Hacker News new | ask | show | jobs
by morgante 4272 days ago
> Password managers are banned from high security applications, because their not secure.

Based on what? I've seen absolutely no evidence that good password managers (1Passoword and its ilk) are insecure.

1 comments

One of the most common failure modes is screen captures which are often used for auditing. So there enabled even when everything is working correctly. For encrypted passwords that are sent directly to the clipboard you still get those files backed up which means you can brute force the password file without throwing up any red flags. Also, pasting passwords is disabled on many secure applications. For apps there stored on an unsecured device with a wide range of failure modes.