3 ms·
You should not trust password managers with critical stuff. Even if the product is secure. Even if it actually does end-to-end encryption. Even if it is open-s
by lmilcin 5y ago
You should not trust password managers with critical stuff.
Even if the product is secure. Even if it actually does end-to-end encryption. Even if it is open-source and you can audit code.
Even if all of the above are met, somebody still can upload a malicious package or commit malicious change that gets propagated to you.
It is probably fine to use password managers for stuff where damage would be limited (accounts to low value things).
But for stuff that matters I know of no better system than a piece of paper, a tamper evident envelope and a logbook.