-
Notifications
You must be signed in to change notification settings - Fork 1k
Closed
Labels
enhancementNew feature or requestNew feature or requestfirefoxFirefox-specific issueFirefox-specific issue
Description
Hello,
Right now this extension requires "Access your data for all websites" permission. I understand why this is used and I agree reading QR codes from the screen is useful, but I consider it too risky to use.
I understand that this extension going rogue would mean that the attacker could get the login information together with the TOTP token. Am I correct?
It would be nice to have an alternative extension (maybe a fork: Authenticator-lite?) that would only allow you to introduce the shared secret as plain text but it doesn't require any additional permissions.
Thank you for your work!
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestfirefoxFirefox-specific issueFirefox-specific issue