logoalt Hacker News

akerl_yesterday at 10:48 PM3 repliesview on HN

Which is why a properly working password manager is not a strong defense against phishing.


Replies

jopsentoday at 6:47 AM

Not a strong defense, but it helps.

But it's also why sites that don't work well with a password manager are actively setting their users up to be phished.

Same with every site that uses sketchy domains, or worse redirects you to xyz.auth0.com to sign in.

otterleyyesterday at 10:52 PM

Correct. The moral of the story is that hardware MFA and/or passkeys are a necessity in today's world. An infinitely complex password and 2FA are no match for attacks that leverage human psychology.

onionisafruityesterday at 10:56 PM

It's a strong defense that this guy decided not to use

show 1 reply