Hacker News new | ask | show | jobs
by logic 3003 days ago
The hoops a password manager has to jump through to get halfway decent integration into a browser is basically begging for security vulnerabilities. Seriously, just look at how much JavaScript is riding behind webextensions like LastPass, KeePassRPC, Bitwarden, etc. It's staggering.

I dont have any interest in using Lockbox; I already have a self-hosted open-source password management solution (Bitwarden, in my case, but that's just an implementation detail) that works for much more than just my web browser, which means I'm way more interested in hearing how Mozilla plans to make this kind of integration smoother and less error-prone.

I need to sync passwords for apps on my phone, for desktop apps that aren't web browsers (and for multiple browsers on several platforms), and Mozilla's one-off reinvention of existing software and protocols for their singular use cases is just xkcd'ing the problem, sadly.