Hacker News new | past | comments | ask | show | jobs | submit login

Basically you just need to turn off auto-login and auto-fill on all sites, no matter what your password manager is. All of the attacks depended on those two features, from what I could tell from a quick scan of the paper.



Can you do that globally?


I just did. (Using LastPass).


How can you set LastPass to globally disable auto-fill and auto-login? I checked again and I couldn't find any options in the extension or vault settings.


Using the Chrome extension, auto-fill is under Prefereces > General > and auto-login is under Preferences > Advanced.


Thanks.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: