Skip to content
View in the app

A better way to browse. Learn more.

Enpass Discussion Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Password Managers: Potential Threats

Featured Replies

I recently came across this article: Password managers: attacks and defenses -- FEBRUARY 6, 2017 found here: https://blog.acolyer.org/2017/02/06/password-managers-attacks-and-defenses/.

It describes common password attacks on password managers, mostly surrounding "autofill."  For example, "The evil coffee shop attacker," "Sweep attacks," "Injection," and so forth.  It lists several password managers like the big browsers (Chrome, Safari, etc.), Lastpass, 1Password, etc. It does not mention enpass.

I would like to know if these types of autofill security concerns have been investigated and addressed in enpass.

Thank you.

I am just starting to use Enpass but from the article and 1password comments, I think that if you disable autosubmit login that would prevent sweep attacks.

Hi All, 

I would like to share that Enpass is not affected by any of these attacks because Enpass never autofills in a website without your manual input to do so.

This is what happens when your try to autofill using Enpass:

  • When a page loads: Enpass does not execute (only attaches) its script when a webpage is loaded except in the case when URL is launched from Enpass app itself.
     
  • Once the page is loaded: You need to click on extension icon or press the shortcut key for which Enpass will show you the list of items for matching hostname/domain.
     
  • Autofilling:  Enpass fills only for selected entry and auto-submits if auto-submission is enabled. In case, you have a single matching item for that domain and the shortcut key is pressed, Enpass fills that item without showing the chooser window but again it was you who auto filled by shortcut.

Hope this helps!

Guest
This topic is now closed to further replies.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.