Post #2232303
2026-05-06 13:12 UTC
@scott@sfba.social
Actually the separation of concerns isn't that clear cut (IMHO)
If the browser has access to your password (api or any other way) it's possible to verify that a password is used for a correct URL.
Or to state it otherwise, copying or typing passwords makes you prone to fall for fake sites eg mastodon.social vs mastodon.sociaI
(The second used a capital 'i' instead of a small 'L'. Which wouldn't work at sociai isn't a proper top level domain but illustrates the point)
And a password manager keeping the cleartext passwords in memory wouldn't be much better 😬
Replies (0)
No replies.