Hacker News new | ask | show | jobs
by unknownfuture 36 days ago
You're ignoring threat modelling.

If I keep a KeepassXC database on a set of devices, sync'd using syncthing, then for a large range of threats I'd need to be a target of interest.

This is in contrast to LastPass which is going to attract a ton of blackhat attention.

Yes, supply chain attacks are possible but they're equally possible for lastpass.

Switching to a self-hosted solution isn't perfect. Nothing is, and pointing that out isn't particularly useful.

What it does do is eliminate whole class of threats: large scale, broad based attacks against a single, high value target.

In fact I'd argue writing passwords down in a notebook or putting them in a naked text file on your computer is better than trusting a centralized service like LP.

Of course, if you are a target of interest, the calculus changes entirely.