|
|
|
|
|
by baobabKoodaa
1835 days ago
|
|
The instructions on PFP website for how to do various things, they often begin with the following steps: > Click PfP icon on any website > Enter your master password Can't a website just fake a PFP icon to induce you to reveal your master password, and now the website owner has access to all of your generated passwords? Isn't this exactly the type of attack that caused taviso to write OP? |
|
Yes the pop-up could be faked, but not the button.
Actually Tavis Ormandy found a lot of security breaches in password managers that loaded GUI elements into the website. Not only that you can fake it, but also they are susceptible to clickjacking.