Collecting everything you type into a web browser (or MS Office) and sending it to them seems like a really bad idea.
Collecting everything you type into a web browser (or MS Office) and sending it to them seems like a really bad idea.
Of course, in the case of Microsoft or Google, you presumably either have disabled the setting or you place your trust in their security practices that it is okay, because they are top tier companies, and most people send them all their private data anyways.
There are a LOT of things out there that collect everything you type these days, and rarely to people want to define them as keyloggers.
When people want privacy they will inevitably have to give up usability. I ditched Swiftkey for an open source Android keyboard that doesn't connect online or asks for any permissions. Its CRAP but it doesn't leak.
It has to work this way or browsers wouldn’t be truly extensible. Be mindful of which extensions you install.
And you only can spare both the time and cognitive load to do this for at most a dozen or two applications, if you really care. The rest, you just have to trust that enough other people are watching carefully.
But the average person isn't going to keep up with even one application. They only bought their computer so they could browse the web and check emails, not so they could learn the details of how it works.
Likewise, most of us don't buy a car in order to spend a lot of time learning about exactly how a combustion engine works. We don't have the time.
Granted, this board is laden with engineers who will make the time to understand how their tools work, but we simply cannot expect this kind of effort from most people.
So, like we have to trust lower-level components to be scrutinized elsewhere, and trust we will be alerted in case of critical issues, the general population must trust the "nerds" to get things right and keep them safe.
This means that typically, the best attack surfaces will be small, widely-distributed, low-level software stacks whose developers can easily be compromised. Not just software either, but hardware.
It does seem like this is ultimately a battle we are going to lose without regulatory legislation in domains that require mass-deployment of software that can potentially breach Constitutional rights. In order to be federally qualified as "privacy-friendly", you have to meet certain guidelines both on a hardware and software level. This would include automatic transmission or collection of certain kinds of data without very express permission.
That sounds an awful lot like "Be careful what email attachments you open." Blaming the user never worked out then either.
I guess android's "partial permission" is the right thing...
https://languagetool.org/ for one supports running your own instance of the server-side portion out-of-the-box. You could run it truly locally assuming your device is appropriate, or your own server which might be more flexible as you can support a greater range of devices and share custom dictionaries between them.
Gives me a "privacy policy", "continue and don't ask again" or "cancel" hyperlink, nothing else. If I want to use it the first time.
But if you open the extension options under the "more tools" > extensions tab you can set the LanguageTool API server URL[0].
Going to try to setup a server over the weekend, thanks.
Yes... But your browser won't detect "spellcheck do can browser your"
Grammar is more than just spelling.
Trying I promise, even different languages. But I'm not a native speaker and a bit dyslexic.
So someone or thing looking over my shoulder would be nice.
It's eye-opening to people when I ask them about an extension they have, say "Honey", and they say they like it because it saves them money. And then I point out it can access everything they do online, and ask them if that's a concern or not.
Chrome team, if they were security-focused, would not permit any closed source extensions which have access to all website data.
People don't seem to understand sometimes that if an extension has this sort of access, you need to be able to trust your browser extensions as much as you trust your browser itself.
I am curious how you manage your passwords.
The notion that it's a good idea to trust a browser extension for secrets management is pretty bizarre to me if you're protecting high value assets.
(Not directed at you personally, but I often hear such comments from people who are then perfectly fine to use a password manager in X11, where in a the default configuration every application can read your keystrokes, screen grabs, clipboard, etc.)
[1] Preferably one that communicates with an out-of-process password manager over an authenticated channel like 1Password.
Beyond that, the "never reuse passwords" adage is horribly oversold. If it handles my money, my email, or my web hosting, it needs to be unique. Passwords for places I comment are commonly reused and not as sophisticated because it is not seriously impactful to me if someone gets a hold of them.
Reuse passwords for sites that can't meaningfully harm you if they get compromised. Minimize how many accounts can harm you by not saving your credit card info in most of them, uncheck that box when you pay for stuff.
I'm also insanely liberal about deploying 2FA. I have it everywhere it's available, even sites with common/stupid passwords. So a lot of sites I don't bother with unique passwords will still be somewhat protected if my password is compromised. I'm also subscribed to haveibeenpwned with every email address I've ever used for anything.
"LastPass encrypts your Vault before it goes to the server using 256-bit AES encryption. Since the Vault is already encrypted before it leaves your computer and reaches the LastPass server, not even LastPass employees can see your sensitive data"
If there is an attack still possible (even using LastPass employees) can you post it here?
https://bugs.chromium.org/p/project-zero/issues/detail?id=88... https://bugs.chromium.org/p/project-zero/issues/detail?id=11... https://bugs.chromium.org/p/project-zero/issues/detail?id=12... https://bugs.chromium.org/p/project-zero/issues/detail?id=12... https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
At a glance what they have in common is flaws in the scripts that the LastPass extension injects into pages. The injected scripts can communicate with the extension core with a set of RPCs. Each of these issues is a way of tricking the extension into running RPCs from untrusted JavaScript on any web page. The RPCs available allow an attacker to fetch the credentials for any site in the database or even execute arbitrary code on the host.
The fix for that was to not use autofill and revert to manually grabbing your username/password when filling out a login form.
Aside from that, I am not aware of other "hot" attack vectors.
Users still need to practice skepticism and ultimately it is their responsibility to protect their passwords. But LastPass has been a very good citizen when it comes to being as secure as possible.
Same as Google/Firefox autocomplete and history, or keyboard spell checker, or email autocomplete and spell checker, etc.
So linux and android are also in the boat of having apps that make your life easier, also need security enforced.
Just wanted to say, its not a Windows only issue, OSX, iphone, android, they are all going to be affected to simular issues.