Skip to content

Comment on Passwords, Backups and a false sense of securityparent

Comments

The whole point of a password manager is that it is convenient. Sure, the database may be exposed to malware, but that applies to any password that gets used, so the additional risk is pretty small.

No, the additional risk is enormous. If they get your password database they get all of your passwords. If you don't use a password database, they only get the passwords you use, which (unless you sign into everything every day) should not be all of your passwords.

I would expect the malware to sit there quietly until it collected at least a few interesting passwords. So it sort of depends on what the attacker is trying to do and how many interesting accounts the attacked has.

Yeah, I figure you've got a good month before they do something with the collected accounts, or more depending on who they sold it to.

At the very least, never save a password to a critical account, such as a financial account or a root/administrator password. I could care less if someone takes over my Twitter and Facebook (if I had them) but am highly paranoid about accounts which will actually affect my life.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.