pfn / passifox

Extensions to allow Chrome and Firefox (4.0+) to auto form-fill passwords from KeePass (requires KeePassHttp)
GNU General Public License v3.0
908 stars 186 forks source link

Added popup confirmation option #668

Open vabene1111 opened 6 years ago

vabene1111 commented 6 years ago

Added an option to display a popup inside the browser before the password gets filled in.

Reasons

There have been reported cases of server side bundeling of hidden input fields to trick autofill plugins into filling in userdata. To my knowledge this has mostly been done for ad tracking but could also be used to steal credentials. https://www.theverge.com/2017/12/30/16829804/browser-password-manager-adthink-princeton-research

Note

You could already confirm autofill per entry by clicking inside keepass but you had to leave the browser, this way is more convenient and no less secure if the user already had Keepass on "allow" and "remember decision"

I had some trouble finding the best place for the little code piece, i think it is a good soulution as is right now but if you prefere some other location just let me know.