Skip to content

Comment on A secure way to store website users "offsite" but still own them.parent

Comments

Like I keep telling you, this isn't any more or less secure than any existing solution because the browser is not secure in the face of an attack. Even with HTTPS if I can inject some javscript then it's a one-liner to get your password.

So no, even with HTTPS and your proposed solution you'd still be screwed.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.