Autofill in password managers can allow login credentials to be stolen
11–20 of 144 posts
Re: Autofill in password managers can allow login credentials to be stolen
#12Good advice. Ever since Tavis Ormandy set his sights on password managers, I have been a very sceptical user. I still use 1Password, but without the browser extension. Putting autofill aside, there's a couple of other concerns I have. I am hesitant about recommending a password manager to the tech illiterate simply because one piece of malware could compromise the entire vault. In that respect, a sticky note is argua…
A piece of paper is the most secure solution, sure, but once you get to the point where you have a hundred passwords, even if you've got them all in the same place, it's too unwieldy to use.
Re: Autofill in password managers can allow login credentials to be stolen
#13Good advice. Ever since Tavis Ormandy set his sights on password managers, I have been a very sceptical user. I still use 1Password, but without the browser extension. Putting autofill aside, there's a couple of other concerns I have. I am hesitant about recommending a password manager to the tech illiterate simply because one piece of malware could compromise the entire vault. In that respect, a sticky note is argua…
This should help alleviate some of the worst password manager risks.
Re: Autofill in password managers can allow login credentials to be stolen
#14Re: Autofill in password managers can allow login credentials to be stolen
#15Earlier quoted context omitted.
If an attacker is on your device, they very likely have access to your clipboard, so how is that more secure? I cringe whenever my password manager's autofill fails and I have to fall back to copy/pasting, because I know that I'm now storing my password in system memory in plaintext. Most password managers clear the clipboard after some timeout, but that's hardly helpful against an on-device threat
If the attacker has access to your device, you're going to be severely compromised no matter what you do. Why pretend otherwise?
Re: Autofill in password managers can allow login credentials to be stolen
#16I like password managers. It keeps people from writing them down on your desk or a notepad, so I'm all for it. I hate autofill. Any form of autofill, automated, user request, any of it. I would like people to just use a small button to open a 'mini instance' of the password manager, like an instant app (or app clips for iphones), and copy your password that way. Autofill is also a huge security risk, excluding if the…
Re: Autofill in password managers can allow login credentials to be stolen
#17Perhaps I'm slow. But if someone's discovered an XSS vulnerability for the site you're on, can't they just as well steal your password when you type it in?
Re: Autofill in password managers can allow login credentials to be stolen
#18Perhaps I'm slow. But if someone's discovered an XSS vulnerability for the site you're on, can't they just as well steal your password when you type it in?
If an XSS vulnerability appears on some other page, it may not be the same page that normally has a login form.
Generally I'd say the gates are kinda open if XSS is possible, but many real exploits do require more than 1 vulnerability working together; so defense in depth applies.
Re: Autofill in password managers can allow login credentials to be stolen
#19Earlier quoted context omitted.
If an attacker is on your device, they very likely have access to your clipboard, so how is that more secure? I cringe whenever my password manager's autofill fails and I have to fall back to copy/pasting, because I know that I'm now storing my password in system memory in plaintext. Most password managers clear the clipboard after some timeout, but that's hardly helpful against an on-device threat
If the attacker has access to your device, you're going to be severely compromised no matter what you do. Why pretend otherwise?
Re: Autofill in password managers can allow login credentials to be stolen
#20Bitwarden uses manual autofill which is nice. You hit ctrl shift L to fill
finally the bliss i had with lastpass before i was forced to move to bitwarden.