3 ms·
But this is irrelevant if you use a password manager.
by ghughes 4y ago
But this is irrelevant if you use a password manager.
- potatoz2 4y agoNot entirely. If I MITM your connection to a website that uses a password, I have access until the breach is detected. If I MITM a public/private key log in, I only have access to the session (which can be made arbitrarily short if logging in is painless/automatic).
- ghughes 4y agoBut you can't, because TLS.
- tinus_hn 4y agoNo, because if the server gets hacked and the attacker can intercept your password, your password manager is managing a password that is, unbeknownst to it, known to an attacker. Who can now use that password to just login to the service.