1Password 和 官方 Chrome 扩展之间明文传输敏感信息 - 鸠占鹊巢 - 知乎专栏



1Password 和 官方 Chrome 扩展之间明文传输敏感信息 - 鸠占鹊巢 - 知乎专栏

根据 medium 上的一篇文章:1Password sends your password across the loopback interface in clear text,1Password 和 官方的 Chrome 插件之间依靠 loopback 明文传输敏感信息,账户,密码,信用卡号等等。

同样基于上述文章,我们可以通过如下流程验证:

系统:Mac,1Password 6.0.2 浏览器:Chrome 48.0.2564.116,最新的 1Password Chrome 扩展。

第一步,卸载 chrome 扩展,然后在 shell 中启动命令抓取 loopback 数据:

sudo tcpdump -i lo0 -s 65535 -w info.cap 

第二步,打开 chrome,重装官方扩展,然后打开,会有一个调起 1Password 应用的授权过程。授权之后,随便打开你在 1Password 中存储了密码的网站,笔者这里以 dnspod 示例。打开之后,点击 Chrome 扩展,查询该网站密码并自动填充进行登录。

第三步:停掉第一步启动的抓取命令。然后查看下 info.cap 这个文件内容,明文密码一目了然。


Read full article from 1Password 和 官方 Chrome 扩展之间明文传输敏感信息 - 鸠占鹊巢 - 知乎专栏


No comments:

Post a Comment

Labels

Algorithm (219) Lucene (130) LeetCode (97) Database (36) Data Structure (33) text mining (28) Solr (27) java (27) Mathematical Algorithm (26) Difficult Algorithm (25) Logic Thinking (23) Puzzles (23) Bit Algorithms (22) Math (21) List (20) Dynamic Programming (19) Linux (19) Tree (18) Machine Learning (15) EPI (11) Queue (11) Smart Algorithm (11) Operating System (9) Java Basic (8) Recursive Algorithm (8) Stack (8) Eclipse (7) Scala (7) Tika (7) J2EE (6) Monitoring (6) Trie (6) Concurrency (5) Geometry Algorithm (5) Greedy Algorithm (5) Mahout (5) MySQL (5) xpost (5) C (4) Interview (4) Vi (4) regular expression (4) to-do (4) C++ (3) Chrome (3) Divide and Conquer (3) Graph Algorithm (3) Permutation (3) Powershell (3) Random (3) Segment Tree (3) UIMA (3) Union-Find (3) Video (3) Virtualization (3) Windows (3) XML (3) Advanced Data Structure (2) Android (2) Bash (2) Classic Algorithm (2) Debugging (2) Design Pattern (2) Google (2) Hadoop (2) Java Collections (2) Markov Chains (2) Probabilities (2) Shell (2) Site (2) Web Development (2) Workplace (2) angularjs (2) .Net (1) Amazon Interview (1) Android Studio (1) Array (1) Boilerpipe (1) Book Notes (1) ChromeOS (1) Chromebook (1) Codility (1) Desgin (1) Design (1) Divide and Conqure (1) GAE (1) Google Interview (1) Great Stuff (1) Hash (1) High Tech Companies (1) Improving (1) LifeTips (1) Maven (1) Network (1) Performance (1) Programming (1) Resources (1) Sampling (1) Sed (1) Smart Thinking (1) Sort (1) Spark (1) Stanford NLP (1) System Design (1) Trove (1) VIP (1) tools (1)

Popular Posts