What prevents a random npm/rubygems/... dependency from running `pbcopy` every second, storing interesting-looking results and relaying them to some server once in a while?
What prevents a random npm/rubygems/... dependency from running `pbcopy` every second, storing interesting-looking results and relaying them to some server once in a while?
Presumably, running `pbcopy` is easier and less detectable than writing a keylogger?
This isn't essential to the operation of a password manager and sensible password managers don't do this.
Say a password manager wants to let me know that my password for Gmail is d78658b8f207c4256370d3e018e0f3d544607849aa5f6bd8, what should it do then?
It seems to me, either the manager or me will copy that value to the clipboard somehow.
I think most 'hacker-friendly' password managers (like password-store), that are unix-y, can be persisted to git, don't depend on megacorps, etc lack these capabilities?
i.e. very few password managers might count as 'decent'.
As a last note, a browser extension that doesn't come from Google or Apple shouldn't be trusted. I have zero extensions (other than uBlock), since they essentially have arbitary read/write capabilites into one's digital life.
What's really missing is a OS-level widget that acts as a secure clipboard. Similar to how one inserts emojis in macOS.
I think this is true - this is really core browser functionality and all password managers are fundamentally hacks. A tiny number of these hacks are non-awful. 'hacker-friendly' password management is a bit like 'hacker-friendly' dentistry - useful to a tiny minority of exceptionally adventurous people.
The safest, sanest thing you can do is use the browser-provided password manager and the browser- or OS- provided sync. Both Safari's and Chrome's use end-to-end encryption (you have to turn it on in Chrome but it's there). The benefits of this far outweigh the downsides, to the point where I actually think the typical recommendation for 1Password is a bit outdated and counter-productive. Browser and platform vendors should obviate the need for this entire class of software and they seem to be moving in that direction.
I have no idea why you feel proprietary goop from Apple is trustworthy while code I can read for myself is not.
Personally I have auto-fill configured. Since I fixed (in my copy and since the PR was accepted eventually everyone's) the lack of any suffix matching beyond TLDs I feel auto-fill security implications are tolerable, I'm sure views vary. But I definitely couldn't put up with manual copy & paste.
I'll start looking into https://github.com/browserpass/browserpass/ .
[0] https://docs.microsoft.com/en-us/windows/desktop/dataxchg/us...