How hard can it be? It can already log in by itself, now it just needs to know the page where you can change your password.
How hard can it be? It can already log in by itself, now it just needs to know the page where you can change your password.
The main issue is; scraping is hard and breaks at the drop of a hat. Sure you could script hourly password changes if you wanted to, but as soon as the host service modifies their forms a little, the whole system breaks and you could possibly be locked out of your account.
Really, the only solution to this kind of thing is offshore corps.
1Password is a local, encrypted store of known passwords. Nothing is generated, except for the original passphrases themselves, which are completely random (not from a seed).
Still, if 1password made scraping work for the biggest sites out there (google, microsoft, etc) then that in itself would already be worthwhile.
The only reason any of this is an issue is because we have our data and communication in the internet. That's what makes mass surveillance possible.
If you keep your data off the internet, then you're only at risk of individual surveillance. But even that's difficult; stuxnet demonstrated that even air gapped computers are at risk, because we move data around on usb sticks and the like.
So, speech and paper, or human memory, are the only really secure media.
As for all the apps we carry around in our pockets ... do you really need instant online access to your bank balance over the internet on the bus? We used to carry around checkbooks and make entries in the register. If you really need to know your balance 24/7, carry a register booklet, or a moleskin. Then you don't have to wonder if Mint et al. are giving up your passwords.
Opt out.