Live data from Hacker News

Browser Extension Password Managers Exposing Passwords Everywhere

isecpartners.github.io

71–80 of 93 posts

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#71
post #58

I never use password managers. The reason is simple: I don't want to rely on another software. If I had to remember 20 passwords I would and in fact I do carry around 10 different passwords in my head constantly. I trust my own brain rather more. And if my brain is comprised, what else can you do with all the security we have on our desktop?

Because

1) Over the years it ends up being much more than 20 passwords. Bank accounts, credit cards, stock trading accounts, web servers, email accounts, IRA accounts, bitcoin passwords/keys, all kinds of work passwords, evernote, etc. I have more than 50 records in KeePass.

2) If you want secure passwords, they must be long (20 characters minimum) and random. Remembering something like that is nearly impossible for me. Once I started using KeePass, I feel way more secure than with my older scheme.

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#72

Earlier quoted context omitted.

What's the alternative? Generate randomized passwords and memorize them all? I have 250+ passwords for different websites, and not a great deal of choice about it. This is certainly way better than the actual likely alternative -- using the same password on all 250+ sites.

1Password's browser extension v4, in contrast, fills in the form only when you press a key combination (⌘-\ on OSX), and has you enter your master password into a dropdown from the OSX Menu Bar, and not inside the browser frame. Pretty snazzy all around.

Aha, I see the distinction now. Thanks. Enough to simply disable autofill in LastPass then? I'm loathe to learn a new system because of such a seemingly small size vulnerability.

LastPass has me enter the master password in a pop up window when I click on the icon from the extension (firefox/chrome), although I suppose that's maybe not as good as an independent application?

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#73
I wish iSEC Partners could have added My1Login (https://www.my1login.com) and DashLane (https://www.dashlane.com/) to their research paper so that we could have got deeper insights and comparison. My favorite is DashLane and I am very impress with its data security mechanism. Read https://www.dashlane.com/security page gives DashLane's security model in a nutshell.

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#74

Earlier quoted context omitted.

1Password's browser extension v4, in contrast, fills in the form only when you press a key combination (⌘-\ on OSX), and has you enter your master password into a dropdown from the OSX Menu Bar, and not inside the browser frame. Pretty snazzy all around.

Aha, I see the distinction now. Thanks. Enough to simply disable autofill in LastPass then? I'm loathe to learn a new system because of such a seemingly small size vulnerability. LastPass has me enter the master password in a pop up window when I click on the icon from the extension (firefox/chrome), although I suppose that's maybe not as good as an independent application?

Exactly.

I can, not only disable autofill in the Lastpass configuration, but also set to require password reprompt for any of my credentials. I could also individually disable autofill for any credential.

Please should first know how something works before criticizing.

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#75
post #28
post #8

Looks like LastPass really screws up by auto filling forms within emails and submitting them. Which means that I can duplicate the yahoo login page, send it to your yahoo mail and LastPass would fill it up and submit because it's served under yahoo domain. 1Password seems to be just fine according to this paper. It did not fuck up like Lastpass and only live flaw is about subdomain matching, which I actually find use…

Are you saying that yahoo web mail lets senders create forms with submit actions? That's.. Horribly broken. But tumbler allows JavaScript redirects to phishing sites, so yahoo standard I guess.

Gmail does this too.. It intercepts the action though, lets you choose if you really want to send.

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#76
post #59

Earlier quoted context omitted.

Not sure it would be that easy. LastPass only auto fills known domains, so you would have to spoof that too.

Hence why they said: "send it to your yahoo mail and LastPass would fill it up and submit because it's served under yahoo domain."

Then you disable autofill. Problem solved.

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#78
post #69

I use KeePass and I haven't integrated it into any of the web browsers I use. When I want to log into a site, I don't load it via my web browser's address bar; instead, I Alt-Tab to KeePass, Ctrl-F to find the site/account, Ctrl-C to copy my password, and Ctrl-U to open the site. This takes only a few seconds longer than using a browser extension like LastPass (which I've used to share credentials with family members…

Keepass has browser extensions as well. They're quite good and only gives the password to the site you want. https://github.com/pfn/passifox

Yes, this. There's also one for chrome. You can set it to have the keepass application pop up a yes/no dialog for every requested password so you will be notified whenever the extention requests the password.

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#79

I use KeePass and I haven't integrated it into any of the web browsers I use. When I want to log into a site, I don't load it via my web browser's address bar; instead, I Alt-Tab to KeePass, Ctrl-F to find the site/account, Ctrl-C to copy my password, and Ctrl-U to open the site. This takes only a few seconds longer than using a browser extension like LastPass (which I've used to share credentials with family members…

is anyone aware of an smartphone app that allows your phone/tablet to act as a usb keyboard for a pc, and "type" passwords in for you?

Bluetooth remote control ?

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#80
post #66

I use KeePass and I haven't integrated it into any of the web browsers I use. When I want to log into a site, I don't load it via my web browser's address bar; instead, I Alt-Tab to KeePass, Ctrl-F to find the site/account, Ctrl-C to copy my password, and Ctrl-U to open the site. This takes only a few seconds longer than using a browser extension like LastPass (which I've used to share credentials with family members…

It loses one key benefit though - phishing sites. When Lastpass doesn't fill something in that I expected it to fill in I eyeball the site very carefully to see wtf is going on.

No, it is actually more secure than Lastpass because the site is opened by KeePass directly (in the browser he specifies).
Post reply on HN