Skip to content

Comment on Ask HN: Chrome says I have 83 compromised passwords. How do I fix this?parent

Comments

I always had issues with KeepassXC. mostly as a concept, I'm not sure if it made sense, but since we're talking about it, how do you cope with the concept that if you lose your phone with the database on it, an attacker can just keep a perpetual copy of your passwords free to brute force and do whatever they wanted? I can revoke access to things with cloud services or self-hosted services, but with all the database in the hand of an attacker he can try to break it indefinitely and undisturbed.. I think KeepassXC for this reason is the worst among cloud hosted and self-hosted solutions

AFAIK, the filesystem is encrypted on any modern device. An attacker would have to first break into the device and then break into the password database. And if they can break into the device it is game over already.

Also, the attacker would have to be really motivated to brute force into it, and if it happened that my phone got stolen and I was worried about your scenario, I'd be just rotating all the high-value passwords I have, which is something that I think can be done quickly.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.