3 ms·
Read the article - each attack it mentions only applies to browser-integrated ones. If instead you mean "browser-integrated" as in the default "remember my pas
by euank 13y ago
Read the article - each attack it mentions only applies to browser-integrated ones.
If instead you mean "browser-integrated" as in the default "remember my password", well, those are not what this paper discusses and are generally better, though they are still not as desirable as a standalone less-privileged manager.
The idea that the password manager should be separate is practically common sense. Browsers provide more surface are for attack. Browsers are made to share content and work with network data. Ideally, your password manager should never touch the network ever. It has no need to.