Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ah, I hadn't considered that... That's a shame...


Just wanted to point out that any implementation as a browser extension (as opposed to bookmarklet) is safe from DOM manipulation; searching on Google for "supergenpass extension" returns results for at least Chrome, Firefox and Opera.


I'm not so sure, the extension still appends DOM elements, I'm sure those are just as susceptible to sniffing...


I haven't looked at the code or even used it that much, but it seems like it only uses content scripts to insert the password into the field, and everything else is dealt with by the popup/background page, which websites don't have access to.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: