52
top 21 comments
sorted by: hot top controversial new old
[-] grue@lemmy.world 14 points 6 days ago

Once again Keepass proves to be the superior solution.

[-] halcyoncmdr@lemmy.world 11 points 6 days ago* (last edited 6 days ago)

That's not at all what the article says.

They tested 11 popular password managers, Keepass wasn't one of them.

So if it wasn't even tested for attacks that nearly every other manager fails at least 1 aspect of, then you should assume it's not safe either.

[-] grue@lemmy.world 6 points 6 days ago

then you should assume it’s not safe either.

Well, except that the method of exploit was involving the web browser plugin, which isn't a thing Keepass does to begin with.

[-] arcterus@piefed.blahaj.zone 5 points 6 days ago

There is an extension, but it's significantly simpler than the other providers.

[-] pdxfed@lemmy.world 3 points 6 days ago

Just like Craigslist; every ounce of energy out into veneer is energy not in the core product design and maintenance and also adds cost. Minimal, functional, excellent.

[-] SoupBrick@pawb.social 13 points 6 days ago

1Password, Bitwarden, Enpass, iCloud Passwords, LastPass, and LogMeOnce

[-] arcterus@piefed.blahaj.zone 8 points 6 days ago

Once again I am reminded why I always use an adblocker.

[-] subignition@fedia.io 7 points 6 days ago

This is somewhat clever, but if you're phished into attempting to login on a malicious page, you've already lost

[-] Catoblepas@piefed.blahaj.zone 4 points 6 days ago

Per the article, the attack works by making you think you’re clicking CAPTCHAs and reduces the opacity of the auto login buttons you’re actually pressing.

[-] subignition@fedia.io 1 points 6 days ago
[-] Catoblepas@piefed.blahaj.zone 6 points 6 days ago

Then I guess your comment confused me because the attack doesn’t require the user to attempt to log in. Completing a CAPTCHA on a random page isn’t internet idiot behavior, it’s what we’ve been trained to expect is the norm.

[-] subignition@fedia.io 3 points 6 days ago

I think I meant to reply to the user who was talking about KeePass. If you have brought the user to a malicious page, you can already just impersonate the login form and something like KeePass that doesn't offer to autofill passwords will be none the wiser (because the user initiates the paste / autotype)

In the XSS case, I think this would be occurring on a page the user trusts but has been compromised by an external script (via an ad or other means). If it's at a domain the user has saved credentials for, odds are high it's a login page, but I think you're right that an attacker could probably add their own input field to provoke the password manager overlay, with an innocuous-looking fake captcha or cookie banner over it.

[-] SpikesOtherDog@ani.social 7 points 6 days ago

Any insight in attacks on the browser password managers themselves?

[-] Blueshift@piefed.world 6 points 6 days ago

Wouldn’t the attack need to happen on a subdomain of the site they’re trying to steal credentials for? At least Bitwarden won’t suggest any credentials to autofill otherwise (haven’t tried the others)

[-] hexagon527 6 points 6 days ago

So if I just use the desktop app and not the browser extension then I'm good?

[-] SendMePhotos@lemmy.world 1 points 6 days ago

That's what I'm getting from this too

[-] SlartyBartFast@sh.itjust.works 3 points 6 days ago

This is why I tattoo all my passwords backwards on my asscrack

[-] FailBetter@crust.piefed.social 4 points 6 days ago

I'm an idiot using bw, do we have much confidence in any means of avoiding this yet or no?

[-] leo@lemmy.linuxuserspace.show 9 points 6 days ago

The easy-ish way is to use the desktop app, but from the article:

However, Bitwarden told BleepingComputer that the issues have been fixed in version 2025.8.0, rolling out this week.

[-] FailBetter@crust.piefed.social 8 points 6 days ago

I have pretty unserious threat model, so hopefully bw team is trustworthy enough to believe in their upcoming fix.

Many thanks Leo!

[-] Cris_Color@lemmy.world 2 points 6 days ago

My understanding is that bitwarden is generally very well regarded by security knowledgable folks, with the most secure option being keepass synced manually, and seemingly bitwarden behind that (among popular choices)

That is my impression as a fairly non-technical casual privacy/security pursuer anyway 🤷‍♂️ I'm also a Bitwarden user as it's a better balance of practicality and security for my needs and usecase

this post was submitted on 21 Aug 2025
52 points (100.0% liked)

Linux and Tech News

2171 readers
2 users here now

This is where all the News about Linux and Linux adjacent things goes. We'll use some of the articles here for the show! You can watch or listen at:

You can also get involved at our forum here on Lemmy:

Or just get the most recent episode of the show here:

founded 2 years ago
MODERATORS