Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Password managers with browser extensions are a good fix for this too. If you're used to entering your password only through the extension, not being able to do that on a login screen would be a big warning sign. Admittedly, these extensions have had some vulnerabilities in the past, but phishing is simply a bigger problem for the vast majority of users.

Obviously, for sites that support U2F (like Google), getting a YubiKey or any other U2F-compatible key would be the best protection against this.



Semi-relevant link from Bruce Schneier on the subject and that he did not design password safe with a browser extension in mind. https://www.schneier.com/blog/archives/2014/09/security_of_p.... The android version implements a keyboard replacement rather than integrate though not as easy to use is still mostly usable.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: