Hacker News new | ask | show | jobs
by gruez 1935 days ago
Your threat model doesn't really make sense either. If your password manager is evil, you're probably screwed anyways because on non-sandboxed platforms (ie. windows, linux, maybe mac), there's basically zero security between applications so there are a variety of ways it can get your google/bank passwords. As for the "dumb" bit, that can almost be entirely mitigated by using a password manager that doesn't have network functionality.