maumay
maumay t1_j1n0kv2 wrote
Reply to comment by sleepybrett in The Lastpass hack was worse than the company first reported by glawgii
Do you trust the correct implementation of TLS encryption when your credentials are sent over the internet? What difference is there with trusting the correct implementation of password encryption?
maumay t1_j1hpzu3 wrote
Reply to comment by sleepybrett in The Lastpass hack was worse than the company first reported by glawgii
Ultimately there is negligible risk if an attacker gets their hands on your encrypted data if it was encrypted correctly. Using something like bitwarden which is open source and regularly audited by external parties give you a pretty strong guarantee this is the case. Storing the vault in the cloud is much more convenient when needing to access passwords from multiple devices.
maumay t1_j1nc0xy wrote
Reply to comment by sleepybrett in The Lastpass hack was worse than the company first reported by glawgii
Ok, like I mentioned there are open source password manager like bitwarden whose source code is regularly audited and which can be verified by anyone.