4 ms·
My password manager is a separate app, I always have to manually copy/paste the credentials. That's because I believed that approach to be more secure, now I se
by stanac 1y ago
My password manager is a separate app, I always have to manually copy/paste the credentials. That's because I believed that approach to be more secure, now I see it's replacing one attack vector for another.
- eviks 1y agoWhat's the most common example of an alternative attack with autofill?
- kaoD 1y agoThe password manager's autofill browser extension gets compromised.
- deleted 1y ago[deleted]
- karel-3d 1y agojust recently there was a clickjacking attack that affected most popular password manager extensions. It tricked the managers into filling passwords to random pages, worked on almost all extensions and all pages.
- eviks 1y agoAre you refering to this one https://marektoth.com/blog/dom-based-extension-clickjacking https://marektoth.com/blog/dom-based-extension-clickjacking? This doesn't seem to be "passwords on random pages", only "Personal Data + Credit Card,", passwords are domain-specific unless the website is hacked itself. > The attacker can only steal credentials for the vulnerable domain.
- karel-3d 1y agook that's nice
- welder 1y agoPlease change that now! It's the muscle memory of never typing a password that prevents you from being victim to phishing.
- SAI_Peregrinus 1y agoThe one I use (KeePassXC) is also a separate app, but there are browser extensions for the major browsers to support autofill. Of course plenty of sites don't actually work with autofill, even the browser builtin autofill, because they don't mark the form fields properly. So autofill not working is common enough that it's not a reliable red flag. Separate password managers have the advantage that they can store passwords for things other than websites, and secret data other than passwords (arbitrary files). KeePassXC's auto-type can work with any application, not just a browser.
- eviks 1y ago> Of course plenty of sites don't actually work with autofill, even the browser builtin autofill, because they don't mark the form fields properly. Can't KeePass use the autotype functionality, but still filter it by website domain/host that it gets from the extension? So basically you'll still never have to copy&paste, and any site requiring this would be a reliable red flag?
- SAI_Peregrinus 1y agoYes, that should generally work. I'm sure someone will decide to make a page requiring a CAPTCHA in between entering the username & the password to create an exception to this case though. It's the sort of insecure-by-design nonsense banks love.
- behindsight 1y ago> I always have to manually copy/paste the credentials. I really hope you clear your clipboard history entirely after doing your copy/paste method because your credentials would otherwise persist for any other application with clipboard perms to just exfiltrate (which has already been exploited in the wild before)
- mtlynch 1y ago>I really hope you clear your clipboard history entirely after doing your copy/paste method because your credentials would otherwise persist for any other application with clipboard perms to just exfiltrate (which has already been exploited in the wild before) How does that work? If a malicious website reads the clipboard, what good is knowing an arbitrary password with no other information? If the user is using a password manager, presumably they don't reuse passwords, so the malicious website would have to guess the matching username + URL where the password applies. If you're talking about a malicious desktop app running on the same system, it's game over anyway because it can read process memory, read keystrokes, etc. Sidenote: Most password managers I've used automatically clear the clipboard 10-15s after you copy a credential.
- behindsight 1y agoInteresting questions, I can later provide more links to more indepth security resources that go over similar points if you would be interested but currently on my phone so I will just jot down some quick surface level points. > If a malicious website reads the clipboard, what good is knowing an arbitrary password with no other information? Even if assuming unique username+url pairings, clipboard history can store multiple items including emails or usernames which could be linked to any data breach and service (or just shotgunned towards the most popular services). It's not really a "no other information" scenario and you drastically reduce the effort required for an attacker regardless. > If you're talking about a malicious desktop app running on the same system, it's game over anyway because it can read process memory, read keystrokes, etc. The app does not have to be overtly malicious, AccuWeather (among others) was caught exfiltrating users' clipboard data for over 4 years to an analytics company who may or may not have gotten compromised. Even if the direct application you are using is non-malicious, you are left hoping wherever your data ends up isn't a giant treasure trove/honeypot waiting to be compromised by attackers. The same reasoning can be used for pretty much anything really, why protect anything locally since they could just keylog you or intercept requests you make. In that case it would be safer for everyone to run Qubes OS and stringently check any application added to their system. In the end it's a balancing act between convenience and security with which striving for absolute perfection ends up being an enemy of good. > Sidenote: Most password managers I've used automatically clear the clipboard 10-15s after you copy a credential. That is true, good password managers took these steps precisely to reduce the clipboard attack surface. Firefox also took steps in 2021 to also limit leaking secrets via the clipboard.