3 ms·
These vaults conveniently come with unencrypted URLs of the login forms associated with each password. An attacker who discovers the plaintext of one password c
by bbbbb5 4y ago
These vaults conveniently come with unencrypted URLs of the login forms associated with each password. An attacker who discovers the plaintext of one password can trivially attempt to reuse that against all of the forms.
Incorrect password attempts are essentially free, so ECB revealing reuse does not meaningfully help the attacker.
- nequo 4y agoOh I see. That makes sense. But for the attacker to try one of my passwords in a login form, they do need to have that password cracked already, which means that they already have my master password. But if they have that, they can decrypt all of my passwords, and the login forms are of no use. Am I misunderstanding something here?
- bbbbb5 4y ago>Am I misunderstanding something here? No, not at all. The point is that while ECB is a silly choice, it does not make it easier for the attacker to crack your vault. It does allow the attacker to see if you're reusing passwords, but does not reveal to the attacker what those passwords are. On the other hand, If the attacker were to discover one of your passwords from another source, they'd be able to confirm reuse anyway by simply attempting to use that password on other websites.