing page. If you don't use SSO you could fall for a non-SSO phishing page. If your email is hidden, then someone might send you a phishing link via a HN reply. The reply might link to a website that has a domain similar to Facebook and presents a Facebook phishing login.
- the8472 5y agoMy experience with SSO workflows is that they often ask for reauthentication due to limited credential timeouts. They pop up randomly as you visit sites you're used to visit. On the other hand site-specific logins tend to last longer which means I'm unlikely to encounter a login prompt as part of regular browsing. To given an example, github only prompts me for my personal credentials when I use the security settings or to authorize a bot. This doesn't happen often, so it's somewhat surprising and makes me check. But my $WORK SSO tied to their github org (and a whole bunch of other things) wants me to log in every other day. This makes more less likely to check since it's forced routine.
- orangepurple 5y agoYou paste the HTTPS login URL from your password manager entry THEN log into the page after the browser validates the HTTPS certificate
- barbazoo 5y agoOne would argue that then you're way beyond "microseconds of lost productivity".
- IncRnd 5y agoThat's what I do for certain types of sites, such as bill-payments, and I don't lose any productivity. It does take time, yes, but there isn't enough time lost that would inhibit productivity.
- tedunangst 5y agoMillions and millions of microseconds lost.
- subsection1h 5y agoI have a wrapper script for pass (passwordstore.org) named pass-open that selects a password file using fzf, copies the included password and opens the included URL (if there is one). Also, my password files may include web browser names and profile names because I log into sites using different web browsers and profiles. So in addition to being my password manager, pass and my wrapper script are my cross-browser bookmark manager, which is convenient because I'm usually in a terminal emulator. I've never understood why people at HN use graphical password managers that are integrated into web browsers and autofill, etc. (but I've never understood why people at HN use most of the graphical software they use).
- gen220 5y agoYou’re not crazy, but we are in the minority. Most people, self-professed hackers included, are more comfortable in the browser sandbox than the terminal emulator sandbox. pass has a better UX than any password manager I’ve ever been compelled to use for work. Especially when used in the way you describe, as your index to the browser (rather than as a sidecar to the browser).