• 2 Posts
  • 228 Comments
Joined 1 year ago
cake
Cake day: June 20th, 2023

help-circle
  • A physical token only authenticates itself as “something you have” if there’s no way to extract the key from it. In practice non-hardcore deployments usually have a backup procedure but in principle, if you want multiple tokens, they should have separate keys. What you’re asking in simplest form involves storing the key on a server where it can potentially spill in a server breach or the like. If the key protects something very valuable, that can be dangerous. If it’s for your old Reddit account, you might decide to do it anyway.



















  • I will have to check whether the font in the address bar has the same issue (edit: yes it does). But the reason the “make password visible” feature exists at all (instead of just “copy password to clipboard”) is to make the password readable by eyeball. It fails to do that. That failure is why there is an open Bugzilla ticket. If it worked properly, there would be no ticket or it would have been closed. But making it work is treated as an enhancement rather than a fix. Gack.

    Also, pasting the password into the address bar drops it into the search system and maybe leaks it, who knows. Not a good idea.