Hacker News new | ask | show | jobs
by misterparker 4609 days ago
What about a site like Passpack? https://www.passpack.com/en/home/

- Does that mean a site like passpack is only waving its hands at its security, and that its client-side cryptography is irrelevant and basically insecure??

1 comments

Yes, exactly. If Passpack (or a government agency that can force Passpack to obey them) wants to read your passwords they can serve you JavaScript that leaks your secure data as soon as your browser encrypts it.