But if you want to sync your credentials across devices, you still have to upload them somewhere, right? Doesn't this just support sync via Dropbox? If so, aren't you then just playing the trust game between two third-parties?
But if you want to sync your credentials across devices, you still have to upload them somewhere, right? Doesn't this just support sync via Dropbox? If so, aren't you then just playing the trust game between two third-parties?
An employee of that company, or if the file was leaked due to technical errors, a member of the general public won't be able to decrypt it. If one of the richest governments wanted to, they might be able to, but if you had reasons to be a target you'd know better than using this.
Also, take a look at SpiderOak.
where did you this idea?
oneeyedpigeon: But if you want to sync your credentials across devices, you still have to upload them somewhere, right?
dorfsmay: You are uploading a file that is encrypted using very strong encryption, not plain text password
I took that to mean:
(with keepass) you are uploading a file that is encrypted ... not plain text password (as for 1password)
dorfsmay has now confirmed that was their meaning in this comment: https://news.ycombinator.com/item?id=11177045
With keepassx, your password never leaves your device in unencrypted form.
"The easiest way for us to protect your data and data about you is to not have that data in the first place. You may be noticing a theme by now: we can’t reveal or abuse data that we don’t have.
We do not have your 1Password data. We do not know your 1Password Master Password. We don’t even know if you use 1Password. We do not know how many items you have in your vault or their type."
https://support.1password.com/private-by-design/#what-we-cou...
Also, you're putting too much faith in other people's computers.
That said, most of these password managers use really strong encryption so having your password file exposed isn't much of an issue.