|
|
|
|
|
by pwg
2793 days ago
|
|
>but it can also prevent a (compromised) server from seeing your password If the server is compromised, then there is no protection of your cleartext password at all. This is because the entity that compromised the server can replace the original JS with anything, including new JS that sends your cleartext password off to their own host as you type each character. The only activity on your part that can save you against comprimised servers is having a unique password per server (i.e., not reusing any passwords). |
|