Hacker News new | ask | show | jobs
by jackweirdy 1577 days ago
It still proves you’re giving the password right this moment, and that it hasn’t been popped from a DB.

On the other hand it doesn’t prove that someone has stolen your phone/laptop, defeated all of its own security, and then defeated the security of the password manager.

For my personal risk propensity, the former is worth having, the latter is too unlikely to worry about