Hacker News new | ask | show | jobs
by brightghost 4741 days ago
Isn't this just the standard 'Windows is woefully insecure' problem? I would be curious to see how this works in the browsers on OS X.
1 comments

On OS X, the passwords are probably stored in the Keychain which would be much better than this.

Personally, I just disable all password storage on all browsers and use 1Password.

Firefox will use the OSX keychain only if you install Keychain Services Integration: https://addons.mozilla.org/en-US/firefox/addon/keychain-serv... . I highly recommend it.
Chrome OSX stores in OSX keychain out of the box.
Like I said, I opt to use 1Password instead for cross platform usage.
So locally running malware only needs to keylog your master 1Password password to decrypt your 1Password data file?
This is harder than it used to be due to the secure text entry and sandboxing options which OS X has added but it's definitely the biggest risk for password manager users.
If you have a keylogger on your machine, all hope is lost. This is true for any password based security, much like a the best safe in the world is thwarted by someone videotaping you entering the combination. Even so, 1Password does utilize sandboxing in OS X and a secure desktop in Windows, which should in theory make this significantly harder to achieve.
Yes... and the premise of the original post was about vulnerability to arbitrary code being executed on the machine with the user account's rights. I.e., nothing's stopping the keyloggers now.

This is the airtight hatchway we're talking about. The post's premise, and the solutions for Chrome and IE, imply bad guys are already on the other side. All hope is lost. Best you can do is try and make it so that anyone just stumbling around rather than purposefully looking for the passwords doesn't find them, and the value of that is questionable on false sense of security arguments.

It's non-news to anyone who understands how Windows is built.

Same here, amazingly happy with LastPass and it even makes logging in on mobile a breeze :)