Hacker News new | ask | show | jobs
by charles_f 1094 days ago
It's not about the leak itself, but the lax of their operational policies that resulted into it, the low level of ownership they demonstrated in communication through the incidents, the weird design decisions that were made to leave parts of wallets unencrypted, that you would never know of since it's all a black box (1pwd for example opensourced some of their designs).
1 comments

Unless you want to self host, it is naive to think other password managers are not also the subject of attack
The problem, IMHO, is that selling a password manager is about selling trust. It is okay to have an incident (to some extent of course: "we got hacked and somebody stole our database, which was not encrypted" is pretty bad), but it is not okay to lose trust.

Given how it has been going with LastPass, I don't see how one would still trust them with their passwords.

Very true, that's why I stick to KeePassDX for many years now.