Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

IMO a password manager is an extremely critical piece of software that I'm ok with if I trust its security model. There are a couple whose security models I do trust. However, merging those security models with random extensions that may or may not have full run of all code executing in the same context as my password manager is a hard no. It's baffling to me that any legit password managers go to the trouble to write and support browser extensions, given the risk. It's betting your reputation for security on a very small amount of user convenience.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: