3 ms·
Hey guys, thanks for all the comments. I'll try to address them before I am going to bed. How I use instapass.io is sending an email/slack/telegram/etc. with t
by pinehqcom 7y ago
Hey guys, thanks for all the comments. I'll try to address them before I am going to bed.
How I use instapass.io is sending an email/slack/telegram/etc. with the password in instapass. This way your password isn't stored on a email/slack/etc.. server in clear text forever. It also makes it possible to see if an attacker opened the password and take appropriate action.
There is a slim risk of an MIIM where you edit the link super fast and have control over messaging service. This is exactly what @johnmarcus wrote.
If you don't trust my service then you can just keep the password in Instapass and the other login info (url to login, email, username, etc..) inside the email.
How should I know what you sent a password to?
I think that's a better choice than sending login info in clear text.