|
|
|
|
|
by kijin
669 days ago
|
|
Password managers are phishing resistant. The browser plugin will not offer to autocomplete passwords on an identical-looking punycode domain. A sufficiently long, randomly generated password is also database-leak resistant. Good luck brute-forcing a 128-bit random string, hashed with scrypt or whatever. So the only significant advantage is replay resistance. Which might or might not be a big deal, but let's not overplay the advantages. |
|
True … but the reaction to this by the vast majority of users is to go "stupid password manager autofill not working again", and copy and paste their password out of the pw manager and paste it straight into the phishing site…