Hacker News new | past | comments | ask | show | jobs | submit login

Having a different vendor for the frontend software and the cloud storage part does arguably increase security.

Let's say a national security agency wants access to your passwords. They can "easily" make LastPass send a custom version of the client to your browser. This custom version could send your password to LastPass, allowing them to decrypt your database.

To me it seems like it would be harder to ship a malicious KeePass program to a single user. Especially if that user has installed KeePass using their Linux OS package manager.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: