4 ms·
You may be getting hung up on this concept a little too much. Of course, using a password manager increases the attack surface in that if the encrypted passwor
by aptwebapps 12y ago
You may be getting hung up on this concept a little too much.
Of course, using a password manager increases the attack surface in that if the encrypted passwords are stored on a server and the encryption wasn't good enough you're in trouble. But what you're talking about, where the plaintext password must be inserted into the web form, doesn't strike me as a vulnerability that would not exist without the password manager. If you simply memorized it you would still have to type it in. Moreover, keeping the password secret is not an end in itself, it's a tool to keep your actual secrets secret. If you login to some sort of account, and then access those secrets on your computer there's the analog hole again.
If you don't have a computer on which it's safe to type in a password you don't have one on which it is safe to read or view your secrets.
- deleted 12y ago[deleted]