Hacker News new | ask | show | jobs
by grouchypumpkin 601 days ago
Isn’t it the same threat model as Lastpass breach? Login credentials seem to be worth money, and crypto keys even more.
1 comments

The comment was referring to Keepassium and Strongbox, which do not store credentials on their servers so it's not exactly the same. While conceivably a compromised Keepass wrapper could decrypt and send the dump of each and every file it opens, I doubt it would pass unnoticed.