Hacker News new | ask | show | jobs
by vorpalhex 963 days ago
Mobile apps, slightly tweaky domain names (which happens normally), much less fancy xss type attacks, plus general data exfil.
1 comments

Mobile BW app also wouldn't fill a password for a different domain
Can confirm this. Additionally, the Bitwarden app on mobiles also checks the app name (i.e. the 'com.company.appname' not the 'user friendly' name). It takes an extra step to 'force' Bitwarden to use a username/password if the name/domain does not match the name/domain(s) recorded against the username/password which adds a nice bit of friction.
There not even being an extra step is still much safer, no?
If I can't get my password thing to autofill on a mobile app (because the mobile app is on a different domain) then it's just annoying because I have to copy and paste over secrets.

That's the wrong thing twice over.

The password app should be as useful to me as a user as it can while still helping me be safe. "Hey, we can't confirm these creds are correct for this app. Do you still want to proceed?"

Or you can add another domain, saving users from easy buttons "yes, phish me anyway" is also useful