Skip to content

Comment on (In)Security of the “Pass” password manager

Comments

I feel like half of these problems would be solved by pass signing and encrypting the stored passwords, and then refusing to decrypt anything not signed by a known-valid key without the user's explicit case-by-case consent and knowledge.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.