3 ms·
I'm probably the least knowledgeable person on HN so please understand these as questions more than objections, okay? I would think the first link doesn't affe
by Gruselbauer 10y ago
I'm probably the least knowledgeable person on HN so please understand these as questions more than objections, okay?
I would think the first link doesn't affect me since I use a fairly strong unique master password and haven't set an insecurity question.
As for the second link, much the same. I mean I'm fairly certain I can create an encrypted plaintext file that withstands extensive cracking attempts with standard Linux tools. These kinds of attacks would suck for people using 'lastpassword' as their master, if the stored vaults were unhashed and unsalted. Even then, how would that circumvent 2FA? Without my phone or Yubikey or whatever, you still don't get in.
As for the last one, and generally for most criticism: these tools give you the means to be more secure, they even encourage you by asking things that must annoy the average user. There's no unlimited trust for devices or browsers, the security checker is actually quite helpful in identifying possible problems - like my banking password being capped at five digits by design... sigh - and telling you when you're getting dumb ideas, like permanently storing your master password on your phone. So in the end, it's up to the user isn't it?
It's not using it by itself that makes the concept an increase in security, it's using it thoughtfully that is.