• gaylord_fartmaster@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 hours ago

    Someone manages to maliciously sneak username and password fields onto a site that store what is entered as soon as it’s typed. They don’t even have to be visible to the user and bitwarden will fill them in as soon as the page loads.

      • gaylord_fartmaster@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 hour ago

        Right, “maliciously sneak”, as in they’ve either gained access to make changes to the site ditectly, or they’ve found a way to inject their scripts to steal creds.

        • Serinus@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          18 minutes ago

          And how is that any different from not having a password manager?

          Yes, if someone hijacks a domain they can get credentials intended for that domain. A password manager doesn’t make a huge difference here, because why would they make the site look any different than normal?

          • gaylord_fartmaster@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            1 hour ago

            They don’t even have to be visible to the user and bitwarden will fill them in as soon as the page loads.

            I guess you didn’t read most of the comment.