Ask HN: How comfortable do you feel using cloud-based password managers?
11–20 of 199 posts
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#12Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#13Same way I feel about security domains at work: you either have to trust encryption, or never use any network. It’s that binary. At work I’ll see people — the security team, usually — taking some already-encrypted thing and re-hardening it to the nth degree. I think that’s stupid. If you don’t trust your encryption, don’t bother using it. If you do trust it, stop there. It’s maths. It’s proven. I feel the same about…
If you are encrypting a password store and using the cloud only for sync, you're trusting an encryption standard.
If you are using a cloud based password manager from a service provider, they may be using encryption, but your trust has to be in the company and their employees.
It's a rather large distinction.
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#14Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#15For other people, such as family members: I totally recommend it. It is way better than whatever password reuse they are doing now, and the chances of a breach are low enough.
My point being: I think they are overall better than not using anything, but if you have the knowledge and diligence to keep an offline encrypted file (and its backup!) up to date, then I would suggest doing that instead.
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#16Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#17Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#18That said, I use my own remote storage (not cloud) with keepass's sftp plugin.
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#19Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#20Same way I feel about security domains at work: you either have to trust encryption, or never use any network. It’s that binary. At work I’ll see people — the security team, usually — taking some already-encrypted thing and re-hardening it to the nth degree. I think that’s stupid. If you don’t trust your encryption, don’t bother using it. If you do trust it, stop there. It’s maths. It’s proven. I feel the same about…
No they are not. That’s one of the things that makes designing correct crypto systems difficult. Going the wrong way through most cryptographic trap doors is conjectured to be difficult but I’m unaware of a single one that’s proven.