Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A malicious process could also do many other things. I think the most likely vector for autotyping attacks is simple phishing / clickjacking.



For general readers: Its pretty safe when done via a browser plugin to a website because the plugin both verifies the website (anti-phishing) and uses auto-fill rather than type (it directly injects into the target field rather than typing, so clickjacking isn't a risk).

Its rare that I use passwords outside of the browser now, but windows and mac allow system credentials to mitigate the same risks for desktop apps (the app must support it).


True, but wouldn't that apply to manual password entry as much?




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: