You are here

Is Password Manager safe

3 posts / 0 new
Last post
tinku99
Offline
Last seen: 17 years 4 months ago
Joined: 2006-12-14 01:30
Is Password Manager safe

Is Password Manager safe on portable firefox 2.0

http://it.slashdot.org/article.pl?sid=06/11/21/2319243&from=rss

for that matter, was it safe on 1.5?

John T. Haller
John T. Haller's picture
Offline
Last seen: 5 hours 53 min ago
AdminDeveloperModeratorTranslator
Joined: 2005-11-28 22:21
Everything

Every copy of Firefox in existence is vulnerable to this. Other browsers are to a certain extent, too, but in different ways. Keep in mind that this only applies when a hostile page that makes use of forms and javascript is hosted on the same domain as a non-hostile page where you'd enter your username and password to log in (and have saved said username and login). And even then, they could only get access to your password for that particular site.

A website which allows users to post anything they'd like unchecked is actually a huge security risk in and of itself. Allowing users to post hostile forms and javascript is just insanely dumb... but that's what some sites like MySpace are doing. That's why there are multiple attacks on MySpace right now... including one that runs JavaScript within Quicktime movies to spread nasty links in MySpace profiles.

In essence, this is thanks to poor security (make that a complete lack of security) at MySpace. Your best off not letting your browser remember your password for sites like that. Mozilla will make a fix, of course. Just like Apple is being forced to... to clean up MySpace's mess for them.

Sometimes, the impossible can become possible, if you're awesome!

tinku99
Offline
Last seen: 17 years 4 months ago
Joined: 2006-12-14 01:30
ok

Thanks for the thoughtful reply.
I felt the same, but wanted some reassurance.
I guess dumb people have had fire to play with, now they have the internet with myspace.

Topic locked