• gaylord_fartmaster@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      4 hours ago

      Someone manages to maliciously sneak username and password fields onto a site that store what is entered as soon as it’s typed. They don’t even have to be visible to the user and bitwarden will fill them in as soon as the page loads.

        • gaylord_fartmaster@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 hours ago

          Right, “maliciously sneak”, as in they’ve either gained access to make changes to the site ditectly, or they’ve found a way to inject their scripts to steal creds.

          • Serinus@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            27 minutes ago

            And how is that any different from not having a password manager?

            Yes, if someone hijacks a domain they can get credentials intended for that domain. A password manager doesn’t make a huge difference here, because why would they make the site look any different than normal?

            • gaylord_fartmaster@lemmy.world
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              1
              ·
              1 hour ago

              They don’t even have to be visible to the user and bitwarden will fill them in as soon as the page loads.

              I guess you didn’t read most of the comment.