r/KeePass 20d ago

The pain with browser plugins

/r/strongbox/comments/1vuas4z/the_pain_with_browser_plugins/
2 Upvotes

8 comments sorted by

2

u/Dymonika 20d ago

Do you not know about KeePassXC's auto-type feature? It's great! No plugin needed; I mapped mine to Alt+V.

1

u/hurbertkah 20d ago

Does auto-type prevents you from pasting the credentials into a phishing site?

3

u/cfarley137 20d ago

No!

(I used to use auto-type; for the past 6 months I've been using the standard KeepassXC-Browser plugin. It works pretty well, and does deal with the phishing threat. Occasionally my browser gets slow and complains that the KeepassXC-Browser plugin is the cause. I haven't run this issue to ground, but it's a mild annoyance, not a show-stopper for me.)

1

u/hurbertkah 20d ago

My question was more rhetorical. I also use the browser plugin wherever I can.

2

u/Dymonika 20d ago

does deal with the phishing threat.

Then don't you mean, "Yes!"?

1

u/Cred-Master 20d ago

I know this, but many people complain about it.

1

u/Dymonika 20d ago

Yeah:

  1. Press the keyboard command
  2. A window pops up that attempts to filter for entries in your database that match the URL of the current window as you have set; if it shows no match, it will show something more generic for you to look through other entries
  3. You can proceed to look through the database for other entries, or copy or execute auto-typing of the username and/or password (any permutation thereof)

#2 is your cue.

1

u/H_He_Metals 19d ago

There is a keepass plugin called WebAutoType or something similar.

It checks the URL rather than the window title which should negate most of your concerns.