Bitwarden flaw can let hackers steal passwords using iframes
bleepingcomputer.com
bleepingcomputer.com
An allowlist of domains where iframe autofill is allowed, pre-populated with some vetted examples like apple/icloud mentioned in the article?
At what point do user options trump accessibility? I tell my parents to use Bitwarden because it's more secure than their alternative (plaintext in Google Doc) but they have no idea what an iframe is or how to spot one. If I taught them they'd never remember because it something so seldom used. Password managers are written for an audience much larger than us. Such an option as suggested would be useless to them.
Maybe Bitwarden made the right choice here?
- odds of arbitrary malicious iframe being on login page seems vanishingly small, especially when a compromise of the login page is probably necessary before the iframe can be injected. How often can an iframe be injected but not arbitrary js?
- iframes having autofill should definitely be a sub option on such a feature.
Either way, also curious about other password managers and their behaviors here. TFA doesn't go into that, seems like a big omission.
It's pretty common to inject credit card skimmers into checkout pages - why would login pages be any different?
e.g. if I have access to inject an iframe, can't I just inject some javascript which will post the credentials to another server?
If I have access to inject an iframe, can't I just modify the server code to just post the credentials to me?
Having an ad on the login page is not universal, but neither is it uncommon, and some websites just have a login form on every page.