Hacker News new | ask | show | jobs
by hshehehjdjdjd 2978 days ago
What possible protection could you have in a non-master password scenario? If you’ve decided that you don’t want the user to have to enter a password, it’s game over from a perspective of trying to keep the password from being retrieved by an attacker with local execution. Even with a master password, you’re only safe until you enter it, then the attacker has that info as well.