Hacker News new | ask | show | jobs
by kenmacd 1073 days ago
Correct me if I'm wrong, but I suspect this has the same issue preventing me from using it as does Bitwarden, namely: if I give you my vault and my password, you can access all my passwords.

With how common hardware security keys (or even just tpm2) are these days this limitation seems inexcusable to me. Which is why I'll stick with gopass/pass using my yubikey (w/ touch policy fixed). You might hack my machine and trick me in to decrypting a few passwords, but at least you won't make off with them all.