Earlier quoted context omitted.
i dont even know which version i run, so no idea if i have to be scared or not. updates are way to painful to do regulary on a working dev machine. (lazy linux user here) anyway i never saved a password, thats exactly my point. There is not a single reason to believe that the apple keychain can be fully trusted, its that simple.
> There is not a single reason to believe that the apple keychain can be fully trusted, its that simple. How do you believe that differs from any other cloud manager, local or cloud-hosted? What reason(s) do you have to believe they can be fully trusted? Or do you not use password managers at all? I assume you don't re-use passwords from site to site (because there's also no single reason to believe any particular si…
On other places i use a password sheme, and if possible 2fa. A sheme is not perfect ether, but would require to attacker to fetch multiple of my passwords until he can recreate it.