▲ | behindsight 4 days ago | ||||||||||||||||||||||
> I always have to manually copy/paste the credentials. I really hope you clear your clipboard history entirely after doing your copy/paste method because your credentials would otherwise persist for any other application with clipboard perms to just exfiltrate (which has already been exploited in the wild before) | |||||||||||||||||||||||
▲ | mtlynch 4 days ago | parent [-] | ||||||||||||||||||||||
>I really hope you clear your clipboard history entirely after doing your copy/paste method because your credentials would otherwise persist for any other application with clipboard perms to just exfiltrate (which has already been exploited in the wild before) How does that work? If a malicious website reads the clipboard, what good is knowing an arbitrary password with no other information? If the user is using a password manager, presumably they don't reuse passwords, so the malicious website would have to guess the matching username + URL where the password applies. If you're talking about a malicious desktop app running on the same system, it's game over anyway because it can read process memory, read keystrokes, etc. Sidenote: Most password managers I've used automatically clear the clipboard 10-15s after you copy a credential. | |||||||||||||||||||||||
|