Hacker News new | past | comments | ask | show | jobs | submit login

I use bitwarden, but on rare occasions when i need type passwd, I always type the wrong password first time just to be safe. I have always had this fear of spoofing which now looks very real.



Pretty easy to just proxy the password through to the real service, and see if it fails or not before adding it to your pwn DB.


If you're worried about this attack in particular, then drag the window above the line of death.

https://textslashplain.com/2017/01/14/the-line-of-death/

Now, if you got put into fullscreen mode without realizing it, that's another problem.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: