Why aren't we doing more to validate the identity of the service we are trying to connect to? CAs don't allow me to establish my own personal web of trust. If I connect once to my bank in a method I deem safe, I should be able to store their credentials in an easy to validate way. That way if I fall for a phishing attack, the browser can CLEARLY indicate to me that I'm encountering a new entity, not one I have an est…
(*): Note that "autofill" only means "automatically populate credentials", not "automatically populate credentials without any user interaction". Clicking the username field, choosing a credential from a dropdown that the password manager populated for you based on which credentials match the website in question, and then having it be applied is also "autofill".