6 ms·
These sorts of 'exploits' take advantage of the site-agnostic nature of passwords. Using a password manager may be able to mitigate this. For this particular a
by a257 5y ago
These sorts of 'exploits' take advantage of the site-agnostic nature of passwords. Using a password manager may be able to mitigate this.
For this particular attack, a fun 'solution' may be to incorporate some sort of AI-based detection system to warn the user if anything resembling a browser is shown on the site.
- pcthrowaway 5y agoA password manager would detect that the site doesn't match, so unless you copy it out of the vault directly it's likely to keep you secure.
- Nextgrid 5y agoA lot of popular password managers share them across subdomains by default, so if you manage to get this on a subdomain of the target domain it'll work fine.
- lxgr 5y agoIf an attacker can get arbitrary content on a subdomain of your site, isn't that pretty much game over for credentials on the apex domain?
- darepublic 5y agothere are various times where I copy out the password manager password because it just doesnt play well with the site. this includes big sites like aws console btw
- saltminer 5y agoAt least with BitWarden, when I click on the extension icon, the site in question should still show up. If I have to search for it, either the domain has changed or something smells phishy.
- miohtama 5y agoNo, the solution is to get rid of passwords. WebAuthn is already being deployed. There will be a decade of consumer education ahead. https://en.wikipedia.org/wiki/WebAuthn https://en.wikipedia.org/wiki/WebAuthn
- asiachick 5y agoI'm not up on all the details but if I use WebAuthn in a major browser can I trivially give a different id to every website or is it more like they all want to authenticate me as the same person joe@apple.com, jill@google.com, clippy@outlook.com etc,....
- tialaramex 5y agotl;dr Yes you can definitely give a different ID to every web site and it's not even possible to correlate those IDs based on you using WebAuthn for them The elliptic curve private keys used to sign the authentication message are actually different for every site you use the authenticator with, they're chosen at random and cheap authenticators aren't even storing them anywhere, which is part of how fiendishly clever WebAuthn / FIDO is. Because the authenticators aren't storing the identifier, if you sign into GitHub as asiachick, after having previously enrolled your authenticator as southamericandude even that authenticator has no idea you're asiachick, and so it won't give the game away, and you can even enroll the same authenticator for both these users and it will work, correctly, and GitHub can only even prove anything is going on by deliberating asking asiachick to authenticate as southamericandude or vice versa, which they've got no reason to try. Now, if you are using WebAuthn to do usernameless authentication (no password, not even a username, just WebAuthn and one touch to log in) this can't work without the authenticator knowing the credentials. But in that case your local device gives you a menu saying like, asiachick or southamericandude ?
- userbinator 5y agoThis makes it possible to implement support for WebAuthn purely in software, making use of a processor's trusted execution environment or a Trusted Platform Module (TPM). Hell no. Do NOT want. No no no no no, never. A password is a simple concept. That stuff seems more aligned with incentives to create complexity, and thus increase possibility of things going wrong. Not to mention the overall dystopian nature of it all.
- cobbal 5y agoUnless your password manager displays a popup to be unlocked. Then that's spoofable too. Which is why I paranoidly move the popup to overlap the URL bar before unlocking.