3 ms·
I agree with feanaro, users should not trust .com over any other tld and if many of them need to touch a hot stove to let this sink in then so be it. Also, I do
by Datenstrom 7y ago
I agree with feanaro, users should not trust .com over any other tld and if many of them need to touch a hot stove to let this sink in then so be it. Also, I don't think anything that has any cost at all should be expected of any open source project unless you are paying them.
- hombre_fatal 7y agoI think that's a very sad and hostile way to treat people not as tech savvy as you. You talk about how users should do their own research, yet nobody at Keepass could even be bothered to update their homepage to help users make the disambiguation. Has Keepass done anything about this over the last year? Keepass' last release was 8 days ago. What even is the point of pushing another commit until you've at least done the bare minimum to help your users? What even is the bedrock purpose of this software at that point? Isn't the goal a password manager to help good folks avoid getting pwned by bad guys in the first place? Yet they now have zero skin in the game when bad guys use their image to pwn their own users? I just see bizarre incongruence. Like working hard to ship releases because that's the dedication your users deserve, gosh darnit, while your website has been compromised and serving different binaries for years.
- Groxx 7y ago>I think that's a very sad and hostile way to treat people not as tech savvy as you. To some degree, agreed. To some degree, this is the way the world works and protecting them earlier increases the risk that they'll make a big mistake later. Potayto, potahto. The underlying system is still so messed up that safety here is literally impossible, and there's no alternative.
- Datenstrom 7y agoI don't mean to be harsh that is just how people learn. It is something false about the world many people believe to be true and people learn from experience. I'm not sure the target audience for Keepass is anyone but tech savvy individuals either, I certainly don't know any non tech people that use it only LastPass and others like it. I touched a hot (wood) stove when I was a kid by the way.
- hombre_fatal 7y agoYou know, on second thought, you might have won me over: maybe Keepass' real gift to the world's security consciousness is giving the lay man his first taste of getting pwned.
- Digit-Al 7y agoHow is putting information on the homepage of the correct site going to help people who have gone to the wrong site? Pretty much nobody is going to go to both sites to see which looks most "legit". At best they'll assume that the sites are mirrors of each other, at worst they won't even notice two in the search results.
- michaelcampbell 7y agoBut they do. Sometimes you have to work out here in reality.
- joyeuse6701 7y agoI think it may be a stretch for a semi-technical user of keepass to realize that they have been pwned because they downloaded a client from keepass.com. They may think they were phished via email or some other avenue, so I don't think it's much of a guarantee that letting this happen would lead to users thinking 'Ah, that's what I get for trusting a tld! I'll be wiser next time.' I think it is more likely that an individual will react with 'ugh, hacked again, how did they guess my passwords!?'