Hacker News new | past | comments | ask | show | jobs | submit login

I use Lastpass and I just realized that it prevents phishing since it autocompletes my login info based on the domain.



Don't forget that the LastPass chrome extension has been tricked in the past to extract passwords from arbitrary domains. It's still important to use your brain when clicking links and invoking LastPass's autofill functions.

https://labs.detectify.com/2016/07/27/how-i-made-lastpass-gi...


That's why I love and recommend password managers to all my friends / relatives. Not only does it help prevent phishing but it promotes stronger passwords.


Likewise - if Firefox doesn't automatically fill in a password that I expect it to, something strange is going on. (Especially now that Firefox automatically uses http credentials for the same page on https, which removes the one other common reasons for this to happen.)


Which is yet another reason (not that we needed one) why those pages which try to prevent autocomplete of passwords are wrong, wrong, wrong.


While I also don't like sites breaking autocomplete, LastPass' "Show matching sites" dropdown only lists accounts valid for the current domain. So a very similar protection is available even without autocomplete.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: