Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Android app vulnerable to clipboard hijacking #6

Open
vijayp opened this issue Jul 31, 2014 · 9 comments
Open

Android app vulnerable to clipboard hijacking #6

vijayp opened this issue Jul 31, 2014 · 9 comments

Comments

@vijayp
Copy link
Collaborator

vijayp commented Jul 31, 2014

This application is vulnerable to clipboard hijacking when using clipboard for copying http://fc13.ifca.ai/proc/4-2.pdf

@michaelbarlow7
Copy link

Has there been any work done on the proposed "USecPassBoard" ? Or is it just a theoretical solution at the moment?

@evanj
Copy link
Collaborator

evanj commented Aug 3, 2014

Certainly there isn't any work that has been done as part of Mitro.

@emilecantin
Copy link

Keepass2Android implements a keyboard, and is open-source. Might be worth a look:

https://keepass2android.codeplex.com/SourceControl/latest#src/KP2AKeyboard/

@luckyagarwal3247
Copy link

Hi,

I am working on solutions to the clipboard vulnerability as part of my masters thesis, currently in the process of designing my own variant of USecPassBoard.

Can anybody point me to helpful resources and/or research done in this domain.

Thanks

@emilecantin
Copy link

As I said, look at Keepass2Android.

@forteller
Copy link

How is the progress on this? Thanks!

@vijayp
Copy link
Collaborator Author

vijayp commented Nov 3, 2014

@forteller From what I can tell, no one is actively working on this. Please feel free to submit a pull request and someone will review!

@forteller
Copy link

Unfortunately I'm no coder. But EFF said they where working on fixing this. Disappointing if they've abandoned it. https://www.eff.org/deeplinks/2014/07/mitro-a-new-free-password-manager

@evanj
Copy link
Collaborator

evanj commented Nov 4, 2014

Well, if you read the EFF's blog post, they never say they are going to be contributing or working on it. I don't work for or speak for the EFF, but they do believe that having a free, open source, trusted and reviewed password manager would be good for user's privacy and security. Hence, when we open sourced it, they helped us promote that, in the hopes that it might become a self-sustaining project.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants