Earlier quoted context omitted.
I've found this to work pretty well in most cases, but there are some websites that don't semantically mark up their fields in a way the browser can recognize, and there's no way to manually trigger the password suggestion feature.
Worse, many sites -- notably banking sites -- reject secure passwords (no weird characters, no long passwords)
AppleID password brute force proof-of-concept
71–80 of 83 posts
Re: AppleID password brute force proof-of-concept
#72Re: AppleID password brute force proof-of-concept
#73Re: AppleID password brute force proof-of-concept
#74Earlier quoted context omitted.
I've found this to work pretty well in most cases, but there are some websites that don't semantically mark up their fields in a way the browser can recognize, and there's no way to manually trigger the password suggestion feature.
Worse, many sites -- notably banking sites -- reject secure passwords (no weird characters, no long passwords)
Re: AppleID password brute force proof-of-concept
#75Weird that this surfaces right after the celebrity photo leak eveyone attributes to an iCloud breach..
Re: AppleID password brute force proof-of-concept
#76Earlier quoted context omitted.
Worse, many sites -- notably banking sites -- reject secure passwords (no weird characters, no long passwords)
What is worse than rejecting is I know of one major site that would, at least used to, silently truncate long passwords. That was... frustrating.
Re: AppleID password brute force proof-of-concept
#77Earlier quoted context omitted.
Safari on OSX & iOS does do random password suggestions, out of the box.
I've found this to work pretty well in most cases, but there are some websites that don't semantically mark up their fields in a way the browser can recognize, and there's no way to manually trigger the password suggestion feature.
My Thai business banking system is paranoid and disables autocomplete, paste, etc, even with the security of a physical token), but the one that really annoys me is things like Basecamp - I had to futz around and disable JavaScript for a login to be recognised and prompt to save a password - by default it does an XHR which doesn't trigger the "save password" prompt.
Re: AppleID password brute force proof-of-concept
#78Earlier quoted context omitted.
@nikcub seems to think it wasn't this. https://twitter.com/nikcub/status/506421890517200896
he's assuming from when the tool was released. The exploit was in the wild for much longer.