This title is hyperbolic linkbait and should probably be changed. From skimming the paper, the only real flaw that seems broadly applicable is in autofill features which I'm not sure 1Password even has. Those intuitively seem like a bad idea and are easy to disable.
It also mentions that auto filling is the default for two of them.
Browser Extension Password Managers Exposing Passwords Everywhere
51–60 of 93 posts
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#52This title is hyperbolic linkbait and should probably be changed. From skimming the paper, the only real flaw that seems broadly applicable is in autofill features which I'm not sure 1Password even has. Those intuitively seem like a bad idea and are easy to disable.
It also mentions that auto filling is the default for two of them.
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#53This title is hyperbolic linkbait and should probably be changed. From skimming the paper, the only real flaw that seems broadly applicable is in autofill features which I'm not sure 1Password even has. Those intuitively seem like a bad idea and are easy to disable.
It also mentions that auto filling is the default for two of them.
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#54Earlier quoted context omitted.
I honestly think for security purposes in general you shouldn't auto fill in a form regardless of the domain and the extension builders should just not build that feature because it exposes issues like this.
What's the alternative? Generate randomized passwords and memorize them all? I have 250+ passwords for different websites, and not a great deal of choice about it. This is certainly way better than the actual likely alternative -- using the same password on all 250+ sites.
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#55Re: Browser Extension Password Managers Exposing Passwords Everywhere
#56Earlier quoted context omitted.
Basically you just need to turn off auto-login and auto-fill on all sites, no matter what your password manager is. All of the attacks depended on those two features, from what I could tell from a quick scan of the paper.
Can you do that globally?
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#57On an unrelated note: I am looking for a password manager that would allow me to assign a system wide shortcut. When the shortcut is pressed, a window would appear where I can search for the password I am looking for (think Alfred or Launchy). Searching for the password and hitting enter would type in the password into whatever field I previously had selected. Something open source would be perfect. I looked, but did…
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#58I trust my own brain rather more. And if my brain is comprised, what else can you do with all the security we have on our desktop?
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#59Looks like LastPass really screws up by auto filling forms within emails and submitting them. Which means that I can duplicate the yahoo login page, send it to your yahoo mail and LastPass would fill it up and submit because it's served under yahoo domain. 1Password seems to be just fine according to this paper. It did not fuck up like Lastpass and only live flaw is about subdomain matching, which I actually find use…
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#60This just completely ruins LastPass as an enterprise product, which seems to be a major revenue stream for them. (Unless LP enterprise allows admins the option to globally disable these insecure "features".)
Update: No, not able to set up a global policy - I'll contact them.