3 ms·
I think that if you, an individual who owns some crypto, wants to store your key in a password vault, that's probably fine, as long as you accept the risks (you
by mithr 3y ago
I think that if you, an individual who owns some crypto, wants to store your key in a password vault, that's probably fine, as long as you accept the risks (you've done your due diligence and trust your password manager is secure enough for your expected risk factor, etc).
But if you're an exchange handling billions of dollars of customer assets, the requirements should probably be higher. The text implies that many employees at the company had access to the password vault, for example. Also, shared password vaults that I've seen tend to have functionality like the ability to share a password externally (something you probably don't want!), relatively low logging abilities (while it would probably be a good idea to track each and every time a crypto key was accessed and who acccesed it), etc.
At least that's my guess at what they meant — perhaps someone had deeper knowledge and can share that.