Elektrine lite

← Feed

@scott@sfba.social

Post #2180163

2026-05-06 12:48 UTC

RE: https://mastodon.social/@xabd/116527370557548161 Call me crazy, but maybe browsers should *never* have access to your passwords. Separation of concerns, etc. (Not an #InfoSec person, but this seems like just one of 1M things that could easily go haywire.)

Replies (2)

  • @suetanvil@freeradical.zone 2026-05-06 12:55

    @scott@sfba.social Pshaw! Next thing, you'll be saying they shouldn't have low-level access Bluetooth or USB!

    Open ##2232301

  • @realn2s@infosec.exchange 2026-05-06 13:12

    @scott@sfba.social Actually the separation of concerns isn't that clear cut (IMHO) If the browser has access to your password (api or any other way) it's possible to verify that a password is used for a correct URL. Or to state it otherwise, copying or typing passwords makes you prone to fall for fake sites eg mastodon.social vs mastodon.sociaI (The second used a capital 'i' instead of a small 'L'. Which wouldn't work at sociai isn't a proper top level domain but illustrates the point) And a password manager keeping the cleartext passwords in memory wouldn't be much better 😬

    Open ##2232303