I remember when KeePass browser plugin had the same issue. The security researchers were not paid.
I remember when KeePass browser plugin had the same issue. The security researchers were not paid.
Several browser plug-ins are available as well as simpler solutions like a browser extension to insert the URL in the title bar and sending keystrokes to the browser to populate it.
The answer is right there in the article: Use the browser's password manager.
I find Firefox's password manager + Sync a good solution, and I don't understand why people don't advocate it more. It's free and open source. Mozilla is a reputable software house with a good security team. Their revenue stream does not depend on you paying for the password manager. It doesn't even depends on monetizing your personal information.
Yesterday I found it even works as a password store for all of iOS.
It works just like another password app.
Or only bad vulnerabilities triggered using JavaScript? Or would you only accept a history with vulnerabilities if security researchers were paid properly for the work they invested into finding the issues?
I have much more confidence in open source password storage that doesnt try to autofill. Theres much less that can go wrong. This is how I store banking passwords.
A serious vulnerability puts me off but not as much as a tepid ass response that tries to downplay the severity of a really bad problem.
That makes me consider the software radioactive.
The fact remains that autofilling passwords in-browser has a gargantuan attack surface and hence the potential to go very wrong. You have to really trust whichever software you use for this.
I expected better from lastpass because I used to give them actual money. I'm not upset that some random keepass extension did this but I also wouldnt use it either.