PaulDotCom mailing list archives

Password manager


From: genesiswave at gmail.com (James Costello)
Date: Wed, 29 Jul 2009 10:26:39 -0500

Thanks for clarifying

On Wed, Jul 29, 2009 at 10:03 AM, Howard Siegel <hsiegel at gmail.com> wrote:

Let me make one point clear...

KeePass does not summarily fill in usernames/passwords just because a
window title that it might recognize pops up in an application.  You must
type type in the command sequence (by default alt-ctrl-A) to wake it up at
which point it looks at the active window's title and if there is a match it
will type in whatever you have programmed it to type (which can be anything
including, or not, a username and password).  It is still you that makes the
decision to tell KeePass to do it's thing, so if you don't recognize the web
site or applciation that is requesting the info, don't tell KeePass to
anything.

The Firefox extension puts the host name in the window title bar to make it
easier to code the auto-type-window information in to KeePass, beacuse a lot
of web sites have generic titles on their login pages, like "Login".  By
using the host name, it makes it easier for KeePass to find the specific
information for that page in it's database once you tell it to do the
lookup.  Again, if you don't recognize the page/host, don't tell KeePass to
do anything.

- h


On Wed, Jul 29, 2009 at 07:54, Howard Siegel <hsiegel at gmail.com> wrote:

Well, no, for two reasons.....

1) I wouldn't even type the "automatic password" trigger key sequence for
your site.

2) The filter I use is " * # mail.google.com # *", which would not match
the window title on your site.  To match your site the filter would have to
be " * # mail.google.com.ihackedu.net # *".

- h


On Wed, Jul 29, 2009 at 04:40, <genesiswave at gmail.com> wrote:

So what happens if I set up mail.google.com.ihackedu.net
Will this pass your creds to me automatically?
Sent via BlackBerry from T-Mobile

-----Original Message-----
From: Howard Siegel <hsiegel at gmail.com>

Date: Tue, 28 Jul 2009 20:31:51
To: PaulDotCom Security Weekly Mailing List<
pauldotcom at mail.pauldotcom.com>
Subject: Re: [Pauldotcom] Password manager


_______________________________________________
 Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com




_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mail.pauldotcom.com/pipermail/pauldotcom/attachments/20090729/d89c5941/attachment.htm 


Current thread: