Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Cloud-based. Private." ... Right.


It's hard to trust a cloud-based password manager.

Now, if they're doing the crypto all local and syncing between devices with a miniature version of SpiderOak that would be OK. This is basically what 1Password does -- local crypto and stored on Dropbox or iCloud. That's not worrying at all as long as the crypto -- completely managed locally -- is strong.

But if they're using, say, SSL and an API with your credentials to access the encrypted cloud storage and they have the key... this is bad.


It encrypts locally and sends encrypted data to "the cloud".


That's a good model to adopt. It's also the "ubiquitous encryption" that has James Comey crying like a baby.

I encourage more apps and services to adopt this model. Just, be careful when you do. Definitely open source your code, and definitely get it audited by a qualified team (e.g. NCC Group's crypto services).


I think SpiderOak commissioned an audit of the underlying framework, Crypton... (googled) yep: https://crypton.io/docs/security/audits.html


Yep, this was mentioned above, and by Least Authority too. They do great work.


The other issue is whether your passwords would be lost if they shut down, or had some catastrophic server failure.


A planned feature is "export all data"


It's not hard to trust a cloud-based password manager -- it's insane.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: