How third-party scripts on websites exploit a flaw in browsers' built-in password managers to identify and track users
In this second installment of the No Boundaries series, we show how a long-known vulnerability in browsers' built-in password managers is abused by third-party scripts for tracking on more than a thousand sites.
This is simultaneously very clever and alarming. Let's see how long it takes for every browser & password manager to change their behavior and whether the solution is more elegant than requiring user acknowledgement before auto-filling. http://twitter.com/...
We've seen variants of this password autocomplete stealing bug for years. Do not use “save password” feature of browsers or password managers integrated to the browser. Bugs in domain name parsers, race conditions, injections and attackers have Javascript power to exploit them. h…
Abusing security features to track people without knowledge or consent is my favorite kind of Eldritch creepiness. Here, an invisible login form is auto-filled by your browser's credential manager. The page can then retrieve your email address and use it as a tracking ID. http://…