2 ms·
I would assume that the most likely issue you would face is malware running on your own computer that captures the master key or sends passwords back to an atta
by rand49an 5y ago
I would assume that the most likely issue you would face is malware running on your own computer that captures the master key or sends passwords back to an attacker. Not someone gaining access to the encrypted password vault and then cracking it - unless you have a very week key.
- gorjusborg 5y agoNo weak key here, and you may be right, but my main concern is that encryption is only strong in a given time period. If someone could gain a copy of a known high-value ciphertext, they may not be able to crack it now, but time is on their side, and I can't recover the file once it is out there. My only recourse is to speculatively rotate passwords inside the file.