Live data from Hacker News

Browser Extension Password Managers Exposing Passwords Everywhere

isecpartners.github.io

11–20 of 93 posts

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#11

How bad is it for LastPass? I've used KeePass for a while, but the convenience of LastPass is such a killer feature :(

Basically you just need to turn off auto-login and auto-fill on all sites, no matter what your password manager is. All of the attacks depended on those two features, from what I could tell from a quick scan of the paper.

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#13
I use KeePass and I haven't integrated it into any of the web browsers I use. When I want to log into a site, I don't load it via my web browser's address bar; instead, I Alt-Tab to KeePass, Ctrl-F to find the site/account, Ctrl-C to copy my password, and Ctrl-U to open the site. This takes only a few seconds longer than using a browser extension like LastPass (which I've used to share credentials with family members).

In addition to this being potentially more secure, another benefit is that I can specify that KeePass open certain sites in a non-default web browser. I prefer not to log into some sites/accounts using my primary web browser, and KeePass helps me to avoid this. If I were to use a solution like LastPass for all my password management, I would need to pause and recall which browser I use to log into a site/account. But with KeePass, I just mindlessly Alt-Tab, Ctrl-F, Ctrl-C, and Ctrl-U.

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#14
post #8

Looks like LastPass really screws up by auto filling forms within emails and submitting them. Which means that I can duplicate the yahoo login page, send it to your yahoo mail and LastPass would fill it up and submit because it's served under yahoo domain. 1Password seems to be just fine according to this paper. It did not fuck up like Lastpass and only live flaw is about subdomain matching, which I actually find use…

With LP, auto-fill is an opt-in, per-domain feature.

Wouldn't Yahoo be exactly the type of site that you would opt-in to autofill for?

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#15
post #8

Looks like LastPass really screws up by auto filling forms within emails and submitting them. Which means that I can duplicate the yahoo login page, send it to your yahoo mail and LastPass would fill it up and submit because it's served under yahoo domain. 1Password seems to be just fine according to this paper. It did not fuck up like Lastpass and only live flaw is about subdomain matching, which I actually find use…

[deleted]

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#17
post #12

Is there a good, ideally free password manager that works on Android, iPhone, and the web? Any recommendations?

I use Keepass for this. The android port (https://play.google.com/store/apps/details?id=com.android.ke...) works perfectly fine for me, and it looks like there are a few ports for iOS as well. Keepass itself has, of course, long established itself as a solid password manager. And the cost is $0.
Post reply on HN