Collected research
Password Managers: Attacks and Defenses
A survey of ten browser and third-party password managers finds their autofill policies differ widely, and several fill credentials into pages a network attacker controls. From a rogue router an attacker can inject invisible login forms and iframes and sweep many stored passwords with no user interaction, and hidden autofill fields also leak credit card and personal data.
Record
- Researcher
- David Silver, Suman Jana, Dan Boneh, Eric Chen and Collin Jackson
- Published by
- usenix.org
- Topic
- Other
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of David Silver, Suman Jana, Dan Boneh, Eric Chen and Collin Jackson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .