Live data from Hacker News

How Browsers Store Your Passwords (and Why You Shouldn't Let Them)

raidersec.blogspot.in

11–20 of 82 posts

Re: How Browsers Store Your Passwords (and Why You Shouldn't Let Them)

#13
post #9

Earlier quoted context omitted.

On OS X, the passwords are probably stored in the Keychain which would be much better than this. Personally, I just disable all password storage on all browsers and use 1Password.

Firefox will use the OSX keychain only if you install Keychain Services Integration: https://addons.mozilla.org/en-US/firefox/addon/keychain-serv... . I highly recommend it.

Like I said, I opt to use 1Password instead for cross platform usage.

Re: How Browsers Store Your Passwords (and Why You Shouldn't Let Them)

#16
post #7

Other side of an airtight hatchway? For this to be at all relevant, you're already got me running your binary with my user's permissions.

Hi there! Thanks for the great comment. I had a similar one on my blog that I responded to in the following way (I hope it helps!): "Good question! You're right - in these cases it is assumed malware is already present on the system and running in the context of the user. But there can simply be better protection. Consider Firefox's use of a Master Password. Even if an attacker is on the otherside of the airtight hat…

But if there is already malware on the user system, it just needs to wait until the user authenticates once in Firefox to get the master password, then it can fetch all the other passwords. Right?

Re: How Browsers Store Your Passwords (and Why You Shouldn't Let Them)

#17

Other side of an airtight hatchway? For this to be at all relevant, you're already got me running your binary with my user's permissions.

Isn't that what the #poopin tweets are about? You're always going to let the hatchway open once by accident.

Re: How Browsers Store Your Passwords (and Why You Shouldn't Let Them)

#19

Other side of an airtight hatchway? For this to be at all relevant, you're already got me running your binary with my user's permissions.

Or, for example, attacker stole your backup via vulnerability in your NAS. Or, for example, some idiots share whole system volumes in e2k and Direct Connect networks. Or ever web:

https://www.google.ru/search?client=opera&q=intitle:%22index...

Re: How Browsers Store Your Passwords (and Why You Shouldn't Let Them)

#20
Google recently refused to give me access to my account when I'd lost the password.

While it was intensely frustrating at the time I'm actually grateful that it is so hard to get an account. I provided considerable amounts of information, but it wasn't enough for them to hand it over.

Still, when I got access to my super secret hard copy of passwords, and loaded Chrome onto a new machine, and signed into Google, I was a bit alarmed by just how much stuff came back from them onto my local machine. I'm currently slowly migrating to Yubikey and a nice password safe and better passwords for everything.

Post reply on HN