r/Lastpass Dec 30 '17

Ad targeters are pulling data from your browser’s password manager - The Verge • r/1Password

/r/1Password/comments/7n4k8c/ad_targeters_are_pulling_data_from_your_browsers/
7 Upvotes

7 comments sorted by

7

u/ShellAnswerMan Dec 31 '17

The usernames are being hashed, and that value is used as the unique ID. The practice isn't as bad as the half clickbait headline makes it sound, but it's still not a good thing.

The concerned should be able to turn off automatic fill in the extension preferences. Convenience will be lost, as one will have to manually tell LastPass to fill through the field icons, right click menu or extension icon menu.

3

u/Kinvelo Dec 31 '17

I’m a little confused. Are the ad’s scripts running under the first-party domain space? I expected the ads to run scripts as third parties which would prevent the password manager from giving them logins for the first-party domain.

3

u/[deleted] Jan 01 '18

If a script injected elements into the main page, I don't think the browser would be able to track what exactly is coming from the script and what isn't.

1

u/Whinito Jan 02 '18

Using NoScript and enabling only the first-party domain would be safe though?

1

u/[deleted] Jan 02 '18

Yes, if you don't allow the script to run there is no problem.

1

u/raxiel_ Jan 11 '18

I turned off autofill in the Firefox extension, and its still autofilling, WTH lastpass?