TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Spook: Side channel attack which could read the memory from password managers

295 pointsby dcuover 3 years ago

13 comments

bee_riderover 3 years ago
This title seems a bit over-broad. The attack is based on using the built-in chrome credential manager. Further, it seems to depend either on the user installing an evil chrome plugin (in which case, you are already doomed, right?), or confusing a website like Tumblr into mixing up the user content and the login page, and getting the autofill info there.<p>The second attack seems limited to just the site that is being messed with. The fact that sites like Tumblr which apparently (?) host random unvetted javascript for bloggers aren&#x27;t protected by site isolation is not that surprising, right?<p>Anyway, autofill and built-in password managers have always seemed suspicious to me. People should stick to stuff like keepass I guess.
评论 #28621717 未加载
评论 #28621507 未加载
评论 #28620058 未加载
评论 #28620270 未加载
评论 #28621598 未加载
评论 #28625588 未加载
评论 #28623851 未加载
bananaportfolioover 3 years ago
It looks like they were able to exploit the Last Level Cache of Intel and Apple processors, but failed to do so against an AMD processor using the Zen architecture. Instead of plainly saying as much, the authors simulate a theoretical leakage rate for AMD processors by way of making V8 expose clflush in absence of a practical LLC eviction mechanism.
评论 #28621563 未加载
alanbernsteinover 3 years ago
So does this justify my use of a password manager with no browser integration, and all the microseconds of lost productivity due to copying and pasting passwords all the time?
评论 #28619124 未加载
评论 #28619415 未加载
评论 #28619098 未加载
评论 #28620109 未加载
评论 #28619115 未加载
评论 #28620822 未加载
评论 #28621928 未加载
评论 #28620310 未加载
_wlduover 3 years ago
Web browsers today have “everything but the kitchen sink” capabilities built-in and are becoming more and more complex each year. They are turning into whole platforms that have browser plug-ins and extensions for every possible need known to humankind.<p>While many of these add-ons are handy and useful, we should not trust them with password management. Browsers are just too complex and have far too much going on.<p>Full article: <a href="https:&#x2F;&#x2F;www.go350.com&#x2F;posts&#x2F;the-design-flaws-of-password-managers&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.go350.com&#x2F;posts&#x2F;the-design-flaws-of-password-man...</a>
评论 #28619490 未加载
c7DJTLrnover 3 years ago
Alright, it has a site and a logo, it checks out.
评论 #28621850 未加载
MrWifflesover 3 years ago
As if we needed yet another reason to avoid Chrome and friends…
评论 #28618712 未加载
Nextgridover 3 years ago
This is why I use the 1Password Classic extension (which they try to deprecate in favour of 1Password X).<p>If I understand correctly, this extension can only ever ask the main 1Password UI (running in its own system process) to appear (providing site metadata such as the URL so it can suggest relevant accounts), in which I can then select the password I want. This means the browser extension itself has no access to the master password nor the entire password database.<p>In contrast, 1Password X and LastPass seem to let the browser extension access <i>all</i> passwords including the master password.
sigg3over 3 years ago
And other than Chrome?<p>&gt; we expect most Chromium-based browsers to be vulnerable [... including] recent versions of Microsoft&#x27;s Edge browser, as well as Brave
pseudosavantover 3 years ago
Some of these claims... &quot;can retrieve data from Chrome extensions (such as credential managers) if a user installs a malicous extension.&quot;<p>News flash, you can do pretty much anything you want if you can get the user to install a malicious extension. That is social engineering, not a side-channel attack.
评论 #28621720 未加载
theogravityover 3 years ago
This is around the third time that I&#x27;ve read about a vulnerability with LastPass.<p>Is 1Password susceptible to the same attack?
评论 #28619267 未加载
noway421over 3 years ago
Will putting `rel=noreferrer` on your links help you protect from this?
manbartover 3 years ago
No sr g. It on we fbeg feed th C hey Vic
Aachenover 3 years ago
Damn, I thought this must be a Dutch find since Spook.js lends itself beautifully as a Dutch word, but alas.
评论 #28619048 未加载