Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

291–292 of 292 posts

Re: Notes on the Celebrity Data Theft

#291

Earlier quoted context omitted.

Why would you ever expose the sync folder publicly? Just keep a copy on a local computer with Dropbox if need be.

Because I only have one computer and no mobile devices— therefore I only have one copy of the password database, and I need the password database to access Dropbox. The sync folder is encrypted—is there some risk I'm not seeing?

Personally, I don't believe in leaving something like a password database exposed. That's akin to leaving a safe in the street. While someone might not be able to get in right away, why make it easier?

For you, I would just keep a copy elsewhere (friends computer etc.) or just get an additional device (mobile or otherwise).

Re: Notes on the Celebrity Data Theft

#292
post #126
post #115

Earlier quoted context omitted.

I was just offering it as a suggestion. Some people like to keep things on their own computers (or servers) and keepass offers that. I use Lastpass, which is hosted and I trust them with my passwords. I simply use keepassx to store two factor reset codes. I do this because if I store my reset codes in the same system as my passwords, then it's not very two-factor anymore, is it?

I completely understand. When people ask me which they should use, I outline the pros/cons of Keepass, LastPass, and 1Password. If you want password management for free, KeePass rocks. If you want to pay, it's definitely a tossup between LastPass and 1Password. I think they are all awesome tools.

This is an aside, but your comment reminded me to check why I've never even considered using 1Password and happily pay for LastPass.

A brief visit to their website later and I remembered: 1Password doesn't have Linux support. It's a shame; it looks really nice and I don't mind paying for good software.

Post reply on HN