Smashing Security

Oops! I auto-filled my password into a cookie banner

Aug 27, 2025
Thom Langford, a security expert and host of Host Unknown, joins to discuss crucial cybersecurity topics. They reveal how certain password managers can be manipulated in clickjacking attacks, urging users to tighten their defenses. The conversation shifts to the looming threat of quantum computing, with Microsoft's commitment to quantum safety by 2033. Thom also shares laughs about tech failures, warns about shady URL tools, and reminisces on the iconic design of the iMac G4 while exploring ways to breathe new life into vintage tech.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Use A Password Manager

  • Use a password manager to store strong, unique passwords instead of reusing one memorable password everywhere.
  • Password managers reduce phishing risk by not offering autofill on wrong domains when configured correctly.
INSIGHT

Autofill Can Be Clickjacked

  • Browser password-manager autofill can be abused via invisible iframes and clickjacking on top of fake pop-ups.
  • Attackers can trap clicks on visible elements and cause the manager to fill hidden forms the user never sees.
ADVICE

Require Manual Confirmation For Autofill

  • Require biometric or master-password confirmation before autofill to add a human verification step.
  • Configure your password manager to require explicit approval rather than silent automatic fills.
Get the Snipd Podcast app to discover more snips from this episode
Get the app