|
|
|
|
|
by Postosuchus
36 days ago
|
|
KeepassXC comes with its own share of risks (supply-chain attacks, zero-day vulnerability detections etc). No matter, which 3p software you are using, you are effectively gambling on the chance that none of those risks materialize. The only alternative is to personally audit the code - library by library, script by script and build it yourself. But even that carries risks: https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref... |
|
If I keep a KeepassXC database on a set of devices, sync'd using syncthing, then for a large range of threats I'd need to be a target of interest.
This is in contrast to LastPass which is going to attract a ton of blackhat attention.
Yes, supply chain attacks are possible but they're equally possible for lastpass.
Switching to a self-hosted solution isn't perfect. Nothing is, and pointing that out isn't particularly useful.
What it does do is eliminate whole class of threats: large scale, broad based attacks against a single, high value target.
In fact I'd argue writing passwords down in a notebook or putting them in a naked text file on your computer is better than trusting a centralized service like LP.
Of course, if you are a target of interest, the calculus changes entirely.