3 ms·
Google's security record at avoiding that kind of breach is just about the best in the industry, and their system that handles custody of password manager secre
by ameliaquining 2mo ago
Google's security record at avoiding that kind of breach is just about the best in the industry, and their system that handles custody of password manager secrets is designed to withstand even a compromise of their production infrastructure (https://security.googleblog.com/2022/10/SecurityofPasskeysintheGooglePasswordManager.html https://security.googleblog.com/2022/10/SecurityofPasskeysin...). I would advise almost all users to worry more about getting locked out of their password database than about that. Of course, I would also advise almost all users not to self-custody cryptocurrency.
- Cider9986 2mo agoYour link is about them using E2EE not that they can be as secure as E2EE for users without it. Users would lose their passkeys if they lost all secrets and devices. Google couldn't recover them. They can still and should still continue using great security practices while protecting E2EE data. >Of course, I would also advise almost all users not to self-custody cryptocurrency. There's no point in crypto if you're not holding your own keys. It's the antithesis of cryptocurrency. People can have highly secure self custody wallets on a modern iPhone or Pixel. And their seeds would have been safe if LastPass didn't have terrible security or they used long passphrases.