Live data from Hacker News

Browser Extension Password Managers Exposing Passwords Everywhere

isecpartners.github.io

91–93 of 93 posts

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#91

Earlier quoted context omitted.

How can you set LastPass to globally disable auto-fill and auto-login? I checked again and I couldn't find any options in the extension or vault settings.

Using the Chrome extension, auto-fill is under Prefereces > General > and auto-login is under Preferences > Advanced.

Thanks.

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#92
post #76

Earlier quoted context omitted.

Hence why they said: "send it to your yahoo mail and LastPass would fill it up and submit because it's served under yahoo domain."

Then you disable autofill. Problem solved.

True....but now if I suggest LastPass to anyone I have to remember to opt-out of this feature.

I am actually a LP user, but I would prefer it was more secure by default.

Re: Browser Extension Password Managers Exposing Passwords Everywhere

#93
post #29
post #3

Earlier quoted context omitted.

I am curious, is there a way to do OTPs with offline databases? I tried poking around with the add-in, but couldn't quite determine whether the implementation could properly protect from replay attacks, most notably whether a copy of the xml file used and the matching old OTP would be enough to unlock a newer database file.

It's impossible to use OTP as part of an encryption key without some sort of oracle that could do the decryption without the OTP.

I know you can always backdoor it with the root key, and I decided to give up on this line because of that.

In theory you could guarantee the OTP going forward, but it would be impossible to protect going backward, which kind of kills the whole point.

Post reply on HN