Person authenticating login credentials using biometric fingerprint scan on a laptop.

Password Manager Security: Risks and Protection Guide

Date Posted:

Category:

Security

Author:

Nachimuthu

Person authenticating login credentials using biometric fingerprint scan on a laptop.

Password Manager Security: Risks and Protection Guide

Date Posted:

Category:

Security

Author:

Nachimuthu

Person authenticating login credentials using biometric fingerprint scan on a laptop.

Password Manager Security: Risks and Protection Guide

Date Posted:

Category:

Security

Author:

Nachimuthu

Get your Tailored Quote for your Organisation

Get your Tailored Quote for your Organisation

Get your Tailored Quote for your Organisation

When Your Password Manager Isn’t as Safe as You Think

Password managers are really important for keeping our computers and information safe these days. They help us by storing our passwords in a place, making strong and unique passwords and filling them when we need to log in to websites. This makes it easy for us without having to remember all of them (passwords).

For companies password managers are a key part of keeping their information safe by reducing the risk of using the same password for multiple things, making sure passwords are strong and making it easy to access online platforms.

But if you treat your password manager like an unhackable digital citadel, it’s time for a reality check. That fortress currently has a massive, invisible back door and that’s what this post is about.

We should not think that password managers are completely safe from hacking.

At DEF CON 33 a researcher named Marek Tóth showed that even the best password managers can be hacked using a trick called clickjacking. He found out that hackers can use HTML codes and tricks to make browser extensions fill in our passwords without us even seeing it which means our login information can be stolen without us knowing.

How the attack works

The exploit is well-designed,

  • The attacker overlays intrusive web elements on top of legitimate web pages. Cookie consent banners, news popup and captcha page are few examples.

  • When you click what looks like a normal button or field, the password manager extension fills your credentials into an invisible field behind the visible elements.

  • The attack can even be adaptive: some variants detect which password manager you’re using in real time and adapt the payload to match it.

  • Certain attacks go further by forcing the UI to follow your mouse cursor, so any click on the page can trigger a data leak.

This turns your own security tools against you, enabling what you might call “stealth mode identity theft”, targeting everything from 1Password to Apple Passwords.

What you can do right now

The “nuclear” option: disable autofill

  • Disable autofill and manually copy‑paste passwords instead.

  • This cuts off the clickjacking element, since there’s no automatic form‑filling to exploit.

That said, disabling autofill works, but also turns your password manager into a glorified digital notes page. It’s secure, but it defeats the purpose.

The real MVP: Passkeys

Where available, Passkeys are the MVP of modern password security. They’re fundamentally resistant to this kind of clickjacking because they require a hardware‑level cryptographic signature (often assisted by a device like a phone, security key, or biometric authentication).

If a site offers a Passkey login, use it - it’s currently the safest option.

For businesses: use SSO

For enterprises, Single Sign‑On (SSO) gives more control over this kind of attack.

  • It centralizes identity at the platform level.

  • It removes the browser extension as a single point of failure for password‑manager‑based attacks.

With strong MFA setup and conditional access policies, SSO can reduce the risk of credentials leak by a vulnerable browser or an extension.

So, what can be done to keep our passwords safe?

  • We should always keep our browser and extensions up to date so that hackers cannot use tricks to get to our information.

  • We should use password managers that're well known and safe and avoid using ones that are not popular or well maintained.

  • We should check what permissions our browser extensions have and turn off any that we do not need to use.

Password managers like these are important, for our safety so we should take care of them by following these steps and using password managers safely.

Conclusion

Your password manager is still a powerful tool, but it’s not invincible. Clickjacking attacks like the ones mentioned above remind us that no single layer of security should ever be treated as “unhackable.”

If you’re serious about identity security:

  • Choose Passkeys where supported.

  • Use SSO for businesses.

  • Keep the application/extension updated and browser clean.


Stay tuned to our blog to see more posts about

Sailpoint products implementation and its related updates.

Stay tuned to our blog to see more posts about SailPoint products implementation and its related updates.

Category:

Category:

Security

Security

When Your Password Manager Isn’t as Safe as You Think

Password managers are really important for keeping our computers and information safe these days. They help us by storing our passwords in a place, making strong and unique passwords and filling them when we need to log in to websites. This makes it easy for us without having to remember all of them (passwords).

For companies password managers are a key part of keeping their information safe by reducing the risk of using the same password for multiple things, making sure passwords are strong and making it easy to access online platforms.

But if you treat your password manager like an unhackable digital citadel, it’s time for a reality check. That fortress currently has a massive, invisible back door and that’s what this post is about.

We should not think that password managers are completely safe from hacking.

At DEF CON 33 a researcher named Marek Tóth showed that even the best password managers can be hacked using a trick called clickjacking. He found out that hackers can use HTML codes and tricks to make browser extensions fill in our passwords without us even seeing it which means our login information can be stolen without us knowing.

How the attack works

The exploit is well-designed,

  • The attacker overlays intrusive web elements on top of legitimate web pages. Cookie consent banners, news popup and captcha page are few examples.

  • When you click what looks like a normal button or field, the password manager extension fills your credentials into an invisible field behind the visible elements.

  • The attack can even be adaptive: some variants detect which password manager you’re using in real time and adapt the payload to match it.

  • Certain attacks go further by forcing the UI to follow your mouse cursor, so any click on the page can trigger a data leak.

This turns your own security tools against you, enabling what you might call “stealth mode identity theft”, targeting everything from 1Password to Apple Passwords.

What you can do right now

The “nuclear” option: disable autofill

  • Disable autofill and manually copy‑paste passwords instead.

  • This cuts off the clickjacking element, since there’s no automatic form‑filling to exploit.

That said, disabling autofill works, but also turns your password manager into a glorified digital notes page. It’s secure, but it defeats the purpose.

The real MVP: Passkeys

Where available, Passkeys are the MVP of modern password security. They’re fundamentally resistant to this kind of clickjacking because they require a hardware‑level cryptographic signature (often assisted by a device like a phone, security key, or biometric authentication).

If a site offers a Passkey login, use it - it’s currently the safest option.

For businesses: use SSO

For enterprises, Single Sign‑On (SSO) gives more control over this kind of attack.

  • It centralizes identity at the platform level.

  • It removes the browser extension as a single point of failure for password‑manager‑based attacks.

With strong MFA setup and conditional access policies, SSO can reduce the risk of credentials leak by a vulnerable browser or an extension.

So, what can be done to keep our passwords safe?

  • We should always keep our browser and extensions up to date so that hackers cannot use tricks to get to our information.

  • We should use password managers that're well known and safe and avoid using ones that are not popular or well maintained.

  • We should check what permissions our browser extensions have and turn off any that we do not need to use.

Password managers like these are important, for our safety so we should take care of them by following these steps and using password managers safely.

Conclusion

Your password manager is still a powerful tool, but it’s not invincible. Clickjacking attacks like the ones mentioned above remind us that no single layer of security should ever be treated as “unhackable.”

If you’re serious about identity security:

  • Choose Passkeys where supported.

  • Use SSO for businesses.

  • Keep the application/extension updated and browser clean.


Stay tuned to our blog to see more posts about

Sailpoint products implementation and its related updates.

Category:

Security