Home Password Strength Clean URL One-time Encrypt

Password safety and browser-local encryption

Which URL parameters to strip when you share a link, who can read plaintext after a cloud upload, and how to verify client-side encryption in DevTools. Each piece answers one question you can check on the spot.

After you install LastPass Authenticator from a search result, who can still read the passwords, sessions, and wallets saved in the browser

17 Sept 2026 LastPass and Delphos: the official authenticator is only on lastpass.com and the app stores, and official systems and vaults were not breached. A Windows PC that ran an unofficial installer from search should treat saved passwords, sessions, and wallets as already read. Change them from a clean device. Send a live key on a one-time link. Do not rehearse with a master password.

After you change the password and MFA, who can still walk into the AI session in your browser

Okta’s Sept 2026 7 GB infostealer dump: unexpired AI session tokens can skip password and MFA. Anthropic told some Claude users that signing out old sessions will not stop a local trojan from stealing the next one. Check the official numbers and your own session list with a test account. Send a live key on a one-time link. Do not rehearse with a master password.

What to redact before you paste a password into ChatGPT or Gemini

Asking about an error is fine. Pasting a live password, API key, or full one-time URL into ChatGPT or Gemini hands plaintext to history, review, and any share page. Check training, Temporary Chat (30 days), Gemini’s 72 hours, and public links. Redact a test string first. Send a live key on a one-time link. Do not rehearse with a master password.

Who else can read the clipboard after you copy a password

After Copy, the password sits in the system clipboard, not only on the generator page. Check web readText permission, Win+V’s 25-item history, and whether Universal Clipboard can paste on another signed-in device. Use a test string, then overwrite.

Random password vs passphrase: four words are not automatically strong

Use a random password when a manager can fill it. Type by hand? Use a passphrase and add words — four from a 100-word list is about 27 bits, far weaker than a default 16-character string. Compare Diceware’s 7,776-word list and NIST’s 15-character single-factor floor, then confirm in Network that the result was not uploaded.

When you send a password once, why the decryption key belongs after # in the URL

Chat history keeps searchable plaintext. On a one-time link, put the decryption key after # — RFC 9110 keeps that fragment off the HTTP request line. Write it as ?key= and access logs can see it. Check Network: the create request should hold ciphertext only, and the read-page request line should omit the key. The full URL is still a credential.

Which fields to redact before sending tickets and chat logs

Once the URL is clean, the body often still holds a phone number, SSN, card, and email. See which fields must be masked, which order IDs to leave, and how to compare original and result on this device. Redaction is not anonymization.

How to verify that browser encryption did not upload plaintext

Online encrypt pages claim they never upload. Open DevTools Network and check the request URL, payload, and analytics for plaintext, a password, or the key after #. AES-256-GCM should finish in Web Crypto before any ciphertext leaves.