You'd expect them to be one of the more targeted companies just because of the 'treasure' they hold - hence the more security breaches.
You'd expect them to be one of the more targeted companies just because of the 'treasure' they hold - hence the more security breaches.
I’ve always taken the route of managing my own local Keepass DB & key files. Sure it’s more cumbersome, but it prevents me from having to decide whether or not to trust some third party vendor or not.
I know 100% that I’m in full control and I’ve never put my DB or key file in the cloud. I can sleep sound knowing that whatever password service, or file sharing service, somehow getting compromised, cannot endanger one of my most valuable assets
Not sure what I can do about that.
Password management, afaik, still needs a zero-knowledge cloud-agnostic solution that is easy to set up and run. There are the big boys (1password, bitwarden, LastPass) and then there are local-only solutions; in between, where the sweet spot should be, there is only a bunch of hacks. The issue is monetization - the incentives for that side are towards centralizing.
What's the risk of keeping the keyfile/password on your device(s) but uploading the database to the cloud? Assuming your keyfile has enough entropy (eg. 256 bits), your database is good as useless without the corresponding key file.
Do you own assessment of all of the "maybes", and come up with your own conclusion and practices. Someone else's hard drive is not to be trusted, but it is convenient.
Pass with a git repo satisfies some of those requirements, but it isn't very user friendly for non-technical users, and fine grained access controls and groups is tricky.
Furthermore, I’d argue that Firefox & chrome password managers probably have several orders of magnitude more passwords stored (and therefore much more highly targeted), yet they don’t seem to have annual security incidents. And you can’t even pay for those products.
People stealing passwords are probably doing it to eventually make money. Criminals could save themselves a ton of work by just directly hacking the banks, yet we don’t hear about highly regular complete compromises there.
Furthermore, if operating a password manager service puts a huge kick-me sign on your service, why don’t the other password managers have plenty of incidents?