Protect what matters – even after you're gone. Make a plan for your digital legacy today.
Forum Discussion
Former Member
3 years agoSecurity Issue with Autofill?
Hi Everyone,
i came across an article on https://www.bleepingcomputer.com/ in regards of security issues with Bitwardens Auto-Fill Feature. Now I'm curious if we have a similia issue with 1Passwor...
Former Member
3 years agoHi @hayduk! We do fill iframes, but we check the URLs of the individual frames every step of the way to make sure that the item in question can actually fill. If the login form is in an iframe that has a URL that doesn't match the one in an item, we'll fill nothing at all.
In regards to filling on subdomains, I want the clarify that we consider that working as intended, unless the base domain is on the PSL (public suffix list).
If a hosting provider does this:
Some content hosting providers allow hosting arbitrary content under a subdomain of their official domain, which also serves their login page
They would need to do their due diligence and submit their root domain to the PSL so that we (and also browsers) know to treat subdomains as distinct security contexts. Almost all of the web operates under the assumption that subdomains of a website are "trusted" in some way, unless the domain they're a sub domain of is on the PSL.