4 ms·
If the cryptography and its implementation is perfect, and you choose a high entropy, well-guarded secret, then encryption is enough on its own. However, being
by feanaro 4y ago
If the cryptography and its implementation is perfect, and you choose a high entropy, well-guarded secret, then encryption is enough on its own. However, being a security researcher, I observe that this is not how the world works in practice, and so encryption is only a single layer in a defence in depth approach. There's little reason to destroy another important layer by centralising all the passwords in a single lucrative bucket.
An obvious way to attack typical cloud password managers is via their web apps, which is an endpoint attack and hence bypasses the encryption. This type of attack is much harder for native, offline password managers.