1Password seems to be just fine according to this paper. It did not fuck up like Lastpass and only live flaw is about subdomain matching, which I actually find useful.
1Password seems to be just fine according to this paper. It did not fuck up like Lastpass and only live flaw is about subdomain matching, which I actually find useful.
LastPass has me enter the master password in a pop up window when I click on the icon from the extension (firefox/chrome), although I suppose that's maybe not as good as an independent application?
I can, not only disable autofill in the Lastpass configuration, but also set to require password reprompt for any of my credentials. I could also individually disable autofill for any credential.
Please should first know how something works before criticizing.
In 1Password 4, there is no auto-filling. People can use Ctrl-\ or Cmd-\ to tell 1Password to "fill this page". In versions prior to 4, auto-fill was an option. (I'm not sure which versions had what defaults.)
A lot of my other accounts can be more easily hacked, but relatively little harm would be done if they were. I think one of my MMO accounts -- to a game I no longer play -- actually was.
But tumbler allows JavaScript redirects to phishing sites, so yahoo standard I guess.
If a form doesn't have a submit action, what's the point of the form?
If you have HTML and CSS, why not have forms?
"send it to your yahoo mail and LastPass would fill it up and submit because it's served under yahoo domain."
I am actually a LP user, but I would prefer it was more secure by default.