Hacker News new | ask | show | jobs
by nightpool 1119 days ago
How do you suggest keeping your database in sync between your desktop and mobile device? I use Keepass2Android and I'm 100% happy with it, because it has incredibly good Dropbox sync support. I don't think throwing out every single networked feature just because of one malicious app is a reasonable or proportionate response.

Besides, I'm sure some clever attackers could think long and hard and come up with plenty of covert exfiltration channels without even needing direct network access. For example, adding a "safety redirect" every time you open your web browser, like t.co does.

1 comments

Can't you store the database locally and then have Dropbox or Google Drive upload it to your drive?

It's still not 100% secure, but you would need both a compromised Keepass app and a compromised Dropbox app.