3 ms·
No, they can't. The websites allow anyone in the world to make a guess at a password. Keepass doesn't since it requires having the private database file which y
by euank 13y ago
No, they can't. The websites allow anyone in the world to make a guess at a password. Keepass doesn't since it requires having the private database file which you store locally.
The websites allow for a vulnerability in third party code to expose you. Keepass, even if it has a vulnerability, can't be exploited remotely since the database is stored only locally.
The websites are in the browser and encourage browser extensions. Browsers suck for security... that's a massive attack surface and they are, by their nature, integrated with the network. Keepass is a dedicated application with a tiny surface that barely communicates with the internet at all and has no need to. A whole class of attacks miss it.
Keepass is leaps and bounds more secure.
- Houshalter 13y agoYes it is secure in that area, I mean for the specific attack this post is about where a hash of your password is hacked. All keepass would do is make your password the product of two hashes instead of one. I wasn't sure if that was that significantly more secure (if it was why aren't websites doing it automatically?) Of course that implies the attacker knows you used KeePass, security through obscurity and being in the minority should protect you.
- mpeg 13y agoNo, the point is not to make your password more secure in case of a data breach like this (although it can, since you can store a password that is very long and composed of random characters) The idea is that even if your password for kickstarter gets compromised, since you are using a password manager that password should only ever be used in kickstarter, so you can just change your password there and carry on