Earlier quoted context omitted.
[I work for AgileBits, makers of 1Password] Thanks for the feedback! Filling into sites and gathering the necessary information for this I think is far easier than determining how a password change takes place. We have an algorithm that we've developed over years that is constantly changing in subtle (and not so subtle) ways to make filling more accurate. Some of the biggest changes in a long time will be coming in t…
> Filling into sites and gathering the necessary information for this I think is far easier than determining how a password change takes place. Maybe start talking it out with browser developers and big websites stuff so there's a way to standardise an endpoint or in-page meta-information allowing for automated password reset?
That way, classy sites could enable a 'safe enough/good enough' flag that any software could use.
There is also the thought that it may be worth hard-coding for the biggest sites. The high profile sites are the most vulnerable when a vulnerability hits, there are big existing databases of user names around, and these can be exploited automatically and quickly on relatively high value targets (gmail accounts, amazon, facebook, twitter etc). Even top 10 would be helpful, but top 100 seems approachable, especially since the bigger sites are probably more consistent. The payoff here could be big next time around.
Also if the framework were around for doing this, you could target a particular site or three that just had a major breech, and push the rules for reset out with the breech notification.
I know it's a huge amount of work to do manually, but even a relatively focused effort could have payoffs, and if working with big sites can start a 'automated password reset' standard rolling, others might adopt it.
Just thinking out loud, I know you've got to juggle priorities and features with limited time.
Thanks again!