|
|
|
|
|
by jen729w
2470 days ago
|
|
Same way I feel about security domains at work: you either have to trust encryption, or never use any network. It’s that binary. At work I’ll see people — the security team, usually — taking some already-encrypted thing and re-hardening it to the nth degree. I think that’s stupid. If you don’t trust your encryption, don’t bother using it. If you do trust it, stop there. It’s maths. It’s proven. I feel the same about 1Password. I trust that they encrypt my stuff with trusted encryption. That’s it. |
|
If you are encrypting a password store and using the cloud only for sync, you're trusting an encryption standard.
If you are using a cloud based password manager from a service provider, they may be using encryption, but your trust has to be in the company and their employees.
It's a rather large distinction.