Use the "passwords" feature to check if one of yours is compromised. If it shows up, never ever reuse those credentials. They'll be baked into thousands of botnets etc. and be forevermore part of automated break-in attempts until one randomly succeeds.

you are viewing a single comment's thread
view the rest of the comments
[–] 10 points 10 months ago (5 children)

Something to keep in mind about not using browser integrations is that you can fall victim to simple keyloggers and clipboard stealers. But using an extension can also be a weakpoint if it autopopulates incorrectly or on a compromised site; but that's far less common.

But, dear readers, don't let that dissuade you: even a text file in a veracrypt volume is better than "PurpleElephant1994"

  • source
  • parent
  • hideshow 5 child comments
  • [–] 13 points 10 months ago (1 child)

    I would dare say PurpleElephant1994 is already much better than most passwords people have been willingly tell me.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 10 months ago

    I recently found out a family member's passwords are things like "1100011", "1111000" and similar variations. It's like they're already using binary to give a helping boost to brute-forcing bots.

  • source
  • parent
  • [–] 4 points 10 months ago

    In theory auto-population is way more likely to save you from getting scammed because it won't do it for a fake site, as the URL doesn't match. In practice though most people are just going to be annoyed it didn't work and do it manually anyway before they realize why it didn't work.

  • source
  • parent