TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Spook: Side channel attack which could read the memory from password managers

295 点作者 dcu超过 3 年前

13 条评论

bee_rider超过 3 年前
This title seems a bit over-broad. The attack is based on using the built-in chrome credential manager. Further, it seems to depend either on the user installing an evil chrome plugin (in which case, you are already doomed, right?), or confusing a website like Tumblr into mixing up the user content and the login page, and getting the autofill info there.<p>The second attack seems limited to just the site that is being messed with. The fact that sites like Tumblr which apparently (?) host random unvetted javascript for bloggers aren&#x27;t protected by site isolation is not that surprising, right?<p>Anyway, autofill and built-in password managers have always seemed suspicious to me. People should stick to stuff like keepass I guess.
评论 #28621717 未加载
评论 #28621507 未加载
评论 #28620058 未加载
评论 #28620270 未加载
评论 #28621598 未加载
评论 #28625588 未加载
评论 #28623851 未加载
bananaportfolio超过 3 年前
It looks like they were able to exploit the Last Level Cache of Intel and Apple processors, but failed to do so against an AMD processor using the Zen architecture. Instead of plainly saying as much, the authors simulate a theoretical leakage rate for AMD processors by way of making V8 expose clflush in absence of a practical LLC eviction mechanism.
评论 #28621563 未加载
alanbernstein超过 3 年前
So does this justify my use of a password manager with no browser integration, and all the microseconds of lost productivity due to copying and pasting passwords all the time?
评论 #28619124 未加载
评论 #28619415 未加载
评论 #28619098 未加载
评论 #28620109 未加载
评论 #28619115 未加载
评论 #28620822 未加载
评论 #28621928 未加载
评论 #28620310 未加载
_wldu超过 3 年前
Web browsers today have “everything but the kitchen sink” capabilities built-in and are becoming more and more complex each year. They are turning into whole platforms that have browser plug-ins and extensions for every possible need known to humankind.<p>While many of these add-ons are handy and useful, we should not trust them with password management. Browsers are just too complex and have far too much going on.<p>Full article: <a href="https:&#x2F;&#x2F;www.go350.com&#x2F;posts&#x2F;the-design-flaws-of-password-managers&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.go350.com&#x2F;posts&#x2F;the-design-flaws-of-password-man...</a>
评论 #28619490 未加载
c7DJTLrn超过 3 年前
Alright, it has a site and a logo, it checks out.
评论 #28621850 未加载
MrWiffles超过 3 年前
As if we needed yet another reason to avoid Chrome and friends…
评论 #28618712 未加载
Nextgrid超过 3 年前
This is why I use the 1Password Classic extension (which they try to deprecate in favour of 1Password X).<p>If I understand correctly, this extension can only ever ask the main 1Password UI (running in its own system process) to appear (providing site metadata such as the URL so it can suggest relevant accounts), in which I can then select the password I want. This means the browser extension itself has no access to the master password nor the entire password database.<p>In contrast, 1Password X and LastPass seem to let the browser extension access <i>all</i> passwords including the master password.
sigg3超过 3 年前
And other than Chrome?<p>&gt; we expect most Chromium-based browsers to be vulnerable [... including] recent versions of Microsoft&#x27;s Edge browser, as well as Brave
pseudosavant超过 3 年前
Some of these claims... &quot;can retrieve data from Chrome extensions (such as credential managers) if a user installs a malicous extension.&quot;<p>News flash, you can do pretty much anything you want if you can get the user to install a malicious extension. That is social engineering, not a side-channel attack.
评论 #28621720 未加载
theogravity超过 3 年前
This is around the third time that I&#x27;ve read about a vulnerability with LastPass.<p>Is 1Password susceptible to the same attack?
评论 #28619267 未加载
noway421超过 3 年前
Will putting `rel=noreferrer` on your links help you protect from this?
manbart超过 3 年前
No sr g. It on we fbeg feed th C hey Vic
Aachen超过 3 年前
Damn, I thought this must be a Dutch find since Spook.js lends itself beautifully as a Dutch word, but alas.
评论 #28619048 未加载