logoalt Hacker News

prmoustacheyesterday at 9:08 PM3 repliesview on HN

You don't use a browser extension if you are serious about security anyway.


Replies

TheDongtoday at 4:48 AM

You do use the browser extension because it's a strong anti-phishing defense.

If someone links me to "rnicrosoft.com" with a perfectly cloned login page, my eyes might not notice that it's a phishing link, but my browser extension will refuse to autofill, and that will cause me to notice.

Phishing is one of the most common attacks, and also one of the easiest to fall for, so I think using the browser extension is on-net more secure even though it does increase your attack surface some.

I know proper 2fa, like webauthn/fido/yubikeys, also solves this (though totp 2fa does not), but a lot of the sites I use do not support a security key. If all my sites supported webauthn, I think avoiding the browser extension would be defensible.

show 1 reply
nextlevelwizardtoday at 4:31 AM

I guess I better just use same password everywhere then…

gck1yesterday at 10:09 PM

How do you autofill from your db then?

show 1 reply