4 ms·
> There are ways to store data securely, one of the simplest methods is to do zero-knowledge encryption of that data by way of key-generation from a password on
by lixtra 5y ago
> There are ways to store data securely, one of the simplest methods is to do zero-knowledge encryption of that data by way of key-generation from a password only the user knows at the time of decryption.
This keeps your passwords save until you enter your master password. At that point you have to trust the software that was downloaded a few days ago from an appstore or a few seconds ago from the company webserver. It might have been backdoored and happily phone home your master password.
Your downloaded password manager might be a few years old and YOU decide when to upgrade.
- tristor 5y agoYour argument has nothing to do with cloud storage or password managers generally and seems to be an argument against automatic updates. So, fine, disable automatic updates (although I'd argue you're safer with them). I also baked in the presumption that the software isn't malicious in my comment and called it out. So, sure, yes malware that leaks your password can exist. That doesn't really have any effect on whether password managers are a good thing or trustworthy.
- vkou 5y agoIf the client for a cloud password manager is open-source, I'm inclined to trust it about as much as I would a non-cloud open-source password manager.
- sleepybrett 5y agoI use 1password7 in a mode where I have to manually sync my vault. I've used other tools to prevent 1password from initiating any network connectivity at all.
- junon 5y agoAnd what threat model does this satisfy?