2 ms·
> it cannot be read by exploiting a buffer overflow What does the attack that does this actually look like? Lastpass reads text off an html page and decides wh
by gregmac 4y ago
> it cannot be read by exploiting a buffer overflow
What does the attack that does this actually look like? Lastpass reads text off an html page and decides when to inject auto-fill prompts and/or enter in a password. Is it possible for a buffer overflow to be exploited there, that lets an attacker (who controls the site) gain access to a password for a different site? How does that work?
Is there some other attack possible here? Ie: is it possible another user-space application can read passwords from memory used by the password manager? How does another app know it's a password? How does it trigger a buffer overflow?
(I'm ignoring apps running with kernel or privileged access: that seems like game over)
- soraminazuki 4y agoCPU side channel attacks are a possibility. In the worst case, it could let an attacker cross OS process boundaries, making it exploitable remotely through Javascript executed in the browser. Although such vulnerabilities would be hard to find and even more difficult to exploit on scale, the possibility seems more realistic than it did pre Meltdown & Spectre. It would be nice if something as high stakes as a password manager was prepared for this kind of scenario.