Post #2180163
2026-05-06 12:48 UTC
Replies (2)
-
@suetanvil@freeradical.zone 2026-05-06 12:55
@scott@sfba.social Pshaw! Next thing, you'll be saying they shouldn't have low-level access Bluetooth or USB!
-
@realn2s@infosec.exchange 2026-05-06 13:12
@scott@sfba.social Actually the separation of concerns isn't that clear cut (IMHO) If the browser has access to your password (api or any other way) it's possible to verify that a password is used for a correct URL. Or to state it otherwise, copying or typing passwords makes you prone to fall for fake sites eg mastodon.social vs mastodon.sociaI (The second used a capital 'i' instead of a small 'L'. Which wouldn't work at sociai isn't a proper top level domain but illustrates the point) And a password manager keeping the cleartext passwords in memory wouldn't be much better 😬