Computer and Browser Security Issues with Pass Mac/Windows App autofill
I was concerned about using the browser extension because of the prevalence of browser based credential stealing malware. If a browser got infected with this type of malware there is a chance the Pass browser extension could be accessed by a hacker.
I asked tech support if this was technically possible and did not get any technical response only a legal response that the security of my computer is my responsibility. This made me think that it probably was possible.
I requested that there be an actual Mac/Windows application. An application would still be vulnerable to hacking based on security flaws and the possibility of OS based malware. It seems to be more secure than the browser where the chance of infection is higher.
Standalone apps have been released and it is an improvement. The standalone app will not do any browser form filling or even a search of the Pass database.
Lastpass has a standalone Mac app that does do form filling. I'm not sure what technology they use to communicate with the browser. It may not be more secure than a browser extension. If it is more secure, it would be nice if the Pass standalone apps could do form filling.
There is more on browser credential stealing here:
https://attack.mitre.org/techniques/T1555/003/
https://www.techspot.com/news/97951-bitwarden-password-manager-browser-extension-has-known-exploit.html
https://www.tomsguide.com/computing/malware-adware/malware-filled-extensions-are-a-chrome-threat-you-cant-ignore-reportedly-installed-by-280-million-over-the-last-three-years
https://www.bankinfosecurity.com/alert-info-stealers-target-stored-browser-credentials-a-24490
https://www.tomsguide.com/news/millions-under-threat-from-malicious-browser-extensions-what-to-do
-
Greg__ commented
I agree, the Mac OS app is kind useless at this point since it doesn't communicate with system password and autofill. We are required to have the browser extension to do that.
This solution is a more secure and OS integrated way of doing.