Hacker News new | ask | show | jobs
by SnacksOnAPlane 2784 days ago
For #1, the master password gets entered in when you need to decrypt the password file, right?

Doesn't that mean that anyone who can read the input stream from your keyboard can decrypt all your passwords?

I mean, I use a password manager because it's the least-shitty way I can think of to not reuse passwords, but to me it's a matter of when and not if some bad guy manages to insert malware into the password manager code and get all the passwords.

1 comments

Correct. That's why I mentioned the keylogger risk.