logoalt Hacker News

AlotOfReadingtoday at 12:03 AM1 replyview on HN

Are there any credential managers that don't validate the domain with passwords? Sure, there are issues with PSL subdomain matching, but at the end of the day it's good enough in the real world. All the other stuff (MITM, malicious site, etc) falls under the other case I already mentioned.


Replies

stavrostoday at 12:07 AM

There's a big difference between "generally doesn't get phished" and "it's impossible to be phished".

show 2 replies