3 ms·
Yep, pretty much. It really reminds me of this: https://xkcd.com/1200/ https://xkcd.com/1200/ for obvious reasons. The only ways I can think that would be able
by kefka 9y ago
Yep, pretty much. It really reminds me of this: https://xkcd.com/1200/ https://xkcd.com/1200/ for obvious reasons.
The only ways I can think that would be able to prevent this are:
1. Physical non-networked device password manager
2. Really creative usage of SELinux
3. QubesOS
And in reality, #1 is kind of how RSA tokens are used. Of course, physical can be lost, stolen, and all that. QubesOS takes a ton of resources to run effectively, given everything is VM'ed and contained with a capability system.
In all honesty, I could see buying an Android at a Pay as You Go place, and repurpose it to be a offline password manager. Never connect it to wifi, BT, cell. And any APK's you need you load via microSD card and USB.