4 ms·
Good mitigation of that would be for a password manager to store an url along with password.
by marbu 5y ago
Good mitigation of that would be for a password manager to store an url along with password.
- K5EiS 5y agoThat is usually what password managers do.
- Biganon 5y agoParent comment was precisely using this as a pro for in-browser password managers (or extensions). They can check the current domain. A standalone desktop app can't do that (well it can, but it's a bit more complicated to truly understand what tab you're currently looking at, and intend to use a password with)
- marbu 5y agoTo clarify: I suggested to store url in the password manager so that when I want to login somewhere, I go the the manager, locate the account, copy paste url stored there into url bar of the browser in a new tab, and then do the same with actual credentials. There is no room for any phishing in such case. That said I understand that when a password manager is closely integrated with (or even within) a browser, it can do more checking for me, and make the whole experience nicer. But such integration is imho not a silver bullet, and there are downsides which comes with this approach as well.