Hacker News new | ask | show | jobs
by rvz 1795 days ago
Well it still recognises to autofill in the password on a different subdomain as shown in the PoC by default, which is not good at all.

To Downvoters: So in the PoC [0] with the default settings the author is completely wrong about their findings? even if you 'manually' autofill in the fields?

So you are saying that the password DOESN'T get extracted out of Bitwarden from a different subdomain than where the login data was stored on by default then?

[0] https://marektoth.com/blog/password-managers-autofill/

1 comments

There is a setting in URL of the password called "Match Detection"[1]. You can change it to "Host" if don't want it to match subdomain.

[1]: https://bitwarden.com/help/article/uri-match-detection/#matc...

> by default

This is the point parent and the source article are making. Not whether or not it’s possible to be configured more securely.