Usually a lurker.
Maybe I should’ve just shut up and thought for a bit longer before writing that comment…

If you want to talk to me elsewhere, you know how to reach me.

  • 2 Posts
  • 913 Comments
Joined 3 years ago
cake
Cake day: July 1st, 2023

help-circle




  • The issue with being unable to websearch public (indexible) knowledge on products, services or problems wont be due to forums dying out or devs switching to discord servers (or adjacent) but instead putting the docs behind an AI gatekeeper and preventing you from just downloading the straight PDF or reading the kb article as an outsider.

    You will own nothing, know nothing and be nothing and you will be happy.










  • Bitwarden did so too.

    But IMO your assumption is a bit of interpreting bad/malicious faith into it.
    I see it more like they are the more publicly known brands/services that do this and underwent the audit.
    I have read the TLDR by the authors (linked a few times in the comments) and the answer by bitwarden.
    Bitwarden said the, fixed the issue, are in the progress of doing it or are accepting it as “this is intended/a trade-off”.
    What is a bit sad is that they had more vulnerabilities than other vendors. But I trust them more as they are mostly OSS.



  • Great.
    I am now your spouse and you want to give me access to the flash drive. What now?

    New requirement: I have several passwords I want to give you access to as well. What now?

    As with everything: Your solution may work for yourself and a few others. The majority don’t want to collect 5 flash drives in different locations every 3 months to update a file (and making sure it’s the correct vault they have copied)



  • “We want our work to help bring about change in this industry,” says Paterson. “The providers of password managers should not make false promises to their customers about security but instead communicate more clearly and precisely what security guarantees their solutions actually offer.”

    Great.
    Now which password vault was the most cooperative and clear in their security communication and which one wasnt?
    The author said that they have given the providers time to fix the issues. Now highlight the ones that did it the best… >_>