Hacker News new | ask | show | jobs
by palant 1206 days ago
Note: I am the author of this article.

Yes, nothing I wrote negates the need for other security precautions. Keeping around a software which is accessible from the internet while not installing any updates for it (the vulnerability in question was already two years old) – obviously a bad idea. Installing software updates timely is always the first step for everyone.

But to address a specific concern of uploading your passwords to the cloud, a strong master password is a solution. And: no, keeping all passwords stored in a local file is far less convenient but not necessarily more secure.