Elektrine lite

← Feed

@realn2s@infosec.exchange

Post #2232303

2026-05-06 13:12 UTC

@scott@sfba.social Actually the separation of concerns isn't that clear cut (IMHO) If the browser has access to your password (api or any other way) it's possible to verify that a password is used for a correct URL. Or to state it otherwise, copying or typing passwords makes you prone to fall for fake sites eg mastodon.social vs mastodon.sociaI (The second used a capital 'i' instead of a small 'L'. Which wouldn't work at sociai isn't a proper top level domain but illustrates the point) And a password manager keeping the cleartext passwords in memory wouldn't be much better 😬

Replies (0)

No replies.