Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Moolticute extension confused by manual 2FA/PIN requests - password overwritten on Mooltipass #140

Open
ghalfacree opened this issue Jul 22, 2022 · 0 comments

Comments

@ghalfacree
Copy link

ghalfacree commented Jul 22, 2022

The Moolticute Firefox browser extension, and likely others, gets very confused with sites that request a manual 2FA code entry - like a number sent via SMS, or generated by a TOTP dongle, or a memorised PIN - on an interstitial page after a user/pass login.

Expected behavior

Log in to a site with Moolticute, get prompted for 2FA code, manually enter 2FA code, proceed as normal.

Actual behavior

Log in to a site with Moolticute, get prompted for 2FA code, Moolticute auto-fills the prompt with the saved password, you overwrite that with the actual 2FA code, Moolticute prompts to "update data" - and if you accept, overwrites the password on the Mooltipass with the 2FA code.

Step by step guide to reproduce the problem

  1. Find site with manual 2FA (I've just encountered the problem with the Scottish Widows internet banking site in the UK, where I can't now log in because my password has been overwritten by three digits of 2FA code...)
  2. Log in as normal.
  3. Watch Moolticute incorrectly auto-fill.
  4. Override it.
  5. Get prompted to "update data".

Further notes

I've been either manually rejecting the "update data" prompt or allowing it to time out, but despite that my password has still been overwritten. I can't completely rule out accidentally accepting it last time I logged in, but I'm about 99 per cent sure I didn't - so I'm not sure why my password's been nuked!

Moolticute Version

v0.55.12-testing

Operating System

Ubuntu 20.04

Mooltipass Extension

Firefox

Mooltipass Device

Mooltipass Mini BLE

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant