
Ich denke, dass sich die Krypto -Community auch dessen bewusst sein sollte und eine offizielle Aussagen von den wichtigsten Krypto -Brieftaschenentwicklern erhalten sollte.
Zitat aus dem Artikel für Sicherheitsforscher:
Die beschriebene Technik ist allgemein und ich habe sie nur auf 11 Passwortmanagern getestet. Andere DOM-Manipulations-Erweiterungen sind wahrscheinlich anfällig (Kennwortmanager, Krypto-Brieftaschen, Notizen usw.).
Metamask wird auch erwähnt:
In der Vergangenheit (2022)die Metamask -Kryptowährungsbrieftasche beispielsweise hatte die gleiche Anfälligkeit (QuelleAnwesend Quelle2).
Auf jeden Fall eine gute Erinnerung für alle:
2FA sollte streng von Anmeldeinformationen getrennt sein – wenn alles an einem Ort gespeichert wird, kann der Angreifer gefährdete Kennwortmanager ausnutzen und auch mit 2FA -aktivierter Zugriff auf das Konto erhalten.
Weitere Details finden Sie in den Kommentaren des ursprünglichen Threads.
https://marektoth.com/blog/dom-based-extension-clickjacking/
7 Kommentare
Ugh. The mainstream is not ready for crypto. All it takes is getting hacked 1 time to turn someone into an anti-crypto person.
tldr; A new security vulnerability called DOM-based Extension Clickjacking has been discovered, targeting browser extensions like password managers. This technique manipulates UI elements injected into the DOM, making them invisible and tricking users into unknowingly sharing sensitive data such as credit card details, login credentials, and personal information. The research tested 11 password managers, revealing vulnerabilities in all of them, potentially affecting tens of millions of users. Mitigation includes configuring site access to ‚on click‘ and limiting web-accessible resources in extensions.
*This summary is auto generated by a bot and not meant to replace reading the original article. As always, DYOR.
wild when a zero day hack is discovered
[removed]
[removed]
Anyone who uses a password manager is just plain stupid…It will always get breached eventually
A year or two ago, I created a new browser profile for using metamask wallet and dapps. That profile only have dexes windows open and no other extensions installed. I open that profile, do my crypto shit, then close it up.
My normal browsing happens on another profile. Media related browsing is on another browser altogether.
Also, most of my stash is in hardware wallet that I only use to send and receive coins. And CEX accounts uses a separate email from my main email, which is also different from my social media email.
Anything else I should do or not do to keep safe?