← Back to context

Comment by distances

2 days ago

I use a unique email address with the + format for each service, like "me+kagi@email.com". Login with email reveals the service through the address.

And yes, I too usually copy-paste both the username and the password, one right after the other. I have often thought that it seems very risky, but good to learn that Wayland already prevents clipboard sniffing.

The reason copy+pasting is risky is it builds a habit where you're vulnerable to phishing sites.

Use the browser extension for your password manager, it auto-fills based on URL, so if you're on "kagii.com", it won't auto-fill and you'll notice something is off, but if you're on "kagi.com" it will.

Auto-filling vs copy+pasting is a security feature.