I made a small update to
SuperGenPass (
full write up) to randomise several of the variable names. This will prevent
this exploit from working. It is by no means fool proof, and I'd still recommend using the Data URI or other out of band version for full assurance. I've been using it for a few weeks now with no incident. Additionally, as the randomisation is done per user, and up-front, I'd recommend
hitting the page via TLS. I use a self-signed cert, the fingerprints are on the right of my blog.