array-io-keychain icon indicating copy to clipboard operation
array-io-keychain copied to clipboard

Fake password entry window problem

Open roman-modelist-dev opened this issue 6 years ago • 0 comments

Attacker can grab pass secret by displaying fake password entry window for user. User will pass secret to the fake window and attacker will can to grab secret.

We need to implement protection mechanism like alt+ctrl+del in windows OS. User must enter specific keyboard shortcut, that attacker can not capture. If attacker will try to print fake pass entry window user will press a key combination. Our service will capture this keyboard shortcut, kill fake pass entry window and display truly pass entry window.

We must to figure out how to implement this protection mechanism on Windows, Linux and MacOS.

roman-modelist-dev avatar Jun 22 '18 15:06 roman-modelist-dev