Kevin Karhan :verified: · @kkarhan
1441 followers · 102814 posts · Server mstdn.social

@b33fpebble @jnbhlr @yassie_j personally, I think that tools like enpass.io work well as that they offer only on legitimate or rather known domains, so -based doesn't work.

Plus they don't do fully-automatic auto-filling but rather expect the user to choose the credentials in an overlay offered by the extension.

So it's not as if one can provoke logins just with an HTTP(S) request.

Even then still demands one to enter a Password or PIN.

#Enpass #Phishing #typosquatting #autofill

Last updated 1 year ago

Amadeus Paulussen · @amadeus
193 followers · 1137 posts · Server mstdn.social

@utopify_org The few times I used a third-party account to login to a site I ended up having some sort of special case account that would not allow me to migrate to a real account with a different email address at a later point in time. As I have anything neatly organized in a and my information anyway I prefer real accounts and apart from the effort to create those accounts manually I feel like I don't benefit from such a login service.

#autofill #PasswordManager

Last updated 1 year ago

Wendell Bell · @wndlb
251 followers · 4563 posts · Server mas.to

@jorgecandeias The iOS app I use, @IceCubesApp, and the standard one have (1 per week) on both and . Then you pick the one with the highest utilization.

#hashtags #people #autofill #windows11

Last updated 2 years ago

Valerie Roney · @vlrny
1020 followers · 2604 posts · Server disabled.social

For your amusement:

The autofill suggests:

1) kafka-ish. WTF, nothing is kafka-ish. Yer frickin in a miserable soul crushing dystopia or you're not.

2) kafka-pot. Which sounds like:
a) something you try and cook your your dinner in but gets immediately consumed by the global elite
OR
b) a strain of weed you need when your life gets too kafka-esque.

#kafka #weed #autofill #autocomplete

Last updated 2 years ago

noticed a with browser extension in the way it interacts with embedded in webpages.

The vulnerability comes down to Bitwarden's behavior as well as the default matching (set by default to base domain, i.e. top-level and second-level domain matches).

They identify two attack vectors:

1) An uncompromised website embeds an external iframe (not sandboxed) that is under an attacker’s control and the ‘Auto-fill on page load’ option is enabled.

2) An attacker hosts a specially crafted web page under a subdomain of e.g. a hosting provider, which has its login form under the same base domain.

Recommended actions:

1) Make sure "Auto-fill on page load" is disabled.

2) Set "Default URI match detection" to "Host" or "Exact".

flashpoint.io/blog/bitwarden-p

#flashpoint #vulnerability #bitwarden #iframes #autofill #uri

Last updated 2 years ago

Yellow Flag · @WPalant
2011 followers · 3465 posts · Server infosec.exchange

As people are discussing functionality of password managers, may I point you to this four years old article of mine?

palant.info/2018/08/29/passwor

As the last advise in the list, it says: “Ignore third-party frames.” Yes, I know that some (few) websites choose to be a PITA by using such frames for legitimate logins. So maybe one wants to consider combining that with a short allowlist. But autofilling in arbitrary third-party frames is just looking for trouble.

#autofill

Last updated 2 years ago

stark@ubuntu:~$ :idle: · @Stark9837
153 followers · 936 posts · Server techhub.social
Kevin Karhan :verified: · @kkarhan
759 followers · 35534 posts · Server mstdn.social

@kubikpixel @bitwarden that's why I don't like ...

#autofill

Last updated 2 years ago

Tarnkappe.info · @tarnkappeinfo
1993 followers · 4266 posts · Server social.tchncs.de
adingbatponder :mastodon: · @adingbatponder
131 followers · 896 posts · Server fosstodon.org

We have all accidentally typed a into a username field and had it stored by the of Chrome etc. to become visible by e.g. another user of your machine / session. How can it be that one cannot set it so that stupid behaviour is not possible? Can I set a of autofill text that is allowed and block all others? Or do I have to block autofill completely for ever?

#password #autofill #whitelist #2fa

Last updated 2 years ago

adingbatponder :mastodon: · @adingbatponder
131 followers · 896 posts · Server fosstodon.org

We have all accidentally type a into a username field and had it stored by the of Chrome etc. to become visible by e.g. another user of your machine / session. How can it be that one cannot set it so that stupid behaviour is not possible? Can I set a of autofill text that is allowed and block all others? Or do I have to block autofill completely for ever?

#password #autofill #whitelist #2fa

Last updated 2 years ago

DeadTOm :devuan: · @deadtom
225 followers · 668 posts · Server fosstodon.org

Computers have spoiled people. In particular, autofill.

Library management is having a big debate right now, regarding usernames. The primary complaint is that we have lots of people with the same first names, and autofill often fills in the wrong thing.

"So pay attention when you type, and don't rely on autofill". I say.

Trust me, how I said it in my head was way worse.

With the looks I got, you'd think I'd just strangled a puppy in the meeting.

#tech #autofill #userfriendly #computers

Last updated 2 years ago

Sortiermodus · @newdefined
241 followers · 8317 posts · Server troet.cafe

Ich habe seit einiger Zeit das Problem, dass im die Erweiterung den nicht mehr macht. Anfangs dachte ich, das wäre nur bei http so und https wäre okay. Aber es komplett unsystematisch und ich habe keine Idee warum

Dahinter steckt ein vaultwarden auf Docker….

#autofill #bitwarden #firefox

Last updated 2 years ago

CK's Technology News · @CKsTechNews
1716 followers · 1444 posts · Server cktn.todon.de

There are some people who claim function sucks, I like to remind such people that the autofill feature alone has 30 flags

#chomes #autofill

Last updated 2 years ago

Lukas 💻📌 · @dumbergerl
19 followers · 81 posts · Server fosstodon.org
Patrick Nepper · @nepper
28 followers · 50 posts · Server mastodon.social

Alright, time for a .

My name is Patrick. I work in at - more specifically on - you may have seen some of the products I get to work on with our globally distributed teams: .

I moved over to as many of you frustrated by its new, toxic leadership.

Outside of work, I'm a of three, as a local politician and councilman, and

#introductionpost #product #google #privacy #security #trust #safety #passwordmanager #autofill #payments #passkeys #FedCM #mastodon #dad #climatewrangler #runner #coffeeaddict

Last updated 2 years ago

🚀muskanity · @muskanity
518 followers · 150 posts · Server mas.to
Zrythm DAW · @zrythm
1004 followers · 1019 posts · Server mastodon.social

#zrythm #daw #autofill

Last updated 4 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online