Where to file bugs/ideas?
Oh well.. here goes:
1)
For some sites, the javascript code is conflicting. It seems to put the form fields into a query because the form doesn't use a standard method of posting but relies on the onsubmit event. (I think)
Of course the login then just fails.
This even happens when I enter the OTP. The password does get replaced with the fetched password.
Example:
https://www.clipperz.com/beta/?username ... assphrase=The extra passphrase fields are also odd.
2)
add the attribute autocomplete="off" to password fields
3)
Add more yubikeys for a single account please.
Also, make the password/username input optional since it's weak and already known from the yubikey id.
4)
Show the master password dialog before the page you try to use the yubikey on outputs an error.
4)
How about making the master password dialog optional for plaintext+OTP combination.
(just like the way yubikey-pam works too)
5)
Make the kg server less knowledgeable.