• Godort@lemmy.ca
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      This is probably fine. The connection to DDG will be over HTTPS, so a captured packet would need to be decoded first. And if someone were to manage to break the encryption, then they would also need to know what service you used the password for.

      Ultimately, it’s more secure to generate locally, but it would be a huge amount of work to get anything usable out of a packet capture

  • chicken@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    That’s fucked up, they should not do that. Even if they do it in a way that users are actually secure (maybe generating the password in the browser, nothing serverside?), it isn’t good to train people to trust a website for this.