Comment on (In)Security of the “Pass” password managerComments−yellowapple3yI feel like half of these problems would be solved by pass signing and encrypting the stored passwords, and then refusing to decrypt anything not signed by a known-valid key without the user's explicit case-by-case consent and knowledge.
Comments
I feel like half of these problems would be solved by pass signing and encrypting the stored passwords, and then refusing to decrypt anything not signed by a known-valid key without the user's explicit case-by-case consent and knowledge.