5 ms·
This is where password managers are useful because they would refuse to fill in login information since the domain doesn't match
by weird-eye-issue 4mo ago
This is where password managers are useful because they would refuse to fill in login information since the domain doesn't match
- vel0city 4mo ago"Dang, this site isn't working right with the password manager's detection. Guess I just gotta paste the password in again..." Meanwhile U2F/Passkeys can't possibly be abused like this.
- tjoff 4mo agoYeah but the downsides of passkeys make them so much worse anyway.
- jcattle 4mo agoPretty happy with having a yubikey on my keychain. Log in someplace new? plonk in your yubikey and off you go!
- someguyiguess 4mo agoAnd when your keychain gets lost then what?
- brendoelfrendo 4mo agoI open the safe where I keep my spare Yubikey. Or I use the passkey stored in my phone, or the one on my laptop. Make passkeys, put them everywhere.
- jcattle 4mo agoThen I have a backup yubikey at home for services which allow to register two keys. For other's there's still good old password+some second factor.
- vel0city 4mo agoThen I use the authenticator built into my phone. Or the authenticator built into my desktop. Or the authenticator built into my laptop. Or my other authenticator. My phone was destroyed not too long ago. I had been using it for passkeys. Oh no, all those passkeys were gone. No problem, when I got my new phone I just used the authenticator on my keyring to get back into my accounts. If my keyring authenticator got lost I'd just buy a new authenticator eventually and add it to my accounts.
- LtWorf 4mo agohttps://xkcd.com/981/ https://xkcd.com/981/
- AlotOfReading 4mo agoI used to keep a yubikey in a spare slot on my laptop. One day it fell out and subsequently escaped through an unnoticed hole in my backpack. I've never lost a password because my backpack was overly abused.
- brendoelfrendo 4mo agoThat's why you keep it on your keychain and not in a spare slot on your laptop.
- AlotOfReading 4mo agoIt's not possible to put a 5c nano on a keychain. They're intended to be kept in the slot at all times.
- deleted 4mo ago[deleted]
- iknowstuff 4mo agoPasskeys are great. Store them in your password manager and what downsides are you referring to
- bonoboTP 4mo agoExactly. All these ideals work in theory but then in reality banks are also incompetent and will use all kinds of domains. Same with meta and Google where they often direct you to domains that aren't under their main one and it's actually legit, but there's no way to know. It's impossible to teach family members to pay attention if it's really that domain because it's often legit not that domain.
- weird-eye-issue 4mo agoWell mine pops up a big warning if you try pasting when the domain doesn't match it so at least it would force you to take a second look. Also all the real world services that I use half past keys as 2fa which I also store in the password manager
- StableAlkyne 4mo agoI use keepass (FOSS under GPL, fully offline). It does not detect domains.
- graemep 4mo agoKeepassXC browser integration will do that.
- jabroni_salad 4mo agoThe autotyper can with a little bit of finangling. Every browser has a 'url in title bar' extension avaialble and then you can use that for your autotype matching. If you do not like to use extensions, changing a page's title is a trivial bookmarklet or userscript to make I would think.
- throawayonthe 4mo agoyou can have it be offline and still a browser extension (when i used keepassxc it could to that)
- weird-eye-issue 4mo agoMaybe use a better one or the browser extension like other commenters are saying?
- tuetuopay 4mo agoThat's without considering a lot of banks have non-textual inputs for their passwords. Man they love their scrambled virtual keyboard! I think the worst I ever had was HSBC that asked me for fragments of my password, like characters 4, 6, 7, 11, and 12. Absolute bonkers of a security theatre.
- shermantanktop 4mo agoHad a similar UK bank experience. Without knowing it would be used for that, I had created a password that had digits. So "What's the 4th character" would be something like "6," "What's the 6th digit" would be "2," like an Abbott and Costello routine.
- weird-eye-issue 4mo agoOh I've never seen anything like that. But it would still help because my password manager pops up matching logins so you could just open that manually and then copy paste parts of it or type it in.
- tuetuopay 4mo agoDefinitely. If bitwarden does not shows a little "1" icon I'm basically lolnope'ing out. Still, it pains me to see that practices from the early keylogger era are still "good practices".
- srdjanr 4mo agoHow can they even do that without storing plaintext passwords?
- tuetuopay 4mo agoIt's a bank, and a rather old at that. I fully expect them to store the password in cleartext. (hence the security theatre qualification) Banks are notorious for taking security as a strict cost/savings measure. I would not be surprised if they enforce weak passwords stored in cleartext on purpose to save on support agents for the people that forget/lose their password. Imagine the customer service reviews: "they were able to find my password back, 5/5". Probably enough savings to offset the cost of refunding people that got their account pwnd. Cost of doing business.
- pibaker 4mo agoUnfortunately it's not uncommon to find legitimate websites that break autofill in some ways. And the more such websites a user encounters, the more likely he will just mindlessly paste his password into a phishing site as he has learned to do for real ones. Passkeys solve this problem but has its own usability issues.
- weird-eye-issue 4mo agoMy password manager will warn me if I manually copy a password out of it and then try to paste it in a domain that does not match