Live data from Hacker News

Autofill in password managers can allow login credentials to be stolen

marektoth.com

141–144 of 144 posts

Re: Autofill in password managers can allow login credentials to be stolen

#141

Earlier quoted context omitted.

Do you have your password manager database and private keys backed up in a way that would survive if you have a fire? A lot of people may think they have backups of stuff like this but unless you remember to grab that thumb drive out of your desk drawer (assuming you're home) a fire might still destroy them.

No, no, I don't have my passwords anywhere but in a paper notebook. And I don't have any other copies. That's what I meant by "my reckless behavior". What percentage of people use a password manager? I think on iOS/macOS it's pretty high because Safari offers to save them, but what about non-technical users in general? As to why I don't use a password manager, I think that the probability of some bug or hack or whate…

> Do I really want to trust Firefox with all my passwords? Do I really want to trust Google with all my passwords? (Fuck no!) Do I really want to trust some random password manager with all my passwords?

There are options like KeePass or Bitwarden that allow you to store your own database file wherever you see fit or self host, respectively.

> The smart thing to do, which I unfortunately don't, is to memorize a handful of passwords and use a password manager for the rest. E.g. remember bank password, use a password manager for Chipotle and Five Guys.

This is the way that I mitigate risk as well. My email password is not present in the db, nor is my checking.

Re: Autofill in password managers can allow login credentials to be stolen

#142
post #88

God bless KeePass. Never have to deal with these. I just double click and ctrl+v whenever I need to use a pass. Takes extra 3 seconds but I feel like I am not giving anything to the browsers to save.

This is less secure than autofill, though it automatic autofill. At least autofill won’t enter your password for office.com on off1ce.com, though it’s possible that a human be fooled by a lookalike URL.

Re: Autofill in password managers can allow login credentials to be stolen

#143
post #22

Earlier quoted context omitted.

Well it still recognises to autofill in the password on a different subdomain as shown in the PoC by default, which is not good at all. To Downvoters: So in the PoC [0] with the default settings the author is completely wrong about their findings? even if you 'manually' autofill in the fields? So you are saying that the password DOESN'T get extracted out of Bitwarden from a different subdomain than where the login da…

There is a setting in URL of the password called "Match Detection"[1]. You can change it to "Host" if don't want it to match subdomain. [1]: https://bitwarden.com/help/article/uri-match-detection/#matc...

> by default

This is the point parent and the source article are making. Not whether or not it’s possible to be configured more securely.

Re: Autofill in password managers can allow login credentials to be stolen

#144
post #88

God bless KeePass. Never have to deal with these. I just double click and ctrl+v whenever I need to use a pass. Takes extra 3 seconds but I feel like I am not giving anything to the browsers to save.

Now your security issue is other applications accessing your clipboard. I'm quite aware of this ever since Samsung/Android started adding a whole interface for the clipboard and added integration with the keyboard (it shows some codes in the clipboard sometimes so you can quickly paste). Can the clipboard be accessed from other apps in the background? Probably?

Clipboard clears after 10 seconds.
Post reply on HN