Live data from Hacker News

Browser Extension Password Managers Exposing Passwords Everywhere

isecpartners.github.io

51–60 of 93 posts

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#51
post #42

This title is hyperbolic linkbait and should probably be changed. From skimming the paper, the only real flaw that seems broadly applicable is in autofill features which I'm not sure 1Password even has. Those intuitively seem like a bad idea and are easy to disable.

It also mentions that auto filling is the default for two of them.

Also, not making the distinction between http/https allows retrieving most passwords if you can man-in-the-middle

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#52
post #42

This title is hyperbolic linkbait and should probably be changed. From skimming the paper, the only real flaw that seems broadly applicable is in autofill features which I'm not sure 1Password even has. Those intuitively seem like a bad idea and are easy to disable.

It also mentions that auto filling is the default for two of them.

Also, not making the distinction between http/https allows retrieving most passwords if you can man-in-the-middle

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#53
post #42

This title is hyperbolic linkbait and should probably be changed. From skimming the paper, the only real flaw that seems broadly applicable is in autofill features which I'm not sure 1Password even has. Those intuitively seem like a bad idea and are easy to disable.

It also mentions that auto filling is the default for two of them.

Also, not making the distinction between http/https allows retrieving most passwords if you can man-in-the-middle

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#54

Earlier quoted context omitted.

I honestly think for security purposes in general you shouldn't auto fill in a form regardless of the domain and the extension builders should just not build that feature because it exposes issues like this.

What's the alternative? Generate randomized passwords and memorize them all? I have 250+ passwords for different websites, and not a great deal of choice about it. This is certainly way better than the actual likely alternative -- using the same password on all 250+ sites.

1Password's browser extension v4, in contrast, fills in the form only when you press a key combination (⌘-\ on OSX), and has you enter your master password into a dropdown from the OSX Menu Bar, and not inside the browser frame. Pretty snazzy all around.

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#55
On an unrelated note: I am looking for a password manager that would allow me to assign a system wide shortcut. When the shortcut is pressed, a window would appear where I can search for the password I am looking for (think Alfred or Launchy). Searching for the password and hitting enter would type in the password into whatever field I previously had selected. Something open source would be perfect. I looked, but did not find anything like that. Something that works on OSX and Windows.

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#56
post #11

Earlier quoted context omitted.

Basically you just need to turn off auto-login and auto-fill on all sites, no matter what your password manager is. All of the attacks depended on those two features, from what I could tell from a quick scan of the paper.

Can you do that globally?

I just did. (Using LastPass).

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#57
post #55

On an unrelated note: I am looking for a password manager that would allow me to assign a system wide shortcut. When the shortcut is pressed, a window would appear where I can search for the password I am looking for (think Alfred or Launchy). Searching for the password and hitting enter would type in the password into whatever field I previously had selected. Something open source would be perfect. I looked, but did…

I'd say KeePass, but that last bit (OSX and Windows) is what eventually made me turn to 1password, :/.

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#58
I never use password managers. The reason is simple: I don't want to rely on another software. If I had to remember 20 passwords I would and in fact I do carry around 10 different passwords in my head constantly.

I trust my own brain rather more. And if my brain is comprised, what else can you do with all the security we have on our desktop?

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#59
post #8

Looks like LastPass really screws up by auto filling forms within emails and submitting them. Which means that I can duplicate the yahoo login page, send it to your yahoo mail and LastPass would fill it up and submit because it's served under yahoo domain. 1Password seems to be just fine according to this paper. It did not fuck up like Lastpass and only live flaw is about subdomain matching, which I actually find use…

Not sure it would be that easy. LastPass only auto fills known domains, so you would have to spoof that too.

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#60

This just completely ruins LastPass as an enterprise product, which seems to be a major revenue stream for them. (Unless LP enterprise allows admins the option to globally disable these insecure "features".)

interesting thought, I'll check it out.

Update: No, not able to set up a global policy - I'll contact them.

Post reply on HN