Other accounts:

@subignition (dead?)
@subignition

  • 6 Posts
  • 1.08K Comments
Joined 3 years ago
cake
Cake day: November 1st, 2023

help-circle
  • I mean, there’s a lot of ways bodies are dirty, but that just means you have to recognize the reasonable limits to cleanliness and learn to deal with what remains. (“shit happens”, after all)

    As someone who struggled a lot with black-and-white thinking when I was younger, I can definitely see how someone could develop some warped views in the absence of decent education / role models.










  • I think I meant to reply to the user who was talking about KeePass. If you have brought the user to a malicious page, you can already just impersonate the login form and something like KeePass that doesn’t offer to autofill passwords will be none the wiser (because the user initiates the paste / autotype)

    In the XSS case, I think this would be occurring on a page the user trusts but has been compromised by an external script (via an ad or other means). If it’s at a domain the user has saved credentials for, odds are high it’s a login page, but I think you’re right that an attacker could probably add their own input field to provoke the password manager overlay, with an innocuous-looking fake captcha or cookie banner over it.