Am I being overly paranoid? How should I be approaching the issue of trusting the developers of password managers?
Am I being overly paranoid? How should I be approaching the issue of trusting the developers of password managers?
Hmm. Maybe? The trouble is at some point you have to trust someone and there isn't a good way to measure this. Even if the source of the iOS app was open (I don't know if it is, just a hypothetical) there is no guarantee that the source you looked at is the same that was used to compile the binary itself.
I use one for iOS. I sure hope it's trustworthy. But if it isn't...well I don't really know where to turn to. LastPass? I tried them before but was amazing at how awful the UX was and I was too paranoid that someone would eventually find a flaw, get in and expose everyone's passwords ever because it's a cloud service...I am likely too paranoid.
I upload my keepass and key file to Dropbox (I know, I know) and then export them to MiniKeePass from the Dropbox app. MiniKeepass auto-associates the key file with the kdbx if it has the same filename as the kdbx, but with a .key extension. I can even edit the DB with Minikeepass and upload it back to Dropbox. It's not as sexy as an Android setup, but it works quite well for me.
The new fork is intriguing. Need to take a closer look.
You can disable an app's ability to connect via mobile data in Settings, though that doesn't solve the issue for using the app + wifi.
Does anyone know what happens if you remove the permission from an APK's manifest with apktool etc?
For piece of mind it'd be nice to disable Internet access for certain apps.
EDIT: I know there are solutions when rooted, and also virtual VPN solutions when not rooted. However, in the latter case you have to trust the VPN with all your traffic.
In that context, it seems to me, a paper solution is not totally daft.
The reasoning being that the thief breaking into your home doesn't care about a random sequence of characters, and how it might allow him to steal your online identity if he boots your computer and finds your vault file.
He cares about the resell value of your camera, iPhone and maybe Macbook.
Edit: I believe OP meant this article:
https://www.schneier.com/blog/archives/2005/06/write_down_yo...
I am considering that I should store the keepass database somewhere else as a backup but not sure exactly where (at least the file server at my work) and also that I should tell the passphrase to somebody (perhaps an old university friend I don't see often; he does not live nearby or work with me) in case of my untimely demise
[edit]: oops, confused osx and ios. I'm not a mac person.
I would love to audit it but I lack both the time and knowledge. How would I verify that what I've audited is the source for the actual binary that the App Store delivers to my phone?
Welcome to the walled garden.