Episode #1040 Quiz
Clickjacking "Whac-A-Mole"
Date: 2025-08-26 | Length: 2.25 hrs | Episode page at twit.tv
About this episode
This episode analyzed a recent DEFCON 33 revelation of DOM-based clickjacking vulnerabilities in browser extensions for password managers like 1Password and Bitwarden, demonstrating how malicious sites trick users into autofilling sensitive data via hidden overlays. Despite patches, complete mitigation remains elusive due to usability-security trade-offs, underscoring inherent risks in browser-based autofill amid complex web interactions.
Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.