> there are ways to spoof what the current website is, causing your context-aware password manager to spit out data it shouldn't.
Can you give an example?
Can you give an example?
I seem to remember reading about similar stuff done elsewhere, but don't remember the details (or apparently a useful search term :P).