5 ms·
... this doesn't sound easier, this sounds much more annoying. But each to is own.
by MetaCosm 13y ago
... this doesn't sound easier, this sounds much more annoying. But each to is own.
- subsection1h 13y agoI didn't assert that it was easier, just potentially more secure. Similarly, it's arguably annoying to only access financial accounts (and the email accounts that are associated with the financial accounts) using a dedicated banking computer, but I think that having a banking computer is worth it. Others will disagree.
- jpgoldberg 13y ago[Disclosure: I work for AgileBits, makers of 1Password] One way of characterizing the particular paper is "password managers with browser extensions don't always prevent you from submitting your data to the wrong place." Systems that rely on the user to copy/paste offer no such protections whatsoever (and so, I suppose, can't fail at them.) So I'm curious about what you may mean by "potentially more secure" in this particular respect. Are you concerned that you might come to rely too heavily on the password manager's anti-phishing mechanisms? [Note that I fully acknowledge that there may be other security reasons you may wish to keep your password manager out of browser. 1Password and KeePass have different security architectures, development processes, platform support, etc, with their own advantages and disadvantages. People need to figure out which works best for them.]
- aclevernickname 13y agoNot knowing the passwords, and keeping them in a locked database you copy/paste from creates plausible deniability if in a situation where one is beaten with a $5 wrench. For some people, the risk of disclosure by violence is more a worry than the risk of disclosure by the clipboard.
- gemma 13y agoKeePass also makes a global keyboard shortcut available (Ctrl+Alt+A by default) that will complete login fields based on the active window title. (The mechanics of the text entry and the window title matching are all configurable, though the defaults are usually fine.) Not as slick as auto-filling without user interaction, but better than manually searching for each entry every time.
- xur17 13y agoI've been using this in ubuntu (ctrl-alt-v in keepassx). It covers most of the sites I use, and works with minimal extra effort. I originally looked at Lastpass, but it seemed 'too' easy. Decryption is done client side via javascript, but what happens if someone hacks into Lastpass's server, and modifies the code to send the user's entered password to their server?
- jlgaddis 13y agohttp://www.pcworld.com/article/227268/lastpass_ceo_exclusive_interview.html http://www.pcworld.com/article/227268/lastpass_ceo_exclusive...