

all they need to do is get you to install a sketchy browser extension and then anytime you generate a password on ddg they’ve captured it. No man in the middle necessary. Unlike generating a pw with your pw manager, then inserting it with your pw manager or just typing it into the field (which shouldn’t be accessible to extensions on any appropriately coded site).










I’ve only partially read over you wrote and am heading into the mountains on vacation, but I will try to read over what you’ve written here sometime this weekend.