2 ms·
I do use Keepass, but I don't want to need to trust Dropbox etc. I know the Keepass file is nominally password protected, but once I upload a Keepass file with
by SomeCallMeTim 12y ago
I do use Keepass, but I don't want to need to trust Dropbox etc.
I know the Keepass file is nominally password protected, but once I upload a Keepass file with all my important passwords to a site like Dropbox, there's no way to ever recall it reliably.
So if there's a Dropbox security hole, someone can potentially grab a copy. And then if there's a Keepass security hole (or if they otherwise acquire my password), then all my important passwords are compromised.
To me it's a form of "two factor" authentication for my passwords: One factor is the passphrase, the other is the physical file itself. And one of those is defeated if I upload the file to some cloud service.
- Spooky23 12y agoMy assumption is that a skilled attacker targeting me in particular will be able to compromise my access to services. Easiest vector is probably compromising email and doing password resets. IMO the security controls that I have in place for my vault files are strong enough to make it too expensive for a general attack on files in Dropbox to be cost effective.