3 ms·
What amazes me most is that people will trust all their passwords to a piece of software and they don't really know what it is doing. If you want to install th
by Haskell 18y ago
What amazes me most is that people will trust all their passwords to a piece of software and they don't really know what it is doing.
If you want to install this Password Gorilla thing in your MacOS, how do you know if it isn't trojaned? Where is the checksum for you to verify it?
Do you remember that even an security researcher and openbsd developer got his box hacked and his software trojaned?
http://tinyurl.com/3owcj7 http://tinyurl.com/3owcj7
Remember what your mother said: Don't accept candy from strangers. So I hope you all are checking the source code and compiling it your selves.
Not that checking the source code would be enough. When was the last time you checked the source code from anything you downloaded?
Ok, so you checked the source code to see that there's no backdoor sending your password over the internet, but do you yet remember the debian SSL vulnerability?
Yes, there could be a similar, subtle, but maliciously introduced flaw in cryptographic algorithm used by the password manager. So it's just a matter of an attacker having access to the cloud storage, not that that would be difficult either (remember the hacked Fedora and Redhat servers?), and "deciphering" all of your passwords.