3 ms·
Fair skepticism - I'd be suspicious too. Two clarifications: 1. We don't ask for your current passwords. The app imports your CSV from your existing password
by thepasswordapp 10mo ago
Fair skepticism - I'd be suspicious too.
Two clarifications:
1. We don't ask for your current passwords. The app imports your CSV from your existing password manager (1Password, Bitwarden, etc.), which you already trust with your credentials. We automate the change process - you provide the new passwords you want.
2. Zero passwords leave your machine. The app runs locally. Browser automation happens in a local Playwright instance. The AI (GPT-5-mini via OpenRouter) only sees page structure, never credential values. Passwords are passed to forms via a separate injection mechanism that's invisible to the LLM context.
The "vibe coding" comment was about development speed with AI assistants, not about skipping security review. We spent weeks specifically on credential isolation architecture - making sure passwords can't leak to logs, LLM prompts, or network requests. That's the opposite of careless.
Code's not open source yet, but we're working toward that for exactly the reasons you describe - trust requires verification.
- 000ooo000 10mo agoThanks for the reply. Would be a useful service, good luck with it.