5 ms·
Seems like a positive change to me.
by chomp 2y ago
Seems like a positive change to me.
- brnt 2y agoThey disabled all plugins, not just those that may access networks. This is not good, it's nonsensical.
- Brian_K_White 2y agoThinking browser or other local integration is not as dangerous as network features is nonsensical. All of the disabled features are expendable. I never used any even while they were in there. Yet I do use keepassxc all day every day for the one job it actually does exist to do. Convenience and necessity are two different things. You want conveninece, and you're not wrong to want it, but you don't need it, and your want of convenience is not important enough to make the base utility when it is a password manager and not a gif editor less safe than it could be by default. It is correct that if you want to trade away safety for convenience, that you have to go out of your way to add that yourself, even if most people will choose to do that, and even if the previous default was backwards and it's now ever so slightly disruptive to correct that error now.
- timw4mail 2y agoAbsolute security means you can't do anything. Too much security friction can easily lead to *much more insecure* workarounds.
- Brian_K_White 2y agoSomehow, I have been using the same app without any of those features. So, the idea that the app is not functional or useful without them is bullshit. As for friction leading indirectly to less security through user behavior... how many clicks and how many seconds is it to install the full version? So, yet more bullshit.
- Phelinofist 2y ago> Convenience and necessity are two different things. You want conveninece, and you're not wrong to want it, but you don't need it, and your want... > Somehow, I have been using the same app without any of those features. So, the idea that the app is not functional or useful without them is bullshit. Different people might have different needs and wants and other criteria to consider it functional? I think this is not up for you to decide.
- Dylan16807 2y ago> Somehow, I have been using the same app without any of those features. And are you putting your passwords on the clipboard in a way that doesn't verify domain names? Congratulations, you're using insecure methods. Not bullshit.
- bananenpubs 2y ago[flagged]
- valicord 2y agoRemoving browser integration and auto-type doesn't increase security, it reduces it by exposing users to clipboard sniffing attacks and phishing websites.
- jeroenhd 2y agoBrowser integration, if done well, is actually more secure than the copy+pasting you end up doing otherwise. Storing passwords in the clipboard is a massive security risk, as the clipboard is shared by all applications and websites, while direct browser integrations allow for only providing the credentials to the specific web page they're meant for. While I'm not opposed to differentiating between a -full and a -minimal version, calling every plugin dangerous by default doesn't make sense.
- cyanydeez 2y ago>if done well Is that xkcd of a tiny project doing a lot of heavy lifting.