Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This isn't a really great solution, in my opinion. Anyone with access to your google account, or anyone with physical access to any of your synced devices could lift your passwords easily.


Wouldn't anyone with access to my two factor authenticated Google/gmail account be able to reset most of my passwords anyway? The biggest risk is perhaps a rogue Chrome extensions scraping the password page when I visit it.


I think they ask your google password once again, when you try to access that functionality, even if you already logged in.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: